Step-by-step method
A reproducible path from question to conclusion.
- 1
Stop the request
Do not follow the link, call the displayed number or give a sign-in code or password. If already speaking to someone, end the call without arguing about their identity.
- 2
Return to a known service
Open the official application or website yourself, or use contact details already held. Ask whether a support case exists and whether the proposed process matches their normal practice.
- 3
Establish what was granted
Record whether you only saw an alert, opened a link, installed software, shared a screen, entered a code, sent a file or paid. Each action changes the checks required.
- 4
Contain granted access
If someone could control the device, ask the IT team or a trusted professional for help. End the unverified session, avoid using that device for sensitive password changes and have accounts and installed programs assessed.
- 5
Protect accounts and payments
From a trusted device, revoke relevant sessions and change affected credentials. If money or banking details were shared, contact the bank immediately through its official channel.
An on-screen warning does not identify its author
A web page can imitate a system warning and display a support number. A caller may name software you really use. Those details do not establish a mandate or prove a fault exists.
Start verification through a channel you select yourself. Do not authorise software installation or remote control merely because a screen says immediate action is required.
Establish the scope before restoring service
Seeing a message is different from opening a remote session. Record the time, installed tool, signed-in accounts, files opened and actions observed. A short timeline helps a professional find relevant traces.
Immediately deleting a program may remove useful evidence without proving the device is safe. Coordinate assessment with the responsible team, especially for a work device.
Re-establish a trusted channel
After the technical review, check mail forwarding rules, authorised devices and sessions, and accounts used during the exchange. Warn relevant people if messages may have been sent from an affected account.
Keep the URL, displayed number, receipts, timeline and software names without publishing personal data. Reporting steps depend on the harm observed and the territory involved.
Common pitfalls
Four shortcuts that weaken the result.
Calling the pop-up number
The number may be part of the scam even when the warning looks technical.
Sharing a one-time code
A sign-in code can let a third party open an account without installing software.
Continuing on the exposed device
A device controlled by someone else is a poor place to change sensitive credentials.
Resetting before assessment
A premature reset may make it harder to establish which accounts and data were affected.
Practical questions
Frequently asked questions.
Is a warning on a website a system alert?
Not necessarily. Close the page without calling its number, then check the device through your usual tools and channels.
Must I immediately unplug the device?
If unauthorised remote control is active, interrupt the connection with help from your IT team when possible. The exact action depends on current activity and evidence needs.
What if I paid the fake support provider?
Contact the bank or payment service promptly through its official channel, keep the receipt and exchanges, and follow the relevant dispute and reporting steps.
Public references
Cybermalveillance.gouv.fr — fake technical support. French public guidance on first actions, remote access and payments.
Editorial scope
Written and reviewed by Internet Intelligence Service on 26 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
