How Tech Support Scams Trap and Exploit Users

TL;DR
Tech support scams work by convincing people that a device is compromised or broken, then directing them to a call center that pressures them to buy fake support. The strongest defenses combine user awareness, detection of suspicious browser behavior, aggressive machine learning models, extended behavioral analysis, and coordinated action against the operators and infrastructure behind these campaigns.
Transcript
Uh, my name is Eric Wahlstrom. I work for the Windows Active Defense team in Microsoft. That's actually the team that builds, uh, things like Windows Defender and Windows Exploit Guard. And recently we've, uh, been spending more time looking at social engineering attacks, uh, trying to figure out how can we, uh, provide more protection for our cust... Read More
Key Insights
- A tech scam is a social engineering attack that falsely convinces users their devices are compromised or broken, directs them to a call center, and uses fear or coercion to sell fake support services.
- The critical transition in a tech scam is the phone call, because getting a target to contact the displayed number moves that person much closer to financial loss and further manipulation.
- Fraudulent lead generation includes unsolicited email, fake antivirus advertising, cold calls, misleading websites, and browser lockup scenarios, while official support websites represent the legitimate end of the support ecosystem.
- Fake antivirus products can provide no benefit at best and create a serious problem at worst, making unfamiliar security software advertisements another potential route into fraudulent support operations.
- Microsoft found that about two out of three surveyed consumers had encountered these scams through cold calls or browser lockups, and about 15 percent of affected respondents ultimately paid.
- Typical reported losses range from $250 to $450, but individual losses can be far higher, including a $1,200 example and a case in which an entire €89,000 bank account was drained.
- Microsoft receives about 13,000 scam reports during a typical month, but the company believes this substantially understates the problem because finding and completing its reporting process requires considerable effort.
- Effective disruption requires more than occasional education or site blacklisting, with the described approach emphasizing aggressive machine learning models, extended behavioral analysis, attack-chain awareness, blocking, law enforcement, and broader security-industry participation.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is a tech support scam?
A tech support scam is a social engineering attack designed to make users believe that a device is compromised or broken. The scam directs victims to a call center, where operators frighten or coerce them into purchasing fake support services. Unlike an attack that necessarily exploits an operating-system flaw, it primarily succeeds by manipulating the user's perception and behavior.
Q: How do tech support scams persuade people to call?
Tech support scams present alarming claims that appear connected to a trusted technology company or security product. Examples include fake Microsoft support interfaces, warnings about spyware or pornographic content, unsolicited emails, cold calls, and browser lockups. These mechanisms repeatedly display or promote a telephone number, attempting to convince the target that calling it is the necessary response to an urgent device problem.
Q: Why is calling the displayed support number dangerous?
Calling the displayed number moves the victim deeper into the scam's attack chain. The warning page or initial message creates fear, while the call center provides a person who can continue applying pressure and steer the target toward purchasing fake services. The presentation states that once scammers get someone on the phone, that person is much closer to a harmful outcome.
Q: How common are tech support scams according to Microsoft?
A Microsoft survey conducted a couple of years before the presentation found that about two out of three contacted consumers said they had been involved in one of these scams, either through a cold call or a browser lockup scenario. About 15 percent paid. Microsoft also receives roughly 13,000 reports in a typical month, although it considers that count substantially lower than the true scale.
Q: How much money can victims lose to tech support scams?
When victims lose money, the typical amount described in the presentation ranges from $250 to $450. The losses can become much larger, however. One later example involved about $1,200, some callers from the European Union reported losing thousands of dollars, and one cited victim had an entire bank account containing €89,000 drained.
Q: Why does Microsoft consider tech support scams its responsibility?
Microsoft identifies several reasons to address the problem even though the scammers are not Microsoft and may not exploit a Windows flaw. Victims associate the experience with Microsoft's brand, and later contact legitimate support for help reversing the damage, creating a major support cost. In addition, 87 percent of surveyed people believed Microsoft and similar companies were responsible for fixing the problem.
Q: What action has Microsoft taken against tech scam operators?
Microsoft's Digital Crimes Unit tracks malicious actors involved in these scams. At the time described, Microsoft had identified about 300 such actors and completed 46 law enforcement actions. The presentation characterizes this as significant because scam organizations can be small, concealed, and overseas, creating a high practical threshold for pursuing formal enforcement against them.
Q: How can the security industry disrupt tech support scams?
The proposed response combines improved awareness of the scam attack chain with technical detection and broader coordinated action. The description specifically identifies aggressive machine learning models and extended behavioral analysis as ways to identify and block attacks. It also calls for the wider security industry to disrupt these threats, moving beyond occasional educational campaigns or the blacklisting of individual sites.
Summary & Key Takeaways
-
Tech scams are social engineering attacks rather than conventional exploits. Fraudulent warnings, unsolicited calls, fake antivirus promotions, and browser lockups create fear by claiming that a device contains spyware, pornography, or other threats. The intended result is a phone call, which moves the victim deeper into a coercive sales process for fake support services.
-
Microsoft's survey found that about two out of three contacted consumers had encountered a scam through a cold call or browser lockup, and about 15 percent paid. Typical losses ranged from $250 to $450, although reported cases included $1,200, thousands of dollars, and one drained bank account containing €89,000.
-
Microsoft receives about 13,000 reports in a typical month, despite its reporting page being difficult to find. Its Digital Crimes Unit had identified roughly 300 malicious actors and completed 46 law enforcement actions. The proposed broader response combines awareness, machine learning, behavioral analysis, blocking, investigation, and industry participation in disrupting scam operations.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator