Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Person assessing a remote-support request and checking the official channel on a separate device

Support impersonation guide · 12 min

Respond to fake technical support without worsening the incident.

An alarming pop-up, apparently official call or chat message may ask you to install a support tool. Break the unverified channel first, then determine whether access, data or payment has been exposed.

Published 26 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Never use the number in an unexpected alert.
  • Check support inside the official app or a website opened separately.
  • If a remote session started, contact the IT team or a trusted professional promptly.
  • Separate installation, account access, data disclosure and payment to guide the response.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Stop the request

    Do not follow the link, call the displayed number or give a sign-in code or password. If already speaking to someone, end the call without arguing about their identity.

  2. 2

    Return to a known service

    Open the official application or website yourself, or use contact details already held. Ask whether a support case exists and whether the proposed process matches their normal practice.

  3. 3

    Establish what was granted

    Record whether you only saw an alert, opened a link, installed software, shared a screen, entered a code, sent a file or paid. Each action changes the checks required.

  4. 4

    Contain granted access

    If someone could control the device, ask the IT team or a trusted professional for help. End the unverified session, avoid using that device for sensitive password changes and have accounts and installed programs assessed.

  5. 5

    Protect accounts and payments

    From a trusted device, revoke relevant sessions and change affected credentials. If money or banking details were shared, contact the bank immediately through its official channel.

An on-screen warning does not identify its author

A web page can imitate a system warning and display a support number. A caller may name software you really use. Those details do not establish a mandate or prove a fault exists.

Start verification through a channel you select yourself. Do not authorise software installation or remote control merely because a screen says immediate action is required.

Establish the scope before restoring service

Seeing a message is different from opening a remote session. Record the time, installed tool, signed-in accounts, files opened and actions observed. A short timeline helps a professional find relevant traces.

Immediately deleting a program may remove useful evidence without proving the device is safe. Coordinate assessment with the responsible team, especially for a work device.

Re-establish a trusted channel

After the technical review, check mail forwarding rules, authorised devices and sessions, and accounts used during the exchange. Warn relevant people if messages may have been sent from an affected account.

Keep the URL, displayed number, receipts, timeline and software names without publishing personal data. Reporting steps depend on the harm observed and the territory involved.

Common pitfalls

Four shortcuts that weaken the result.

Calling the pop-up number

The number may be part of the scam even when the warning looks technical.

Sharing a one-time code

A sign-in code can let a third party open an account without installing software.

Continuing on the exposed device

A device controlled by someone else is a poor place to change sensitive credentials.

Resetting before assessment

A premature reset may make it harder to establish which accounts and data were affected.

Practical questions

Frequently asked questions.

Is a warning on a website a system alert?

Not necessarily. Close the page without calling its number, then check the device through your usual tools and channels.

Must I immediately unplug the device?

If unauthorised remote control is active, interrupt the connection with help from your IT team when possible. The exact action depends on current activity and evidence needs.

What if I paid the fake support provider?

Contact the bank or payment service promptly through its official channel, keep the receipt and exchanges, and follow the relevant dispute and reporting steps.

Public references

Cybermalveillance.gouv.fr — fake technical support. French public guidance on first actions, remote access and payments.

Editorial scope

Written and reviewed by Internet Intelligence Service on 26 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.