Remote access scams: when someone else takes control of your screen

    A pop-up warns that your computer is infected and gives a number to call. Or the phone rings and someone from your internet provider, Microsoft, Amazon or your bank says they have detected a problem. The goal in every version is the same: get you to install AnyDesk, TeamViewer, QuickSupport or similar, and then operate your device while you watch.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    The rule that ends every one of these calls

    No company you have not contacted first will ever phone you about a problem on your computer, and no legitimate organisation ever needs to control your screen to give you a refund, cancel a subscription or secure an account. Those two sentences defeat the entire category.

    Australia's National Anti-Scam Centre put remote access losses near $70 million in 2025, and the same pattern appears in FTC, Action Fraud and Canadian Anti-Fraud Centre data. The losses are large because once a criminal controls the device they can open online banking with the victim's own saved credentials.

    • Microsoft, Apple, Amazon and ISPs do not cold-call about infections
    • A pop-up with a phone number is always fraudulent
    • No refund requires remote access to your device
    • No bank asks you to install software to protect your money
    • Support you did not initiate is not support

    How victims are reached

    Cold calls remain common, especially to landlines and older households, with spoofed caller ID showing a local or official-looking number. Pop-up warnings are the other main route: a full-screen page with alarm sounds, a fake scan and a support number, usually reached through a mistyped address or an advert on a low-quality site.

    Search results are the third route. Criminals pay for or optimise listings for 'printer support', 'router helpline', 'bank customer care' or 'antivirus refund', so people with a genuine problem call a fraudulent number. Take support numbers only from a product's own app, your account page or the paperwork you already have.

    The refund overpayment trick

    This is the most lucrative variant. The caller says a subscription is being refunded, has you log in to your bank while they watch, then edits what you see on the screen or asks you to type an amount, making it appear that they transferred far too much, say £5,000 instead of £50.

    They then plead that the excess must be returned or they will lose their job, and direct you to send the difference by transfer, crypto or gift cards. No money ever arrived. The apparent balance change was a display trick or a transfer between your own accounts, and the money you send is genuinely gone.

    • A 'refund' you did not request is the opening move
    • You are asked to log in to banking while they observe
    • A balance appears to change by an implausible amount
    • Emotional pressure: they will be fired, it is your fault
    • Repayment demanded by transfer, crypto or gift cards

    How to shut it down mid-call

    Disconnect the device from the internet, by turning off Wi-Fi or unplugging the cable. That instantly ends their control, regardless of what they are doing. Then hang up: there is nothing to negotiate and no explanation you owe them.

    If a pop-up will not close, do not call the number and do not click anything inside the page. Close the browser through Task Manager on Windows or Force Quit on a Mac, or restart the device. The warning is a web page, not a scan of your computer.

    • Turn off Wi-Fi or unplug the network cable first
    • Hang up without explaining or arguing
    • Never call the number in a pop-up warning
    • Close a stuck pop-up with Task Manager or Force Quit
    • Do not let anyone talk you back into reconnecting

    Cleaning up afterwards

    Uninstall every remote-access tool involved, then restart. Run a full scan with your security software and check for anything that was installed or scheduled during the session. Assume anything visible on screen during the call was recorded, including passwords typed while they watched.

    Change passwords from a different, clean device, starting with email and online banking, and enable two-factor authentication. Contact your bank's fraud line to flag the account and review recent transactions and payees, and check whether any new payment recipient or forwarding rule was added. Our virus removal and identity theft recovery guides cover the full sequence.

    • Uninstall AnyDesk, TeamViewer, QuickSupport or similar
    • Full malware scan and a check of newly installed apps
    • Change email and banking passwords from a clean device
    • Turn on two-factor authentication everywhere
    • Ask your bank to review payees and recent transactions

    Frequently asked questions

    Will Microsoft or Apple ever call me about a virus?

    No. Neither company makes unsolicited calls about infections, and any caller claiming to is a criminal.

    Is AnyDesk or TeamViewer malware?

    No, both are legitimate tools used by real IT teams. The fraud lies in a stranger persuading you to install one so they can control your device.

    They were on my computer but I sent no money. Am I safe?

    Not necessarily. Assume credentials were seen and files may have been copied. Scan the device and change key passwords from a different machine.

    The refund overpayment looked real in my banking app. How?

    Usually by editing what is displayed in the browser or by moving money between your own accounts. Check statements independently rather than trusting what appeared on screen.

    How do I find a genuine support number?

    From the product's own app, your account page, the original receipt or the back of your card. Never from a search result, an advert or a pop-up.