Case Library / Vishing (Voice Phishing) / NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support line that sold bogus multi-year tech-support packages, resulting in a $4.9M FTC judgment plus a separate DOJ criminal conviction that sent CEO Jagmeet Singh Virk to prison.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

NTS IT Care, Inc., run by CEO/CFO Jagmeet Singh Virk, operated a tech-support scam built around deceptive browser pop-up ads. The pop-ups were designed to mimic urgent operating-system security alerts, sometimes claiming to be from Microsoft or Apple, telling consumers their computer had been infected with malware or otherwise compromised and was now 'blocked.' The pop-ups instructed victims to call a toll-free number immediately to fix the problem. Consumers who called were routed to a call center in India operated by NTS Global Services, Pvt. Ltd. (managed by a co-conspirator referred to in DOJ filings as "Kapoor"), where representatives remotely accessed consumers' computers, ran fake diagnostic scans, falsely claimed to find viruses, spyware, or security breaches (or claimed the computer had no protection at all), and used high-pressure sales tactics to sell multi-year technical-support packages typically costing $99.99 to $499.99. Two parallel federal cases followed. The FTC sued NTS IT Care and Virk in the Northern District of California (case No. 4:20-cv-03388-PJH), filing its complaint on May 19, 2020, alleging violations of the FTC Act and the Telemarketing Sales Rule; a stipulated order for permanent injunction and monetary judgment was entered on December 4, 2020, without an admission of liability. Separately, DOJ charged Virk by criminal information (N.D. Cal., San Jose Division) with Conspiracy to Commit Wire Fraud (18 U.S.C. §1349), filed July 22, 2020; Virk pleaded guilty on May 14, 2020, and was sentenced on May 11, 2023 to 12 months and a day in prison plus three years of supervised release. The FTC's civil case and order were kept under seal specifically pending the outcome of that criminal prosecution. Once the criminal case concluded, the FTC unsealed the matter and, on November 7, 2023, announced it was mailing 272 refund checks totaling $255,046 to consumers harmed by the scheme.

How the Attack Worked

The deception began with malvertising-style browser pop-ups engineered to look like a genuine operating-system security warning (leveraging Microsoft/Apple branding cues) rather than an obvious ad. The pop-up created immediate fear and urgency by claiming the device was already compromised and effectively unusable ('blocked'), then funneled the panicked user toward a single remediation path: call this number now. This flips the usual vishing pattern (attacker cold-calls victim) into a lure-driven inbound model, where the victim self-initiates contact, arriving already primed to believe there is an active threat and predisposed to trust whoever answers as the entity that can fix it. Once on the phone, the call was routed to a call center in India operated by NTS Global Services, Pvt. Ltd. (a Virk-linked but formally distinct entity from NTS IT Care, Inc., managed on the ground by a co-conspirator referred to in DOJ filings as "Kapoor"), where agents remotely accessed the consumer's computer and used fabricated technical 'evidence' (bogus scan results) to reinforce the false narrative and justify urgency, then pivoted to a high-pressure upsell of costly multi-year support contracts the victims did not need. The scheme specifically exploited older adults and people less familiar with computer security, who were less likely to recognize the pop-up as fake or to question the callers' technical claims.

The Lure & the Tell

The lure was a browser pop-up styled as an urgent OS-level security alert (invoking Microsoft/Apple) claiming the computer was infected and blocked, with a toll-free number to call immediately. Tells that, in hindsight, marked it as fraudulent: legitimate OS or vendor security alerts do not appear as ad-style browser pop-ups demanding an immediate phone call; genuine Microsoft/Apple do not proactively cold-contact consumers via pop-up to sell remote tech support; the 'diagnostic scan' run by phone agents after remotely accessing the machine was staged/fabricated rather than a real, verifiable check of the device; and the sales pitch pressuring an immediate multi-year purchase (bypassing normal consideration time) was itself a hallmark of telemarketing-fraud tactics the FTC's Telemarketing Sales Rule targets.

