How theScamWorks
Fake tech support or virus alert · How it works

Fake Microsoft Security Alert: The Phone Number Is the Scam

Published Updated 17 min read
Video: Fake Microsoft Security Alert: The Phone Number Is the Scam — 15:11. Watch on YouTube.

Nothing is infected. The full-screen alert is a web page delivered through an ad slot, and the phone number is the product being sold. Microsoft states that its error and warning messages never include a phone number. The FTC states that real security pop-ups never ask you to call one.

Key facts

they never include a phone number
Microsoft's own rule about its error and warning messages
Microsoft, Protect yourself from tech support scams
they will never ask you to call a phone number
The FTC's rule about genuine security pop-ups
FTC Consumer Advice, How To Spot, Avoid, and Report Tech Support Scams
47,794 complaints and $2,134,675,818
Tech support fraud reported to the FBI in 2025, the third most expensive fraud category of the year
FBI Internet Crime Complaint Center, 2025 Annual Report
21,333 complaints and $1,040,730,043
Share of that category reported by victims over 60
FBI Internet Crime Complaint Center, 2025 Annual Report
$32,865,655 of the $65,367,648 reported lost
Money frozen by the FBI's Financial Fraud Kill Chain in 2025 incidents involving victims over 60
FBI Internet Crime Complaint Center, 2025 Annual Report
about 725 complaints and $311.8 million
Gold courier scams, where couriers collect cash and precious metals from tech-support and government-impersonation victims
FBI Internet Crime Complaint Center, 2025 Annual Report
almost 50% of victims were over 60, and 66% of total losses
Age profile of victims in the FBI's Phantom Hacker alert, where tech support, bank and government personas are layered
FBI Internet Crime Complaint Center, Phantom Hacker PSA, 29 September 2023
approximately 15 million calls
Calls routed to fake support call centres by a single platform charging per call, in a case sentenced in a federal court in North Carolina
U.S. Department of Justice, February 2026
more than $20 million in sales
Pop-up call leads sold to call centres by one broker in the same case, with sentences of 30, 40 and 24 months and $3,711,000 forfeited
U.S. Department of Justice, February 2026
17 minutes and $290.90
Average length of a fake support call, and average charge, across 60 calls recorded by researchers
Stony Brook University, Dial One for Scam, NDSS 2017
8,698 domains
Unique scam-support web domains found in 250 days, with 43% online for three days or less
Stony Brook University, Dial One for Scam, NDSS 2017
59% of 16,254 adults
Adults surveyed in 16 countries who had an encounter with a tech support scam, of whom 7% lost money
Microsoft and YouGov, Global Tech Support Scam Research, 2021
12% of 24 to 37 year olds
Age group most likely to lose money in that survey, against 2% of people aged 54 and over
Microsoft and YouGov, Global Tech Support Scam Research, 2021

Nothing is infected. The full-screen alert is a web page delivered through an ad slot, and the phone number is the product being sold. Microsoft states that its error and warning messages never include a phone number. The FTC states that real security pop-ups never ask you to call one.

Nobody hacks Microsoft to run this. They borrow the name. Microsoft is a company being robbed here too: it publishes the rule that ends the scam and pays an investigations unit to chase the people wearing its brand.

What follows is one composite case up to the moment of the phone call, the industry that gets paid for that call, and the single sentence that ends it. This article stops at the call, because that is where the decision is still yours.

The case

Call her Ellen. She is not one person. She is a composite, built from the tech-support complaints in the FBI’s files and the pattern the Federal Trade Commission and the Justice Department describe in their own records. Every step below happens, in this order, to somebody today.

Ellen is sixty-eight. Retired. Comfortable with a computer, not fascinated by one. She is reading a recipe on a perfectly ordinary website when the page stops being a recipe.

The tone starts. The browser snaps to full screen. A red band drops across the top. There is a shield, an error code that means nothing, and, in the largest type on the page, a phone number — with one line underneath it: do not shut down your computer. She reaches for the mouse and the window does not close.

Security researchers at Malwarebytes, who have taken these pages apart for years, describe the effect precisely: the sound of an alert and a browser that appears to be completely locked up “triggers panic for many people.” That is not a side effect of the design. It is the design.

Now count what is on that machine. Twenty years of photographs. Tax returns. Her bank. Ellen does not know how a browser works, and she should not have to. What she knows is that something official is telling her not to touch anything, and offering exactly one way out.

