NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
Social Engineering Examples·7 sources
NTS IT Care, Inc., run by CEO/CFO Jagmeet Singh Virk, operated a tech-support scam built around deceptive browser pop-up ads. The pop-ups were designed to mimic urgent operating-system security alerts, sometimes claiming to be from Microsoft or Apple, telling consumers their computer had been infected with malware or otherwise compromised and was now 'blocked.' The pop-ups instructed victims to call a toll-free number immediately to fix the problem.
Consumers who called were routed to a call center in India operated by NTS Global Services, Pvt. Ltd. (managed by a co-conspirator referred to in DOJ filings as "Kapoor"), where representatives remotely accessed consumers' computers, ran fake diagnostic scans, falsely claimed to find viruses, spyware, or security breaches (or claimed the computer had no protection at all), and used high-pressure sales tactics to sell multi-year technical-support packages typically costing $99.99 to $499.99. Two parallel federal cases followed.
The FTC sued NTS IT Care and Virk in the Northern District of California (case No. 4:20-cv-03388-PJH), filing its complaint on May 19, 2020, alleging violations of the FTC Act and the Telemarketing Sales Rule; a stipulated order for permanent injunction and monetary judgment was entered on December 4, 2020, without an admission of liability. Separately, DOJ charged Virk by criminal information (N.D. Cal., San Jose Division) with Conspiracy to Commit Wire Fraud (18 U.S.C. §1349), filed July 22, 2020; Virk pleaded guilty on May 14, 2020, and was sentenced on May 11, 2023 to 12 months and a day in prison plus three years of supervised release.
The FTC's civil case and order were kept under seal specifically pending the outcome of that criminal prosecution. Once the criminal case concluded, the FTC unsealed the matter and, on November 7, 2023, announced it was mailing 272 refund checks totaling $255,046 to consumers harmed by the scheme.
The deception began with malvertising-style browser pop-ups engineered to look like a genuine operating-system security warning (leveraging Microsoft/Apple branding cues) rather than an obvious ad. The pop-up created immediate fear and urgency by claiming the device was already compromised and effectively unusable ('blocked'), then funneled the panicked user toward a single remediation path: call this number now.
This flips the usual vishing pattern (attacker cold-calls victim) into a lure-driven inbound model, where the victim self-initiates contact, arriving already primed to believe there is an active threat and predisposed to trust whoever answers as the entity that can fix it. Once on the phone, the call was routed to a call center in India operated by NTS Global Services, Pvt.
Ltd. (a Virk-linked but formally distinct entity from NTS IT Care, Inc., managed on the ground by a co-conspirator referred to in DOJ filings as "Kapoor"), where agents remotely accessed the consumer's computer and used fabricated technical 'evidence' (bogus scan results) to reinforce the false narrative and justify urgency, then pivoted to a high-pressure upsell of costly multi-year support contracts the victims did not need.
The scheme specifically exploited older adults and people less familiar with computer security, who were less likely to recognize the pop-up as fake or to question the callers' technical claims.
The lure was a browser pop-up styled as an urgent OS-level security alert (invoking Microsoft/Apple) claiming the computer was infected and blocked, with a toll-free number to call immediately. Tells that, in hindsight, marked it as fraudulent: legitimate OS or vendor security alerts do not appear as ad-style browser pop-ups demanding an immediate phone call; genuine Microsoft/Apple do not proactively cold-contact consumers via pop-up to sell remote tech support; the 'diagnostic scan' run by phone agents after remotely accessing the machine was staged/fabricated rather than a real, verifiable check of the device; and the sales pitch pressuring an immediate multi-year purchase (bypassing normal consideration time) was itself a hallmark of telemarketing-fraud tactics the FTC's Telemarketing Sales Rule targets.
Two parallel federal actions resulted. Civil: the FTC obtained a stipulated permanent injunction and a $4.9 million monetary judgment (jointly and severally) against NTS IT Care, Inc. and Jagmeet Singh Virk, entered under seal on December 4, 2020, in the U.S. District Court for the Northern District of California (No. 4:20-cv-03388-PJH). Most of the judgment was suspended based on the defendants' documented inability to pay, with Virk required to pay $14,857 from escrow within seven days; the full $4.9M becomes collectible if the financial disclosures underlying the suspension are later found false.
The order imposed a permanent ban on NTS and Virk from advertising, marketing, selling, or assisting others in selling any tech-support product or service, and from owning, controlling, or managing such a business, plus a permanent bar on deceptive/abusive telemarketing practices, misrepresenting affiliation with companies like Microsoft or Apple, and collecting further payment from consumers who had already bought the bogus support packages.
On November 7, 2023, the FTC unsealed the case and mailed 272 refund checks totaling $255,046 (average about $937) to affected consumers; by March 31, 2024, 226 of those checks (83.09%) had been cashed. The FTC's civil case and order were kept under seal from filing (May 2020) through November 2023 specifically pending resolution of the parallel DOJ criminal case against Virk, which is why restitution was not announced until three years after the judgment.
Criminal: DOJ separately charged Jagmeet Singh Virk by criminal information in the same district (N.D. Cal., San Jose Division) with Conspiracy to Commit Wire Fraud (18 U.S.C. §1349), filed July 22, 2020; Virk pleaded guilty on May 14, 2020, and on May 11, 2023, Judge Phyllis J. Hamilton sentenced him to 12 months and a day of imprisonment followed by three years of supervised release, with self-surrender to the Bureau of Prisons ordered for June 26, 2023. The FTC's own consumer-facing refund page states plainly that "Virk was sentenced to prison."