Outcome

Two parallel federal actions resulted. Civil: the FTC obtained a stipulated permanent injunction and a $4.9 million monetary judgment (jointly and severally) against NTS IT Care, Inc. and Jagmeet Singh Virk, entered under seal on December 4, 2020, in the U.S. District Court for the Northern District of California (No. 4:20-cv-03388-PJH). Most of the judgment was suspended based on the defendants' documented inability to pay, with Virk required to pay $14,857 from escrow within seven days; the full $4.9M becomes collectible if the financial disclosures underlying the suspension are later found false. The order imposed a permanent ban on NTS and Virk from advertising, marketing, selling, or assisting others in selling any tech-support product or service, and from owning, controlling, or managing such a business, plus a permanent bar on deceptive/abusive telemarketing practices, misrepresenting affiliation with companies like Microsoft or Apple, and collecting further payment from consumers who had already bought the bogus support packages. On November 7, 2023, the FTC unsealed the case and mailed 272 refund checks totaling $255,046 (average about $937) to affected consumers; by March 31, 2024, 226 of those checks (83.09%) had been cashed. The FTC's civil case and order were kept under seal from filing (May 2020) through November 2023 specifically pending resolution of the parallel DOJ criminal case against Virk, which is why restitution was not announced until three years after the judgment. Criminal: DOJ separately charged Jagmeet Singh Virk by criminal information in the same district (N.D. Cal., San Jose Division) with Conspiracy to Commit Wire Fraud (18 U.S.C. §1349), filed July 22, 2020; Virk pleaded guilty on May 14, 2020, and on May 11, 2023, Judge Phyllis J. Hamilton sentenced him to 12 months and a day of imprisonment followed by three years of supervised release, with self-surrender to the Bureau of Prisons ordered for June 26, 2023. The FTC's own consumer-facing refund page states plainly that "Virk was sentenced to prison."

Why It Matters

This case is a canonical, court-documented example of pop-up-lure tech-support vishing: the attacker never has to dial a number because the fear-inducing pop-up gets the victim to call in voluntarily, which lowers the victim's guard relative to a cold inbound scam call. It illustrates how brand impersonation (Microsoft/Apple) plus manufactured urgency (device 'blocked') can bypass skepticism, particularly for older or less tech-savvy consumers, and it shows the multi-year regulatory tail of these schemes: a civil complaint filed in 2020, a civil judgment entered under seal that same year, a parallel criminal prosecution that took until 2023 to reach sentencing, and consumer restitution only becoming public once the criminal case concluded, three years after the civil judgment. It is also a reminder that FTC monetary judgments in these schemes are frequently suspended for inability to pay, so the real deterrent and personal consequence for the operator came not from the $4.9M civil figure but from the separate DOJ prosecution that put the CEO in prison.

