Start with the pattern, not a guess
Microsoft branding, a Windows-style dialog, or caller ID is not proof of identity. Unsolicited callers and browser warnings that demand payment, gift cards, remote-control software, or secrecy should be treated as impersonation. Close the message and reach support through contact information you independently verified.
Practical checks and decisions
Work from observation to one controlled change at a time. Stop when the next step could risk data, accounts, electrical safety, or additional hardware damage.
Treat unexpected browser warnings and calls as unverified
End the contact and do not use a phone number, link, download, or payment instruction supplied by the warning. Preserve the message, number, receipt, software name, and order of events.
Never call a number shown in a full-screen pop-up
From a separate trusted device, protect email and financial access first. Contact banks and account providers through independently verified channels and change only credentials that may have been exposed.
Use official account and support channels you locate independently
Disconnect unexpected remote access and do not continue arguing with the caller. Record whether the person saw the screen, installed software, opened accounts, received a code, or obtained payment information.
Disconnect and get local help if remote access was granted
Review active sessions, forwarding rules, recovery methods, installed remote tools, and unfamiliar transactions. The response should match the access that actually occurred, not the scammer’s claims.
When a professional diagnosis makes sense
Get help promptly when money, passwords, email, remote access, or unfamiliar account activity may be involved. Preserve a timeline, end contact with the suspected scammer, and make urgent account changes from a separate trusted device.
For hands-on or remote help, explore the service options related to this issue, or browse the Help Center for another guide.