Not a payment. Not a download. A phone call — the only move on offer, and the one that feels safest. Calling for help is the responsible thing to do, and it is the single action that hands the situation to the people who built the screen.

She calls.

The voice is calm. Unhurried. He uses her first name. He asks permission before every step and waits for her to say yes. And he never once asks her to trust him. He does not have to. He asks her to trust the logo already on her screen — a name that was on that computer the day she bought it, years before he ever picked up a phone. He is simply the person that name sent.

That is the transfer, and the transfer is the crime. It happens in the first ninety seconds, before a single dollar moves. Everything after it is paperwork.

Nobody on that call is in a hurry. Computer scientists at Stony Brook University recorded sixty of these calls end to end and found the scammers “patient (average call duration is 17 minutes)”, charging “hundreds of dollars (average charge is $290.9)”. Seventeen minutes is longer than most people have ever spent on the phone with their actual bank. Time is what converts a frightened caller into a paying one.

Then the impostors stack. Somewhere in the call the story changes: your accounts have been accessed. Ellen’s phone rings again, and this time the caller says he is from her bank’s fraud department. After him, someone with a government seal. The FBI’s Phantom Hacker alert describes exactly this escalation, and says the personas are layered “to enhance the trust victims place in the scammers” — tech support, then the financial institution, then a federal agency with letterhead to match. The Bureau also records the instruction that gives the whole thing away: the caller tells the victim not to tell anyone the real reason they are moving their money.

And that is where this article stops, deliberately, at the doorway. What happens on that computer once the door is open is a separate story, and it is coming. This one is about the ninety seconds before it — because nobody hacked Microsoft that day. The company was never touched. To understand what was actually stolen, look at what that phone number was worth, and at who got paid for it.

How it works, step by step

Seven moves. Only the first two involve a computer at all.

  1. The page arrives through a site you had every reason to trust. Malwarebytes found that “malvertising was almost always an element in the chain” — the alert is served through the advertising slot of an ordinary, legitimate website. It works because it breaks the rule people think protects them. You did not go anywhere suspicious, so the alert cannot be your fault, so it must be real.
  2. What you are looking at is a web page, not a virus. Malwarebytes calls it a browser locker and defines it as “a social engineering technique that gives the illusion of a computer virus and scares people into calling a toll-free number for assistance.” Nothing was installed. Nothing was scanned. It works because a page can imitate a system, and almost nobody can tell the difference between the browser misbehaving and the computer misbehaving.
  3. The design is built for panic, and the only exit is a phone call. An alarm tone, a browser that appears stuck, a red banner, a meaningless error code, one instruction not to shut the machine down — and, in the largest type on the page, a number. No link, no download, no payment form. It works because panic shortens the list of options you can hold in your head, and because calling for help is the responsible-feeling one. Note which action the instruction forbids: restarting is the thing that would close the page.
  4. The call is patient. Seventeen minutes on average, in the Stony Brook recordings. He asks permission, waits, uses your name. It works because urgency would break the illusion — real support is calm, so the performance is calm, and every minute you stay invests you further in the premise that there is a problem to solve.
  5. The caller never asks you to trust him. He asks you to trust the brand already on your screen. He confirms what the page said. He gives you a case number. It works because there is no claim for you to disbelieve: he is not introducing himself as an authority, he is presenting himself as an employee of one you already accept.
  6. The charge is sized to be paid, not questioned. Around $290 on average in the recordings; Malwarebytes documented one operation presenting “support plan” invoices of $195 to $345. It works because that range sits below the threshold where people demand paperwork, and by then you have spent seventeen minutes being helped.
  7. Then the personas stack, and the amounts change. Support hands off to your bank, which says a foreign hacker has reached your accounts and the money must be moved somewhere safe, and then to a federal agency. It works because each new caller appears to independently confirm the last, and because the instruction not to explain the real reason removes the one person who would have stopped it — the teller, the son, the neighbour.

Who is on the other end, and what they are actually selling

Not a hacker. A call centre with a script, a rota and a per-call cost of goods.

In February 2026 a federal court in North Carolina sentenced three men in an international tech-support fraud scheme, and the court record lays the business out with unusual clarity. There is not one criminal in it. There are three industries stacked on each other.

At the bottom, the people who make and publish the pop-ups — the ones that, in the Justice Department’s words, “suddenly appeared on victims’ screens and froze their computers” and “instructed victims to call the number in the pop ups.”

In the middle, a broker who sold the calls those pop-ups produced. Telephone calls, as a commodity, by the batch. He moved more than $20 million worth.

Above him, the routing: a platform that took a call coming off a pop-up and handed it to whichever call centre had paid for it, charging per routed call. It routed approximately 15 million calls.

At the end of the line, the call centres, where you find the sentence the case turns on. According to the Justice Department, the operators who answered “misrepresented themselves as Microsoft”, and one operation in the chain defrauded thousands of victims of more than $7 million. The scheme, the Department says, “tricked millions of U.S.-based computer users into calling the call centers.”

Read that chain again for what is missing from it. Nobody in it needs to know anything about your computer.

Why the pages are disposable and the number is not

Computer scientists at Stony Brook University catalogued 8,698 unique scam-support domains in 250 days, pointing at 1,581 phone numbers. Of those domains, 27% were online for a single day and 43% for three days or less. Malwarebytes extracted more than 16,000 malicious domains from a single operation in a few months.

Reach is not small either. Monitoring just 142 of those pages for two months, the researchers counted 1,688,412 unique IP addresses arriving at them — nearly twelve thousand visitors per page on average, and 138,514 at the busiest one.

Taking a page down therefore costs the operation almost nothing, because the page was never the asset. The phone line is the inventory, and the brand printed on the page is the only component that has to last.

Where the money goes

Money moves in two directions here, and the second one is what makes this an industry rather than a crime.

Upstream, before you pay anything. Every layer in the chain above is paid for the call itself: the publisher for producing it, the broker for selling it, the platform for routing it. None of those payments depends on you buying anything. Your call is already the revenue event for three parties before a technician says hello, which is why the pages keep coming no matter how many are taken down.

Downstream, once you are on the line. Microsoft’s own description of the scam lists how the charge is taken: a one-off fee, a subscription, cryptocurrency or gift cards. The Stony Brook recordings put the average charge at $290.90, and Malwarebytes documented invoices of $195 to $345.

And then the escalation, which is where the billions are. A $290 charge does not produce a two-billion-dollar loss category. The bank persona and the government persona do, by converting a support call into wire transfers, crypto deposits and cash. The FTC records scammers directing victims to deposit money at Bitcoin ATMs and to hand bundles of cash or gold to couriers who come to the door. The FBI counts that as its own line: gold courier scams, about 725 complaints and $311.8 million in 2025, described as couriers collecting cash and precious metals from victims of tech support and government impersonation.

Why those rails and no others. Because of what you can do afterwards. The FTC’s explanation is one sentence: scammers ask for gift cards, wire transfers, bank transfers, cryptocurrency or a payment app because paying that way is “like using cash — once you pay, it’s hard to get your money back.” A card charge has an issuer who owes you a process. A wire has a window measured in hours. A gift-card code read aloud over the phone has nothing at all.

What it adds up to. The FBI logged 47,794 tech-support complaints and $2,134,675,818 in losses in 2025, the third most expensive fraud category of the year behind investment fraud and business email compromise — with $1,040,730,043 of it, close to half, reported by victims over 60.

And what can still be clawed back. The FBI’s Financial Fraud Kill Chain works on speed alone. In 2025, across incidents involving victims over 60, it helped freeze $32,865,655 of the $65,367,648 reported lost, and the most common initiating fraud in those cases was tech support and account takeover. Roughly half the money — but only where somebody called fast.

How to spot it

One sentence does most of the work, and two organisations publish it.

Microsoft: “Microsoft error and warning messages never include a phone number.”

FTC: “Real security pop-up warnings and messages will never ask you to call a phone number.”

A warning with a phone number on it is not a warning. It is an advertisement. The test needs no technical knowledge, and it does not degrade: if the screen wants you to dial, it is selling you something.

Five more checks, each with the thing you actually do.

