CyberGlossary

Attacks & Threats

Tech Support Scam

Also known as: Fake support fraud, Refund scam

Definition

A fraud in which attackers pose as technical support agents from a well-known vendor to convince victims to install remote-access tools, hand over credentials, or pay for fake services.

Tech support scams usually combine intimidating pop-ups, scareware browser lockers, cold calls, or paid search ads impersonating major brands such as Microsoft, Apple, or banks. The victim is talked into installing legitimate remote-control software (AnyDesk, TeamViewer, ScreenConnect), then walked through "diagnostics" that culminate in paying for a non-existent subscription, transferring funds, or granting persistent access for later abuse (refund scams, banking trojan deployment). Defences include browser anti-fraud filters, ad-platform brand-impersonation policies, awareness campaigns aimed at older users, OS-level blocks on unsigned remote-access tools, and clear vendor messaging that they never cold-call customers.

Examples

  • A fake "Windows Defender" pop-up with a toll-free number that connects to scammers selling a fake clean-up service.
  • Refund-scam callers who use remote access to manipulate a victim's bank balance and demand returns in crypto.

Related terms