Security pop-ups from real tech companies never ask you to call a phone number, but scammers use that trick to reach your bank account

Business woman phone call and overwhelmed in office with paperwork laptop and proposal in agency Chaos deadline and tech with multitasking stress and burnout with documents and busy staff

A full-screen warning can make a frozen computer look like a financial emergency. The phone number in the warning is the trap: calling it connects the user to an impostor who may seek remote control, bank credentials, or an immediate payment. The safest first move is to stop interacting with the message. A genuine security alert does not require a call to a number displayed in a pop-up, and no bank account needs to be moved to a supposed safe location.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

Why the phone number proves the pop-up is fake

The Federal Trade Commission’s current tech-support warning says that real security pop-ups never ask users to call a phone number. Scammers design fake alerts to resemble well-known technology companies, antivirus products, or operating-system messages and use alarm sounds, countdowns, and claims of infection to force a quick reaction. Once a victim calls, the impostor asks for remote access and pretends to scan the device. The caller may display ordinary system files as evidence of a virus, claim that accounts were hacked, or transfer the victim to another impostor posing as a bank or government investigator.

How the bank account enters the story

The false technician may say that criminals are using the victim’s bank account and that money must be transferred for protection. Another version begins with a fake subscription-renewal email. The impostor offers a refund, opens a fake banking page, and claims that too much money was returned, creating pressure to “repay” the difference. Remote-access software lets the scammer view the screen, capture credentials, move the pointer, and conceal activity. Payment demands often involve gift cards, wires, cryptocurrency, cash, gold, or a payment app because those methods are difficult to reverse. Government employees do not order consumers to withdraw money or place it in a “federal safety locker.”

Who tech-support scammers target

The scheme can reach any computer or phone user through malicious advertising, compromised websites, unsolicited email, or browser notifications. Older adults may be targeted with familiar brand names and callers who stay on the line for hours. The FTC’s tech-support enforcement guidance notes that the federal Telemarketing Sales Rule now covers inbound calls made in response to tech-support pop-ups and ads as well as cold calls. Caregivers can reduce risk by reviewing notification permissions, writing trusted support contacts near the computer, and arranging appropriate bank alerts.

Closing the warning without calling

No number in the message should be called and no link should be clicked. The browser can be closed; if it will not close, the device can be restarted. A scan should be run with security software already installed or obtained from a trusted source. Support should be contacted through a known company website or a local technician chosen independently. The warning should not be granted notification permission, and any unfamiliar browser extensions or applications should be removed. A screenshot can help document the incident, but interacting with the pop-up to gather evidence is unnecessary. The goal is to end the connection before credentials or money are exposed.

Closing the browser does not require accepting the pop-up’s buttons. A forced restart may discard unsaved work, but it is safer than entering a password or downloading a “repair” tool from the warning. After restart, the user should open the browser’s history and extension settings without returning to the suspicious page. If the alert reappears automatically, a trusted technician can clear the startup page, notification permission, or extension responsible before the device is used for email or banking.

The device should be disconnected from the internet, and the remote-access program should be removed with trusted technical help. Passwords should be changed from a different, clean device, beginning with email and financial accounts. Multi-factor authentication should be enabled, active sessions reviewed, and unfamiliar recovery addresses or forwarding rules removed before the affected computer returns to service.

Financial institutions should be reached from the number on a statement, card, or authenticated app, never through a transfer from the supposed technician. The report should state that an unknown person viewed or controlled the screen, not merely that a suspicious call occurred. That distinction helps the bank review newly added payees, external-account links, profile changes, wire attempts, and security-token enrollment that may not appear in the ordinary transaction list.

The bank, brokerage, and card issuers should be told what happened. Transactions, new payees, wire instructions, external-account links, and contact details should be examined across the remote-access period. The FTC’s post-scam response guide lists steps by payment method and by the type of information exposed, allowing the response to follow the transfer channel actually used.

Recovering after remote access was granted

If a Social Security number or other identity data was disclosed, a credit freeze and an official IdentityTheft.gov recovery plan may be appropriate. Bank alerts should remain elevated for several months. Email forwarding rules and recovery addresses should be checked because an intruder can retain access after a password change. A reset may be needed when the scope of remote access is unclear. Important files should be backed up carefully, and financial activity should not resume on the device until it is trusted. The incident and fake support number can also be submitted through ReportFraud.ftc.gov.

Protecting the device and accounts afterward

A real security warning points to settings or trusted support; it does not put a call center inside a frightening pop-up. Refusing the displayed number breaks the scam’s path from a browser screen to a bank account. Independent contact, a clean device, and quick bank notice provide the strongest recovery when contact has already occurred.

Browsers, operating systems, and security software should be kept current through automatic updates. Unneeded extensions can be removed, and browser notification permissions can be limited to trusted sites. An ad blocker may reduce malicious advertising, though it cannot replace careful browsing and updates. A standard account without administrator privileges can also limit what an unapproved installer changes, although it cannot make remote access safe.

Search results for technical support can include paid impostor ads. Support numbers should come from the product’s settings, purchase documents, or the company’s official site reached directly. Bookmarks for a bank, email provider, and major technology accounts reduce dependence on search during a stressful event. A printed support list remains usable when the device itself is untrusted.

A short household response card can state: do not call the pop-up, do not grant remote access, restart the device, and call a trusted person. Rehearsing those steps gives a frightened user something concrete to do while the warning tries to remove time for thought. If remote access was granted, the record should include the software name, start and end times, accounts opened on screen, passwords typed, transfers attempted, and phone numbers used. That timeline gives banks and technicians facts they can act on instead of a general description of a “computer hack.”

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

More Financial Reading

Social Security and Medicare change every year, and nobody sends you a memo. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.