What is changing now
The current pattern.
Official guidance describes two recurring entry points: a false security warning that claims a device is infected, and a fake subscription-renewal or refund message. Both can lead to remote-access software, staged banking screens, gift-card or crypto payments, and instructions to hide the activity from family or bank staff.
How it works
Confidence first, then pressure.
A browser page, advertisement, call, email or text claims that a trusted technology company detected a virus, charge or account problem. The warning is designed to make the displayed number feel like the only safe route, even though a website cannot reliably diagnose a device through a dramatic pop-up.
Once connected, the caller asks the user to install remote-control software or visit a support page. They may open normal system tools and misrepresent harmless entries as evidence of compromise. With screen access, they can observe credentials, alter what appears in a browser or persuade the user to sign in to banking.
Refund variants create a fake overpayment on screen and ask the victim to return the difference. The supposed refund exists only in the display the scammer controls. Payment is then requested by transfer, gift card, cryptocurrency, cash collection or another method that is difficult to reverse.
Worked example
A realistic pattern, separated into evidence.
This composite example is educational. It does not describe a real person or reproduce a live malicious message.
A renewal email turns into a refund emergency
- 01The opening
An email says an expensive antivirus subscription renewed today and provides a number for cancellation. The recipient does not recognise the purchase and calls quickly to stop the charge.
- 02The escalation
The agent asks to connect to the computer to process a refund, opens online banking and claims to have returned ten times too much. They instruct the customer to repay the difference immediately and not mention the error to bank staff.
- 03The decision point
The message created the problem and supplied the only route to fix it. Remote access, a bank login, an alleged overpayment and secrecy are separate control tactics that all benefit the caller.
Warning signs
Reasons to stop and verify.
- A browser pop-up that displays a support number and prevents ordinary navigation
- An unexpected call claiming a known company detected a problem on the device
- A subscription-renewal notice that demands a phone call within hours
- A request to install screen-sharing or remote-control software
- Instructions to open banking, move money or hide the reason for a payment
- Gift cards, cryptocurrency, wire transfer or cash requested for support or a refund
Independent verification
Test the request without using its evidence.
These checks deliberately move the decision away from the person, link, number or account that introduced the request.
- 01
Check whether the claimed event exists
Use the real software account, app-store subscription list or bank statement. Do not rely on an invoice image or balance shown during a remote session.
- 02
Find support from a clean route
Use help built into the device or software, or type the vendor’s official domain. Avoid numbers in pop-ups, unsolicited messages and paid search advertisements.
- 03
Refuse remote control for an unsolicited problem
A company that contacts you unexpectedly has not earned device access. End the conversation before installing anything or sharing the screen.
- 04
Verify money on a separate device
If a caller claims money moved, sign in from another trusted device or call the bank. Do not let the remote operator interpret the balance for you.
Safer response
Move the decision outside the contact.
- 01
Close the warning
Use the browser or operating-system controls to close the page. Do not call, click or download from the alert.
- 02
Use trusted security tools
Update the device and run its established security scan. Seek help from a provider or technician you chose independently.
- 03
Keep banking separate
Never open financial accounts while an unknown person can see or control the device.
- 04
Treat secrecy as a stop signal
A legitimate technician will not tell you to mislead a bank, buy gift cards or conceal a support payment.
If you already acted
Protect access and contact the real provider.
- Disconnect the affected device from the internet and end the remote session.
- From another trusted device, contact the bank and secure email, financial and other important accounts.
- Remove the remote-access tool, update the device and run a full security scan before sensitive use.
- Review account sessions, forwarding rules, recovery details, payees and transactions for changes.
- Preserve the message, phone number, payment records and software name, then report the incident locally.
Sources
Official guidance used for this article.
Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.