The call that asks you to install remote access: how the scam works
Remote access is a genuinely useful tool, which is exactly why it is the centrepiece of the most common fraud aimed at ordinary computer users. The technology is not the problem — the phone call is.
The one rule that ends every version of it
Nobody legitimate contacts you first about a problem with your computer. Not Microsoft, not Apple, not your bank, not your ISP, not "Windows support". They have no way of knowing your machine has a problem and no mechanism to call you about it. An unsolicited contact claiming otherwise is a scam with certainty, not probability.
This applies to every channel: a phone call, a browser pop-up with a number to ring, an email, a text, a message from a hacked friend. If you did not initiate the contact, the contact is the attack.
The script, so you recognise it in progress
- An alarming opening. Your computer is sending error reports; your bank account has suspicious activity; your subscription auto-renewed for a large amount and you can "cancel" by calling. Urgency plus money is the setup.
- Fake evidence. They walk you through commands that look diagnostic and are meaningless. The Windows Event Viewer always shows warnings and errors on a perfectly healthy machine, and they present that as proof of infection.
netstatshows normal connections, presented as intruders. Theassoccommand shows a long identifier they claim is your unique "licence ID" — it is the same on every Windows machine on earth. - The install. They ask you to install a remote access tool. Real, legitimate software — that is the point, because it passes antivirus and looks reassuring.
- The payment. Either a "support fee", or a fake refund flow where they show a bank page they have edited in your browser to look like they sent too much, then ask you to return the difference in gift cards or a transfer. The bank page is not real; nothing was sent.
- The lock-out. If you hesitate, some set a syskey or BIOS password, or simply start deleting files while you watch, to force compliance.
If you are on the call right now
- Disconnect the internet. Physically — pull the Ethernet cable or turn off Wi-Fi. Do not negotiate, do not close windows politely, do not explain. This ends the session instantly and is the only step that matters in the moment.
- Hang up. Do not call back, do not use any number they gave you.
- Do not pay, and do not "return" anything. The refund-overpayment story is fabricated end to end. Money you send is gone and gift card codes are unrecoverable.
- Then start the cleanup below, in that order.
Cleanup, if access was granted
- Uninstall the remote access software they had you install. All of it — some install more than one.
- Change passwords from a different device. Not the affected computer. Email first, because it is the reset path for everything else; then banking, then anything reusing that password.
- Turn on two-factor authentication on email and banking while you are there.
- Call your bank on the number printed on your card, not one from the call. Tell them a remote access scam is involved; they have a defined process for it.
- Check for what was left behind: new user accounts on the machine, scheduled tasks, mail forwarding rules in your email settings. Mail forwarding is the one people miss, and it is how a compromise persists after every password is changed.
- If money moved or you cannot be sure the machine is clean, get local professional help and consider a full reinstall. A machine someone had interactive control of cannot be verified clean by looking at it.
Protecting someone who is a target
Older relatives are disproportionately targeted, and the effective intervention is not a lecture about technology. It is a rule that removes the decision under pressure: agree in advance that they will hang up on any unexpected call about the computer and phone you instead. A pre-agreed action is much easier to follow than judgement while someone is applying urgency.
It also helps to say clearly that you will never be angry about the call, and that you would much rather be phoned about ten harmless ones than not be phoned about the real one. Embarrassment is what keeps people on the line and what stops them reporting it afterwards.
The flip side is that remote access itself is genuinely the best way to help family with a computer problem — when they initiate it and it is you at the other end. See helping a relative remotely for how to do that without teaching habits a scammer can exploit.
More guides
Never put RDP straight on the internet — and what to do instead
Port 3389 is scanned continuously, credential stuffing against it is automated, and it is the most common entry point for ransomware. Four safer ways to reach the same machine.
Why a remote connection will not establish, and how to tell which layer failed
NAT, CGNAT, symmetric NAT and corporate firewalls each break the connection in a different place. A diagnosis order that identifies the layer in a few minutes.
Why the remote cursor lags, and which of the six causes is yours
Network round-trip, upstream bandwidth, encoder delay, frame rate, resolution and relay hops each add lag in a different way. How to tell them apart and what actually helps.
Try RemoteFrames
Install the host on the computer you want to reach, then enter its 6-digit code in any browser. No account — two free 10-minute sessions a day.
Try RemoteFrames