  1. Unsolicited contact about your computer is the tell, whatever the channel. Test: ask whether you started this. The FTC: “Legitimate tech companies won’t contact you by phone, email, or text message to tell you there’s a problem with your computer.” Microsoft’s version: if you did not ask them to, they will not call you.
  2. Verify on a number you already had, never the one you were given. Test: hang up and look the company up yourself. The FTC’s instruction is “hang up and verify” — using a phone number or website you know is real, and not trusting the number or the name they provided. A real support line does not mind being called back.
  3. The payment method is the diagnosis. Test: offer to pay by card, through the company’s own website. Gift cards, wire transfers, bank transfers, cryptocurrency and payment apps are requested because, as the FTC puts it, paying that way is like using cash. Refusal of every reversible method is the answer.
  4. Any instruction to move money in order to protect it is the scam. Test: the FTC’s rule is three words: “Don’t move money to ‘protect it.’” No bank asks for that, and the FBI adds that the US government will never ask for money by wire transfer to foreign accounts, in cryptocurrency, or on gift or prepaid cards. A courier arriving for cash or gold is proof, not procedure.
  5. Secrecy is a symptom. Test: say out loud, to somebody in the room, what you were told to hide. A real bank never asks you to keep the reason for a transfer from your family or from the teller. The FTC’s simplest advice comes before any technical step: “Talk to someone you trust — a friend, a family member, a neighbor.”

Getting off the screen

Nothing on that page needs to be clicked, including anything shaped like a close button, because those belong to the page. Close the browser itself. If the window will not close, make your operating system force the browser to quit, then reopen it without restoring the previous session. It is a page, and a page dies when the browser does.

The FBI’s own list is short: do not click unsolicited pop-ups; do not call a telephone number that appears in one; do not download software at the request of someone who contacted you; and do not give control of your machine to anyone who contacted you first.

What to do if it already happened

In this order, because the order is what limits the damage.

  1. Hang up. Ending the call mid-sentence costs you nothing. There is no consequence, no case number and nobody to apologise to.
  2. Do not move money to protect it, whoever the next caller claims to be, and do not hand cash or gold to anyone who arrives to collect it.
  3. Call your bank on the number printed on your card, not one you were given, and tell them the calls were fraudulent. Ask them to review and hold anything pending, and to flag the destination of any transfer already sent.
  4. Report immediately, because speed is measurable here. In 2025 the FBI’s Financial Fraud Kill Chain helped freeze $32,865,655 of the $65,367,648 reported lost in incidents involving victims over 60. Report to the FBI at ic3.gov — the intake that feeds that recovery process — and to the FTC at reportfraud.ftc.gov, the consumer-protection intake behind the loss data and the enforcement picture.
  5. Report the impersonation to Microsoft at microsoft.com/reportascam. It is the company’s own channel for this, and it feeds the unit that works with national law enforcement — the one that produced the arrests further down this page.
  6. If you paid, contact the card issuer or bank straight away. If you bought gift cards, call the card’s issuer immediately and keep the receipts and the card numbers, because unspent funds are sometimes recoverable.
  7. If you handed over personal information, work through identitytheft.gov for a recovery plan and the affidavit banks accept, and set a fraud alert with the credit bureaus.
  8. Tell someone. In Microsoft’s survey, 59% of people had met one of these. Being targeted is a statistic, not a character flaw, and the entire script exists to keep one person alone on a phone line for seventeen minutes.

Nobody can promise recovery. What the numbers above show is that the window is real and it is short.

How to not be next

  • Memorise the one sentence and nothing else. A real warning never has a phone number on it. It covers every version of this page, in any brand, in any language, forever, and it requires no judgement about what is on your screen.
  • Never dial a number that appeared on a screen. Not a browser, not an email, not a text. Numbers you call should come from the back of a card, a printed statement or a site you navigated to yourself.
  • Practise the exit once, while nothing is wrong. Know how your operating system force-quits an application, and know how to reopen a browser without restoring the last session. Two minutes now removes the panic later.
  • Decide in advance that no money moves in secret. Agree with one person that any unusual transfer gets mentioned to them first. That single rule breaks the persona ladder at the exact point the FBI says it depends on secrecy.
  • Do not assume this is an older person’s problem. In Microsoft’s survey, 12% of 24-to-37-year-olds who engaged lost money, against 2% of people aged 54 and over. Older victims lose far more per person; younger ones get caught more often.
  • Send your parents one sentence this week. Not a lecture, and not a lesson about browsers. A real warning never has a phone number on it. That is the whole conversation.

