Microsoft’s own guidance on technical-support scams settles the question a jarring pop-up window is designed to short-circuit: “Genuine Microsoft error messages never include a phone number to call.” The Federal Trade Commission says the same rule applies across the industry, regardless of which company’s logo the fake warning borrows. A phone number inside a security alert is not a shortcut to help; it is the scam.
Both organizations describe the same mechanical trick behind the message, and both land on the identical instruction once the trick is explained.
The mechanics behind the pop-up
The FTC’s April 2025 consumer alert describes an urgent pop-up message claiming a problem has been found on the device, appearing without warning, typically while browsing, and often locking the screen or playing an alarm sound to discourage a calm response. The message routinely borrows a recognizable brand, with the FTC noting that scammers “say or suggest it’s from Microsoft, Apple, or Geek Squad” specifically because those names carry built-in trust that a generic warning would not.
The pop-up’s entire job is to compress the time between seeing it and dialing the number printed inside it. A countdown timer, a blaring alert tone or a warning that the device will be “locked” within minutes are common additions, none of which a real operating system or antivirus product uses to communicate an actual security event.
What happens after the call connects
Calling the number does not connect to Microsoft, Apple or Geek Squad; it connects to a call center built for exactly this script. The FTC describes the next step plainly: the person who answers will falsely claim the device is infected and attempt to sell a “solution.” That solution is typically remote access to the machine, a paid “cleanup” service, or both, charged to a card or gift card before the call ends.
Remote access is the highest-stakes part of the exchange. Once a caller is granted control of the device, the fabricated infection becomes almost beside the point — the access itself is the payload, and what happens with it ranges from installing real malware to searching for banking credentials stored in a browser.
The phone number as the reliable tell
Microsoft’s own guidance on avoiding and reporting these scams is unusually direct about the one detail that never appears in a real alert: a phone number. The company instructs people never to call a number listed inside an error message, stating flatly that its own genuine messages never include one. A separate Microsoft support page repeats the instruction for the broader category of unsolicited tech-support contact, whether it arrives as a pop-up, an unexpected phone call, or an email claiming to be from company support staff.
The reasoning holds regardless of which company’s name is attached to the warning. Legitimate security software flags problems inside its own interface — a dashboard alert, an app notification, a scan result — not through a full-screen takeover that also happens to supply a phone number and demand an immediate call. The FTC’s guidance and Microsoft’s guidance converge on the same bright line for that reason: the phone number is not an incidental detail of a real warning that a scammer copied badly, it is the one element a real warning structurally cannot contain.
What to do instead of dialing
Both the FTC and Microsoft recommend the same sequence once a pop-up like this appears. Close the browser window, or force-quit it if it will not close normally, rather than clicking anything inside the alert, including a button that claims to dismiss or fix the problem. Restarting the device typically clears a browser-based pop-up entirely, since most of these alerts are rendered by a malicious or compromised webpage rather than by anything installed on the machine.
If a real concern remains afterward, the FTC’s broader tech-support-scam guidance recommends contacting the software or device maker directly through contact information found independently — a number on the company’s official website, not one supplied by the pop-up — before paying for or agreeing to any remote-access session.
Reporting matters even after nothing was paid. Microsoft’s guidance walks through submitting a report directly to the company when its name has been used in a fake alert, and the FTC directs the same reports to its own fraud-reporting system, since both organizations use the volume and pattern of complaints to identify which call centers and phone numbers are actively running the scheme. A pop-up dismissed without a report tells neither company anything about the number behind it, leaving that same number free to keep appearing in front of the next person who happens to load the wrong page.
The FBI’s Internet Crime Complaint Center has documented the same call-center model behind other impersonation scripts, including ones spoofing “authentic phone numbers, email addresses, employee names, and credentials” of real institutions to make a fraudulent call look legitimate on caller ID — the same spoofing logic that makes a fake tech-support number look, superficially, like it belongs to a real company.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south
- A recalled pill hid a stimulant dose linked to heart attacks and death
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell