Attack Techniques

Tech-support scam

A fake support agent persuades the victim to grant remote access or pay for nothing.

A tech-support scam convinces the victim that their device or account has a problem, then offers help. Once trust and often remote access are granted, the attacker takes payment for nothing, installs something, or moves money directly.

This library records 3 cases. Older adults are disproportionately targeted, and the regulator has treated it as consumer protection rather than purely cybercrime.

How the attack runs

  1. An alarming prompt: a browser pop-up, a warning, or an unsolicited call about an infection.
  2. A support number the victim dials themselves, which increases trust.
  3. A remote-access tool is installed, usually a legitimate one, so no security product objects.
  4. Fabricated evidence, with ordinary system logs presented as proof of compromise.
  5. Payment or direct theft, either a fee for a nonexistent fix or access to banking while connected.

Documented cases

  • NTS IT Care (2020, $4.9M FTC judgment): fake Microsoft and Apple security pop-ups frightened consumers, mostly older Americans, into calling.
  • A Barclays customer (2024): a jeweller was talked into installing AnyDesk during a call impersonating the bank.
  • A fake AnyDesk installer (2025) delivering an infostealer, showing the same trusted tool weaponised at the download stage.

How it differs from related techniques

Callback phishing shares the victim-dials mechanic but usually targets businesses. Vishing is the parent channel. ClickFix uses a fake error to get the user to run a command instead of making a call.

The control that would have stopped it

  • No legitimate provider makes unsolicited contact about an infection. This single rule prevents most of these losses.
  • Never install remote-access software at the request of an inbound caller, and treat AnyDesk or TeamViewer requests as a stop condition.
  • Download tools only from the vendor’s own site, which addresses the fake-installer variant.
  • For banks: flag remote-access sessions during transactions, a detectable and high-signal pattern.
  • Brief older relatives specifically. The FTC data is unambiguous about who is targeted.
Explore more

Related techniques and attack types

Parent attack type