What Actually Happens After You Call the Fake Tech Support Number
Most people who call a fake tech support number don’t know it’s fake when they call. The number appeared in a search result that looked official. Or the popup alarm said to call it. Or someone forwarded them the number as helpful advice.
What happens next follows a remarkably consistent script. Scammers running these operations are well-trained. They use real-sounding job titles, professional language, and a step-by-step process that mirrors what a legitimate tech support call might look like — right up until it doesn’t.
Here’s the full sequence, step by step.
Step 1: The Professional Greeting
The call is answered promptly, usually with something like “Microsoft Support, this is [name], how can I help you today?” or “Apple Technical Services, you’ve reached the security department.” The caller is calm, friendly, and completely professional.
This is intentional. The opening reassures you. You feel like you’ve reached the right place.
They may ask for your name, your operating system, and what problem you’re experiencing. They take notes. They sound like they’re doing their job.
Step 2: Establishing the “Problem”
Even if you called with a specific concern, the scammer will guide the conversation toward a diagnosis. They’ll ask you to describe your computer, check a few things on your screen, or open programs you’ve never opened before.
A common technique: they ask you to open a program called Event Viewer (on Windows), which displays a log of system events. This log, in normal operation on any computer, contains entries marked “Error” and “Warning.” These are routine. Every computer has them. The scammer tells you these entries mean your computer is infected or compromised.
To you, it looks like proof. To the scammer, it’s a prop they use every single time.
Step 3: The Remote Access Request
Once the “problem” has been established, the scammer tells you they need to take a look for themselves. They’ll ask you to install a piece of software — often AnyDesk, TeamViewer, or a similar program — so they can connect to your computer remotely.
Remote access software, used legitimately, lets a technician see and control your screen to help you troubleshoot. In the hands of a scammer, it gives them access to everything on your device: your files, your saved passwords, and critically, any banking or financial applications you have open or stored.
They may walk you through the installation while keeping you on the phone. It’s presented as routine. Many people at this stage still believe they’re in a legitimate support call.
Step 4: The “Findings”
Once they’re connected, the scammer narrates a performance. They open folders, run fake scans, and show you alarming-looking results. They may say things like “I can see multiple unauthorized access attempts” or “There’s a serious breach in your firewall — I’m surprised you’re still online.”
None of what they’re showing you is real. They’re navigating your computer in a way that’s designed to look serious while building toward the next step.
Step 5: The Payment Request
Here is where the script reveals itself. After explaining the problem in technical-sounding terms, the scammer presents a solution — and a price.
Payment is requested in ways that are untraceable and irreversible: gift cards (read the numbers off over the phone), e-Transfer to an individual, cryptocurrency, or in some cases, wire transfer.
This is the step where many people realize something is wrong. But by this point, they may have already handed over remote access to their device — which is the more serious risk.
Step 6: What Happens With Remote Access
If you gave remote access and didn’t notice the scammer had it, they may continue accessing your device after the call ends, depending on the software. More immediately, while you’re on the phone, they may have been viewing your open banking sessions, saving your passwords, or setting up ways to return.
Some people don’t realize money has moved from their accounts until days later.
The Pattern You Can Recognize
Every step in this sequence has a normal-sounding explanation that keeps you on the line. That’s what makes it effective. But the pattern — professional greeting, alarming “diagnosis,” remote access request, untraceable payment — is consistent every time.
Knowing the script means you can name what’s happening if it happens to someone you care about.
One thing to do: Share this article with someone in your life — a parent, a grandparent, a friend — who you think would benefit from knowing exactly how this scam unfolds. Recognition is the most useful thing you can give someone before they encounter it.
If you’ve experienced this type of scam, report it to the Canadian Anti-Fraud Centre at 1-888-495-8501 or antifraudcentre.ca.