This case is a canonical, court-documented example of pop-up-lure tech-support vishing: the attacker never has to dial a number because the fear-inducing pop-up gets the victim to call in voluntarily, which lowers the victim's guard relative to a cold inbound scam call. It illustrates how brand impersonation (Microsoft/Apple) plus manufactured urgency (device 'blocked') can bypass skepticism, particularly for older or less tech-savvy consumers, and it shows the multi-year regulatory tail of these schemes: a civil complaint filed in 2020, a civil judgment entered under seal that same year, a parallel criminal prosecution that took until 2023 to reach sentencing, and consumer restitution only becoming public once the criminal case concluded, three years after the civil judgment.
It is also a reminder that FTC monetary judgments in these schemes are frequently suspended for inability to pay, so the real deterrent and personal consequence for the operator came not from the $4.9M civil figure but from the separate DOJ prosecution that put the CEO in prison.
Treat any browser pop-up claiming your device is infected or blocked, especially ones urging an immediate phone call, as fraudulent; close the browser/tab rather than calling the number or clicking anything in the pop-up. Remember that Microsoft, Apple, and legitimate OS vendors do not push security alerts via ad-style browser pop-ups or solicit inbound support calls this way.
Never grant remote access or make a purchase decision under manufactured time pressure from an unsolicited technical warning; instead, contact the vendor directly through a known, independently verified channel. Organizations serving older or vulnerable consumers should provide explicit education on this exact lure pattern, since it was broad enough (FTC-documented, hundreds of victims) to warrant both a federal civil enforcement action and a parallel DOJ criminal prosecution resulting in imprisonment.
Social Engineering Examples. “NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam”. Accessed 14 September 2026. https://socialengineeringexamples.com/nts-it-care-tech-support-scam-2020
Per the FTC's complaint, the operators built and maintained browser pop-up creative and delivery infrastructure engineered to look like an operating-system-level security alert rather than an ordinary ad, consistent with commercial ad-buying or malvertising channels and disposable web hosting used to push the pop-up to consumers broadly across the internet, alongside a staffed India-based call center (NTS Global Services, Pvt. Ltd.) built out to absorb inbound call volume and a toll-free number to route callers to it.
Malvertising-style ad abuse is difficult to eliminate entirely at the ad-network level, but ad-network vetting and malvertising-detection services, plus browser and endpoint tools that block deceptive full-screen or redirect-triggered pop-ups, reduce how often the lure ever reaches a user's screen.
The pop-up impersonated a genuine Microsoft or Apple security warning, per the DOJ criminal information, displaying fake labels such as a "Windows Support Alert," a "Microsoft Helpline," or a "Certified Windows Technician," and falsely claimed the computer was infected, that personal data such as logins and photos were being stolen, and that the machine was now "blocked," combining brand authority with manufactured fear and urgency.
Brand-impersonation content itself is nearly impossible to suppress before display, so the realistic control is consumer education, reinforced by the vendors themselves, that Microsoft, Apple, and legitimate OS makers never issue security alerts as ad-style browser pop-ups or solicit inbound support calls this way.
The pop-up instructed the consumer to call a toll-free number immediately, flipping the usual vishing pattern so the victim dialed in voluntarily, already primed to believe a real threat existed and predisposed to trust whoever answered.
There is no practical technical control once a consumer decides to dial a number themselves; the nearest real control is the Stage 2 education that stops the pop-up from being believed in the first place, since caller-ID and robocall defenses do not apply to victim-initiated calls.
Per the DOJ information, NTS Global Services agents in India remotely accessed the consumer's computer and ran fabricated "diagnostic scans," falsely claiming to detect viruses, spyware, or security breaches, or claiming the machine had no protection at all, to manufacture technical-looking evidence that reinforced the false narrative.
Consumers and organizations should have a hard rule against granting remote-desktop access to an unsolicited caller and should treat any "scan" completed within seconds of connecting as staged rather than a genuine technical check, verifying independently through a vendor's official support channel instead.
Sales representatives used high-pressure tactics to push consumers, largely older adults and people less familiar with computer security, into buying multi-year technical-support packages typically priced between $99.99 and $499.99, collecting credit-card and personal information directly over the call.
Refusing to make a purchase decision under manufactured time pressure, insisting on time to consider and independently verify the seller, and relying on credit-card issuer fraud and chargeback protections addresses this stage directly, and is the exact conduct the FTC's Telemarketing Sales Rule was designed to police.
Recurring billing and exploitation of consumer data (objective completion): Per the FTC complaint, the scheme generated approximately $5 million from consumers since 2016 alone through this repeated sales cycle, while also retaining consumers' personal and payment data for potential further use, which the eventual FTC order specifically had to prohibit and require destroyed.
After-the-fact remedies did the work here: the FTC's stipulated order permanently barred NTS and Virk from further collection, from benefiting from consumer data, and required its destruction, while DOJ's parallel forfeiture allegation targeted the wire-fraud proceeds directly, showing that once objective completion occurs the practical countermeasure shifts from consumer self-defense to regulatory and criminal enforcement.
Browse by what this case has in common with others in the library.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
Posing as NatWest bank security, vishing criminals convinced Surrey solicitor Karen Mackie to wire £734,000 of client money to fraudulent…
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.