NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.
Reviewed by the Social Engineering Examples team.
NTS IT Care, Inc., run by CEO/CFO Jagmeet Singh Virk, operated a tech-support scam built around deceptive browser pop-up ads. The pop-ups were designed to mimic urgent operating-system security alerts, sometimes claiming to be from Microsoft or Apple, telling consumers their computer had been infected with malware or otherwise compromised and was now 'blocked.' The pop-ups instructed victims to call a toll-free number immediately to fix the problem. Consumers who called were routed to a call center in India operated by NTS Global Services, Pvt. Ltd. (managed by a co-conspirator referred to in DOJ filings as "Kapoor"), where representatives remotely accessed consumers' computers, ran fake diagnostic scans, falsely claimed to find viruses, spyware, or security breaches (or claimed the computer had no protection at all), and used high-pressure sales tactics to sell multi-year technical-support packages typically costing $99.99 to $499.99. Two parallel federal cases followed. The FTC sued NTS IT Care and Virk in the Northern District of California (case No. 4:20-cv-03388-PJH), filing its complaint on May 19, 2020, alleging violations of the FTC Act and the Telemarketing Sales Rule; a stipulated order for permanent injunction and monetary judgment was entered on December 4, 2020, without an admission of liability. Separately, DOJ charged Virk by criminal information (N.D. Cal., San Jose Division) with Conspiracy to Commit Wire Fraud (18 U.S.C. §1349), filed July 22, 2020; Virk pleaded guilty on May 14, 2020, and was sentenced on May 11, 2023 to 12 months and a day in prison plus three years of supervised release. The FTC's civil case and order were kept under seal specifically pending the outcome of that criminal prosecution. Once the criminal case concluded, the FTC unsealed the matter and, on November 7, 2023, announced it was mailing 272 refund checks totaling $255,046 to consumers harmed by the scheme.
The deception began with malvertising-style browser pop-ups engineered to look like a genuine operating-system security warning (leveraging Microsoft/Apple branding cues) rather than an obvious ad. The pop-up created immediate fear and urgency by claiming the device was already compromised and effectively unusable ('blocked'), then funneled the panicked user toward a single remediation path: call this number now. This flips the usual vishing pattern (attacker cold-calls victim) into a lure-driven inbound model, where the victim self-initiates contact, arriving already primed to believe there is an active threat and predisposed to trust whoever answers as the entity that can fix it. Once on the phone, the call was routed to a call center in India operated by NTS Global Services, Pvt. Ltd. (a Virk-linked but formally distinct entity from NTS IT Care, Inc., managed on the ground by a co-conspirator referred to in DOJ filings as "Kapoor"), where agents remotely accessed the consumer's computer and used fabricated technical 'evidence' (bogus scan results) to reinforce the false narrative and justify urgency, then pivoted to a high-pressure upsell of costly multi-year support contracts the victims did not need. The scheme specifically exploited older adults and people less familiar with computer security, who were less likely to recognize the pop-up as fake or to question the callers' technical claims.
The lure was a browser pop-up styled as an urgent OS-level security alert (invoking Microsoft/Apple) claiming the computer was infected and blocked, with a toll-free number to call immediately. Tells that, in hindsight, marked it as fraudulent: legitimate OS or vendor security alerts do not appear as ad-style browser pop-ups demanding an immediate phone call; genuine Microsoft/Apple do not proactively cold-contact consumers via pop-up to sell remote tech support; the 'diagnostic scan' run by phone agents after remotely accessing the machine was staged/fabricated rather than a real, verifiable check of the device; and the sales pitch pressuring an immediate multi-year purchase (bypassing normal consideration time) was itself a hallmark of telemarketing-fraud tactics the FTC's Telemarketing Sales Rule targets.
Two parallel federal actions resulted. Civil: the FTC obtained a stipulated permanent injunction and a $4.9 million monetary judgment (jointly and severally) against NTS IT Care, Inc. and Jagmeet Singh Virk, entered under seal on December 4, 2020, in the U.S. District Court for the Northern District of California (No. 4:20-cv-03388-PJH). Most of the judgment was suspended based on the defendants' documented inability to pay, with Virk required to pay $14,857 from escrow within seven days; the full $4.9M becomes collectible if the financial disclosures underlying the suspension are later found false. The order imposed a permanent ban on NTS and Virk from advertising, marketing, selling, or assisting others in selling any tech-support product or service, and from owning, controlling, or managing such a business, plus a permanent bar on deceptive/abusive telemarketing practices, misrepresenting affiliation with companies like Microsoft or Apple, and collecting further payment from consumers who had already bought the bogus support packages. On November 7, 2023, the FTC unsealed the case and mailed 272 refund checks totaling $255,046 (average about $937) to affected consumers; by March 31, 2024, 226 of those checks (83.09%) had been cashed. The FTC's civil case and order were kept under seal from filing (May 2020) through November 2023 specifically pending resolution of the parallel DOJ criminal case against Virk, which is why restitution was not announced until three years after the judgment. Criminal: DOJ separately charged Jagmeet Singh Virk by criminal information in the same district (N.D. Cal., San Jose Division) with Conspiracy to Commit Wire Fraud (18 U.S.C. §1349), filed July 22, 2020; Virk pleaded guilty on May 14, 2020, and on May 11, 2023, Judge Phyllis J. Hamilton sentenced him to 12 months and a day of imprisonment followed by three years of supervised release, with self-surrender to the Bureau of Prisons ordered for June 26, 2023. The FTC's own consumer-facing refund page states plainly that "Virk was sentenced to prison."
This case is a canonical, court-documented example of pop-up-lure tech-support vishing: the attacker never has to dial a number because the fear-inducing pop-up gets the victim to call in voluntarily, which lowers the victim's guard relative to a cold inbound scam call. It illustrates how brand impersonation (Microsoft/Apple) plus manufactured urgency (device 'blocked') can bypass skepticism, particularly for older or less tech-savvy consumers, and it shows the multi-year regulatory tail of these schemes: a civil complaint filed in 2020, a civil judgment entered under seal that same year, a parallel criminal prosecution that took until 2023 to reach sentencing, and consumer restitution only becoming public once the criminal case concluded, three years after the civil judgment. It is also a reminder that FTC monetary judgments in these schemes are frequently suspended for inability to pay, so the real deterrent and personal consequence for the operator came not from the $4.9M civil figure but from the separate DOJ prosecution that put the CEO in prison.
Treat any browser pop-up claiming your device is infected or blocked, especially ones urging an immediate phone call, as fraudulent; close the browser/tab rather than calling the number or clicking anything in the pop-up. Remember that Microsoft, Apple, and legitimate OS vendors do not push security alerts via ad-style browser pop-ups or solicit inbound support calls this way. Never grant remote access or make a purchase decision under manufactured time pressure from an unsolicited technical warning; instead, contact the vendor directly through a known, independently verified channel. Organizations serving older or vulnerable consumers should provide explicit education on this exact lure pattern, since it was broad enough (FTC-documented, hundreds of victims) to warrant both a federal civil enforcement action and a parallel DOJ criminal prosecution resulting in imprisonment.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire…
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii…