Fake Microsoft Security Alert: The Phone Number Is the Scam
Nothing is infected. The full-screen alert is a web page delivered through an ad slot, and the phone number is the product being sold. Microsoft states that its error and warning messages never include a phone number. The FTC states that real security pop-ups never ask you to call one.
Key facts
- they never include a phone number
- Microsoft's own rule about its error and warning messages
- Microsoft, Protect yourself from tech support scams
- they will never ask you to call a phone number
- The FTC's rule about genuine security pop-ups
- FTC Consumer Advice, How To Spot, Avoid, and Report Tech Support Scams
- 47,794 complaints and $2,134,675,818
- Tech support fraud reported to the FBI in 2025, the third most expensive fraud category of the year
- FBI Internet Crime Complaint Center, 2025 Annual Report
- 21,333 complaints and $1,040,730,043
- Share of that category reported by victims over 60
- FBI Internet Crime Complaint Center, 2025 Annual Report
- $32,865,655 of the $65,367,648 reported lost
- Money frozen by the FBI's Financial Fraud Kill Chain in 2025 incidents involving victims over 60
- FBI Internet Crime Complaint Center, 2025 Annual Report
- almost 50% of victims were over 60, and 66% of total losses
- Age profile of victims in the FBI's Phantom Hacker alert, where tech support, bank and government personas are layered
- FBI Internet Crime Complaint Center, Phantom Hacker PSA, 29 September 2023
- approximately 15 million calls
- Calls routed to fake support call centres by a single platform charging per call, in a case sentenced in a federal court in North Carolina
- U.S. Department of Justice, February 2026
- more than $20 million in sales
- Pop-up call leads sold to call centres by one broker in the same case, with sentences of 30, 40 and 24 months and $3,711,000 forfeited
- U.S. Department of Justice, February 2026
- 17 minutes and $290.90
- Average length of a fake support call, and average charge, across 60 calls recorded by researchers
- Stony Brook University, Dial One for Scam, NDSS 2017
- 8,698 domains
- Unique scam-support web domains found in 250 days, with 43% online for three days or less
- Stony Brook University, Dial One for Scam, NDSS 2017
- 59% of 16,254 adults
- Adults surveyed in 16 countries who had an encounter with a tech support scam, of whom 7% lost money
- Microsoft and YouGov, Global Tech Support Scam Research, 2021
- 12% of 24 to 37 year olds
- Age group most likely to lose money in that survey, against 2% of people aged 54 and over
- Microsoft and YouGov, Global Tech Support Scam Research, 2021
Nothing is infected. The full-screen alert is a web page delivered through an ad slot, and the phone number is the product being sold. Microsoft states that its error and warning messages never include a phone number. The FTC states that real security pop-ups never ask you to call one.
Nobody hacks Microsoft to run this. They borrow the name. Microsoft is the company being robbed here too: it publishes the rule that ends the scam and pays an investigations unit to chase the people wearing its brand.
How it works
- The page arrives through an ordinary website. Malwarebytes found that “malvertising was almost always an element in the chain” — the alert is served through the advertising slot of a site you had every reason to trust. You did not go looking for it, and you did not visit anywhere suspicious.
- What you are looking at is a web page, not a virus. Malwarebytes calls it a browser locker and defines it as “a social engineering technique that gives the illusion of a computer virus and scares people into calling a toll-free number for assistance.” Nothing was installed. Nothing was scanned.
- The design is built for panic, not information. An alarm sound, a browser that appears completely stuck, a red banner, an error code that means nothing, and one instruction not to shut the computer down. Malwarebytes noted that this combination “triggers panic for many people.” The largest element on the page is the phone number, because that is what the page is for.
- The call is patient. Researchers at Stony Brook University recorded 60 of these calls end to end. The average call ran 17 minutes, and the average charge was $290.90. Nobody is in a hurry on the other end. Time is what converts a frightened caller into a paying one.
- The caller never asks you to trust him. He asks you to trust the brand already on your screen. He confirms what the page said. He gives a case number. Every sentence borrows credibility from a name he has nothing to do with.
- The number is an industry, not a person. A case sentenced in a federal court in North Carolina in February 2026 laid out the layers: publishers who place the pop-ups, a broker who sold the resulting calls as leads and generated more than $20 million in sales, and a platform that routed approximately 15 million calls to call centres overseas, charging per call. Those call centres, the Justice Department said, “misrepresented themselves as Microsoft.” One company in the chain defrauded thousands of victims of more than $7 million.