The numbers, and what they mean

  • The FBI logged 47,794 tech-support fraud complaints and $2,134,675,818 in losses in 2025, the third most expensive fraud category of the year behind investment fraud and business email compromise. Victims over 60 filed 21,333 of those complaints and reported $1,040,730,043 (IC3 2025 Annual Report).
  • Across all categories, people over 60 reported 201,266 complaints and $7.748 billion in 2025, up 59% on 2024, at an average loss of $38,500, with 12,444 individual losses above $100,000 (IC3 2025). The FTC measures the same curve from its own side: reports of older adults losing $10,000 or more to impersonation scams are up more than fourfold since 2020, and the combined losses of people over 60 who lost more than $100,000 rose from $55 million in 2020 to $445 million in 2024 (FTC, August 2025).
  • The FBI’s Phantom Hacker alert states that “almost 50% of the victims reported to IC3 were over 60 years-old, comprising 66% of the total losses” (FBI PSA, 29 September 2023).
  • In Microsoft’s 2021 global survey with YouGov, across 16,254 adults in 16 countries, 59% had some encounter with a tech-support scam and 7% lost money — while 79% said it was unlikely a reputable company would ever contact them that way (Microsoft, July 2021). Knowing is not the same as recognising it while the alarm is sounding.
  • Microsoft’s Digital Crimes Unit traced a network impersonating the company and targeting older adults in Japan, and alerted Japan’s National Police Agency and India’s Central Bureau of Investigation. Investigators searched 19 locations, made 6 arrests and shut down two illegal call centres. Around 90% of the roughly 200 affected people identified were over 50 (Microsoft, June 2025). In the North Carolina case, the three defendants received 30, 40 and 24 months and forfeited $3,711,000 (DOJ, February 2026).

Enforcement can take the room. It cannot take the name, because the operators never owned it. They rent it, for the price of an advertising slot — which is why the raids got better in the same years the losses went up.

Watch the full documentary

The alert, the industry behind the number and the one sentence that ends it are in the documentary: Don’t Call the Number on That Fake Microsoft Alert.

The persona ladder that follows the first call, support to bank to government, is the same borrowed-authority trick used at scale in the celebrity crypto giveaway deepfake. The fee that unlocks nothing appears again in the pig butchering scam and, at pocket-money prices, in the free prize that charges shipping. The instruction to stay on the line, and to tell nobody why, is the same lever pulled in the virtual kidnapping call — there the caller forbids hanging up because one phone call to the right person would end the whole thing. The same borrowed agency name, stamped on a van instead of a screen, certifies a problem that was never there in the air duct cleaning scam. And the same alert, arriving as a text instead of a screen, ends somewhere stranger still: in the fake bank fraud alert nobody touches your device at all — the caller never needs access, because you are the one who moves the money.

Questions people ask

Is the Microsoft security alert pop-up with a phone number real?

No. Microsoft states that its error and warning messages never include a phone number, and the FTC states that real security pop-ups will never ask you to call one. A warning with a number on it is an advertisement wearing a warning’s clothes.

Does that page mean my computer is infected or hacked?

The page proves nothing about your computer. Malwarebytes defines what you are looking at as a browser locker, a technique that gives the illusion of a computer virus in order to make people phone a number. It is a web page, not a scan result.

Where did the pop-up come from if I only visited normal websites?

Through the advertising slot on one of those normal websites. Malwarebytes found that malvertising was almost always an element in the chain, which is why nothing about your browsing history explains it and why blaming yourself for visiting somewhere suspicious is misplaced.

How do I close a fake virus warning page?

Do not click anything inside the window, including anything shaped like a close button, because those belong to the page. Close the browser itself. If it will not close, make your operating system force it to quit, then reopen the browser without restoring the previous session.

Does Microsoft ever call you about a virus?

No. Microsoft’s support pages state that the company does not make unsolicited phone calls or send unsolicited emails to offer technical support or request personal or financial information, and that if you did not ask them to, they will not call you.

I called the number. What should I do now?

Hang up. Do not move money to protect it, which is the FTC’s own instruction. Call your bank using the number printed on your card, then report to ic3.gov, reportfraud.ftc.gov and microsoft.com/reportascam. Speed matters: in 2025 the FBI’s kill chain froze $32,865,655 of the $65,367,648 reported lost by victims over 60.

Why would my bank tell me to move money into a safe account?

It would not. The FBI’s Phantom Hacker alert describes a second caller posing as your bank, telling you a foreign hacker has reached your accounts, instructing you to move the money to a safe account, and telling you not to explain the real reason to anyone. That instruction is the scam identifying itself.

Is this only a scam that catches older people?

No, and the data splits in two directions. In Microsoft’s 2021 global survey with YouGov, 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. But the dollars concentrate in older victims: the FBI recorded $1,040,730,043 of the 2025 category total from people over 60.