Defenses

Treat any browser pop-up claiming your device is infected or blocked, especially ones urging an immediate phone call, as fraudulent; close the browser/tab rather than calling the number or clicking anything in the pop-up. Remember that Microsoft, Apple, and legitimate OS vendors do not push security alerts via ad-style browser pop-ups or solicit inbound support calls this way. Never grant remote access or make a purchase decision under manufactured time pressure from an unsolicited technical warning; instead, contact the vendor directly through a known, independently verified channel. Organizations serving older or vulnerable consumers should provide explicit education on this exact lure pattern, since it was broad enough (FTC-documented, hundreds of victims) to warrant both a federal civil enforcement action and a parallel DOJ criminal prosecution resulting in imprisonment.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Infrastructure and lure setup: Per the FTC's complaint, the operators built and maintained browser pop-up creative and delivery infrastructure engineered to look like an operating-system-level security alert rather than an ordinary ad, consistent with commercial ad-buying or malvertising channels and disposable web hosting used to push the pop-up to consumers broadly across the internet, alongside a staffed India-based call center (NTS Global Services, Pvt. Ltd.) built out to absorb inbound call volume and a toll-free number to route callers to it.
Countering Stage 1: Malvertising-style ad abuse is difficult to eliminate entirely at the ad-network level, but ad-network vetting and malvertising-detection services, plus browser and endpoint tools that block deceptive full-screen or redirect-triggered pop-ups, reduce how often the lure ever reaches a user's screen.
2
Brand and alert impersonation: The pop-up impersonated a genuine Microsoft or Apple security warning, per the DOJ criminal information, displaying fake labels such as a "Windows Support Alert," a "Microsoft Helpline," or a "Certified Windows Technician," and falsely claimed the computer was infected, that personal data such as logins and photos were being stolen, and that the machine was now "blocked," combining brand authority with manufactured fear and urgency.
Countering Stage 2: Brand-impersonation content itself is nearly impossible to suppress before display, so the realistic control is consumer education, reinforced by the vendors themselves, that Microsoft, Apple, and legitimate OS makers never issue security alerts as ad-style browser pop-ups or solicit inbound support calls this way.
3
Victim self-initiated inbound contact: The pop-up instructed the consumer to call a toll-free number immediately, flipping the usual vishing pattern so the victim dialed in voluntarily, already primed to believe a real threat existed and predisposed to trust whoever answered.
Countering Stage 3: There is no practical technical control once a consumer decides to dial a number themselves; the nearest real control is the Stage 2 education that stops the pop-up from being believed in the first place, since caller-ID and robocall defenses do not apply to victim-initiated calls.
4
Pretext reinforcement via fake remote diagnostics: Per the DOJ information, NTS Global Services agents in India remotely accessed the consumer's computer and ran fabricated "diagnostic scans," falsely claiming to detect viruses, spyware, or security breaches, or claiming the machine had no protection at all, to manufacture technical-looking evidence that reinforced the false narrative.
Countering Stage 4: Consumers and organizations should have a hard rule against granting remote-desktop access to an unsolicited caller and should treat any "scan" completed within seconds of connecting as staged rather than a genuine technical check, verifying independently through a vendor's official support channel instead.
5
High-pressure upsell and payment capture: Sales representatives used high-pressure tactics to push consumers, largely older adults and people less familiar with computer security, into buying multi-year technical-support packages typically priced between $99.99 and $499.99, collecting credit-card and personal information directly over the call.
Countering Stage 5: Refusing to make a purchase decision under manufactured time pressure, insisting on time to consider and independently verify the seller, and relying on credit-card issuer fraud and chargeback protections addresses this stage directly, and is the exact conduct the FTC's Telemarketing Sales Rule was designed to police.
6
Recurring billing and exploitation of consumer data (objective completion): Per the FTC complaint, the scheme generated approximately $5 million from consumers since 2016 alone through this repeated sales cycle, while also retaining consumers' personal and payment data for potential further use, which the eventual FTC order specifically had to prohibit and require destroyed.
Countering Stage 6: After-the-fact remedies did the work here: the FTC's stipulated order permanently barred NTS and Virk from further collection, from benefiting from consumer data, and required its destruction, while DOJ's parallel forfeiture allegation targeted the wire-fraud proceeds directly, showing that once objective completion occurs the practical countermeasure shifts from consumer self-defense to regulatory and criminal enforcement.
Quick Facts
Victim
U.S. consumers, particularly older Americans and people unfamiliar with computer security, who encountered the fake pop-up while browsing
Location
United States (victims nationwide); call center operations in the Republic of India (run by NTS Global Services, Pvt. Ltd.); FTC civil case litigated in N.D. California (Oakland); DOJ criminal case litigated in N.D. California (San Jose Division).
Date
Scheme operated from at least 2014 (per DOJ, conspiracy dated "on or about March 2014" through the present) and prior to 2020; FTC civil complaint filed under seal May 19, 2020; parallel DOJ criminal information against Jagmeet Singh Virk filed July 22, 2020, with a guilty plea entered May 14, 2020; stipulated FTC final order entered under seal December 4, 2020; Virk sentenced May 11, 2023 (self-surrender to BOP June 26, 2023); FTC case unsealed and refunds announced November 7, 2023.
Impact
Civil: $4.9 million equitable monetary judgment entered jointly and severally against NTS IT Care, Inc. and Jagmeet Singh Virk (largely suspended based on documented inability to pay, with Virk required to pay $14,857 from escrow within 7 days; the full $4.9M becomes collectible if the underlying financial disclosures are later found false). In November 2023 the FTC mailed 272 refund checks totaling $255,046 (average ~$937.67, rounded by the FTC to $937) to consumers who lost money to the scheme; as of March 31, 2024, 226 of those checks (83.09%) had been cashed. Individual consumer losses in the underlying scam reportedly ran $99.99 to $499.99 per bogus multi-year tech-support package, with the FTC's complaint estimating Defendants took approximately $5 million from consumers since 2016 alone. Criminal: Jagmeet Singh Virk was separately prosecuted by DOJ and, per the criminal information's forfeiture allegation (18 U.S.C. §981(a)(1)(C) and 28 U.S.C. §2461(c)), was subject to forfeiture of a sum equal to the wire-fraud proceeds he obtained, in addition to a $250,000 statutory maximum fine exposure under 18 U.S.C. §1349 (actual fine/restitution amount as imposed at sentencing not independently detailed in public DOJ summary reviewed).
Status
Confirmed
Case Type
Real-World Incident
Sector
Retail & E-commerce, Technology & Software
Threat Actor
Organized Crime
Related

Related Cases

CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…

Incident 2014Read →

NatWest "Vishing" Callback Fraud Costs Surrey Solicitor Karen Mackie £734,000 and Her Career

Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire…

Incident 2015Read →

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii…

Incident 2015Read →