- The pages are disposable and the number is the asset. The Stony Brook team found 8,698 unique scam-support domains in 250 days, with 43% online for three days or less. Taking a page down costs the operation almost nothing. The phone line is the inventory.
- Then the impostors stack. The FBI’s Phantom Hacker alert describes the escalation: the tech-support persona hands off to someone claiming to be your bank, who says a foreign hacker has reached your accounts and that the money must be moved to a safe account. The alert notes that this caller instructs the victim not to tell anyone the real reason for moving the money. A third persona claims to be from a federal agency, with letterhead to match.
This article stops at the phone call, which is where the decision is still yours.
Key facts
- The FBI logged 47,794 tech-support fraud complaints and $2,134,675,818 in losses in 2025, making it the third most expensive fraud category of the year, behind investment fraud and business email compromise (IC3 2025 Annual Report).
- Victims over 60 filed 21,333 of those complaints and reported $1,040,730,043 — close to half the money in the whole category (IC3 2025).
- The FBI’s Phantom Hacker alert states that “almost 50% of the victims reported to IC3 were over 60 years-old, comprising 66% of the total losses” (FBI PSA, 29 September 2023).
- In Microsoft’s 2021 global survey with YouGov, across 16,254 adults in 16 countries, 59% had some encounter with a tech-support scam and 7% lost money. The age split is not what people expect: 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. And 79% said it was unlikely a reputable company would contact them that way (Microsoft, July 2021). Knowing is not the same as recognising it while the alarm is sounding.
- Microsoft’s Digital Crimes Unit alerted national law enforcement to one of these operations, which searched 19 locations, made 6 arrests and shut down two illegal call centres. Around 90% of the roughly 200 affected people identified were over 50 (Microsoft, June 2025).
- In the North Carolina case, the three defendants received sentences of 30, 40 and 24 months and forfeited $3,711,000 (DOJ, February 2026).
Enforcement can take the room. It cannot take the name, because the operators never owned it. They rent it, for the price of an advertising slot.
How to spot it
One sentence does most of the work, and two organisations publish it.
Microsoft: “Microsoft error and warning messages never include a phone number.”
FTC: “Real security pop-up warnings and messages will never ask you to call a phone number.”
A warning with a phone number on it is not a warning. It is an advertisement.
Four more checks:
- Unsolicited contact about your computer is the tell, whatever the channel. The FTC: “Legitimate tech companies won’t contact you by phone, email, or text message to tell you there’s a problem with your computer.” Microsoft’s version: if you did not ask them to, they will not call you.
- The payment method is the diagnosis. Gift cards, wire transfers, bank transfers, cryptocurrency and payment apps are requested because, as the FTC puts it, paying that way is “like using cash — once you pay, it’s hard to get your money back.”
- Any instruction to move money to protect it is the scam. The FTC’s rule is three words long: “Don’t move money to ‘protect it.’” The FBI adds that the US government will never ask you to send money by wire transfer to foreign accounts, in cryptocurrency, or on gift or prepaid cards.
- Secrecy is a symptom. A real bank never asks you to hide the reason for a transfer from your family or from the teller.
Getting off the screen. Nothing on that page needs to be clicked, including anything shaped like a close button, because those belong to the page. Close the browser itself. If the window will not close, make your operating system force the browser to quit, then reopen it without restoring the previous session. And the FTC’s simplest instruction, which works before any of the technical ones: “Talk to someone you trust — a friend, a family member, a neighbor.”
What to do if it already happened
- Hang up. Ending the call mid-sentence costs you nothing.
- Do not move money to protect it, whoever the next caller claims to be.
- Call your bank on the number printed on your card, not one you were given, and tell them the calls were fraudulent. Ask them to review and hold anything pending.
- Report immediately, because speed is measurable here. In 2025 the FBI’s Financial Fraud Kill Chain helped freeze $32,865,655 of the $65,367,648 reported lost in incidents involving victims over 60. Report to the FBI at ic3.gov and to the FTC at reportfraud.ftc.gov.
- Report the impersonation to Microsoft at microsoft.com/reportascam. It is the company’s own channel for this, and it feeds the unit that works with law enforcement.
- If you paid, contact the card issuer or bank straight away. If you bought gift cards, call the card’s issuer immediately and keep the receipts and the card numbers, because some funds are recoverable while they are unspent.
- If you handed over personal information, work through identitytheft.gov and set a fraud alert with the credit bureaus.
- Tell someone. In Microsoft’s survey, 59% of people had met one of these. Being targeted is a statistic, not a character flaw, and the entire script exists to keep one person alone on a phone line for seventeen minutes.
Watch the full documentary
The alert, the industry behind the number and the one sentence that ends it are in the documentary, publishing this week on the How the Scam Works channel.
FAQ
Is the Microsoft security alert pop-up with a phone number real? No. Microsoft states that its error and warning messages never include a phone number, and the FTC states that real security pop-ups will never ask you to call one. A warning with a number on it is an advertisement wearing a warning’s clothes.
Does that page mean my computer is infected or hacked? The page proves nothing about your computer. Malwarebytes defines what you are looking at as a browser locker, a technique that gives the illusion of a computer virus in order to make people phone a number. It is a web page, not a scan result.
Does Microsoft ever call you about a virus? No. Microsoft’s support pages state that the company does not make unsolicited phone calls or send unsolicited emails to offer technical support or request personal or financial information, and that if you did not ask them to, they will not call you.
I called the number. What should I do now? Hang up. Do not move money to protect it, which is the FTC’s own instruction. Call your bank using the number printed on your card, then report to ic3.gov, reportfraud.ftc.gov and microsoft.com/reportascam. Speed matters: in 2025 the FBI’s kill chain froze $32,865,655 of the $65,367,648 reported lost by victims over 60.
Why would my bank tell me to move money into a safe account? It would not. The FBI’s Phantom Hacker alert describes a second caller posing as your bank, telling you a foreign hacker has reached your accounts, instructing you to move the money to a safe account, and telling you not to explain the real reason to anyone. That instruction is the scam identifying itself.
Is this only a scam that catches older people? No, and the data splits in two directions. In Microsoft’s 2021 global survey with YouGov, 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. But the dollars concentrate in older victims: the FBI recorded $1,040,730,043 of the 2025 category total from people over 60.
Related
The persona ladder that follows the first call, support to bank to government, is the same borrowed-authority trick used at scale in the celebrity crypto giveaway deepfake. The fee that unlocks nothing appears again in the pig butchering scam and, at pocket-money prices, in the free prize that charges shipping.
Questions people ask
Is the Microsoft security alert pop-up with a phone number real?
No. Microsoft states that its error and warning messages never include a phone number, and the FTC states that real security pop-ups will never ask you to call one. A warning with a number on it is an advertisement wearing a warning’s clothes.
Does that page mean my computer is infected or hacked?
The page proves nothing about your computer. Malwarebytes defines what you are looking at as a browser locker, a technique that gives the illusion of a computer virus in order to make people phone a number. It is a web page, not a scan result.
Does Microsoft ever call you about a virus?
No. Microsoft’s support pages state that the company does not make unsolicited phone calls or send unsolicited emails to offer technical support or request personal or financial information, and that if you did not ask them to, they will not call you.
I called the number. What should I do now?
Hang up. Do not move money to protect it, which is the FTC’s own instruction. Call your bank using the number printed on your card, then report to ic3.gov, reportfraud.ftc.gov and microsoft.com/reportascam. Speed matters: in 2025 the FBI’s kill chain froze $32,865,655 of the $65,367,648 reported lost by victims over 60.
Why would my bank tell me to move money into a safe account?
It would not. The FBI’s Phantom Hacker alert describes a second caller posing as your bank, telling you a foreign hacker has reached your accounts, instructing you to move the money to a safe account, and telling you not to explain the real reason to anyone. That instruction is the scam identifying itself.
Is this only a scam that catches older people?
No, and the data splits in two directions. In Microsoft’s 2021 global survey with YouGov, 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. But the dollars concentrate in older victims: the FBI recorded $1,040,730,043 of the 2025 category total from people over 60.
Read next
Investment fraud Pig Butchering Scam: How the Wrong-Number Text Works
How the pig butchering scam turns a wrong-number text into a crypto account you can never withdraw from, with FBI, DOJ, Chainalysis and UN figures.
Celebrity impersonation Celebrity Crypto Giveaway Deepfake: How It Works
A verified channel, a famous face and an offer to double your crypto. How the celebrity giveaway deepfake works, with FBI, NYDFS, Google and NYT figures.
Free prize or giveaway Free Prize Scam: Why 'Just Pay Shipping' Is the Scam
Why strangers give away a free PS5 or iPhone and then ask you to cover shipping. The advance-fee prize scam explained, with FTC, FBI and BBB figures.