Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Person assessing a remote-support request and checking the official channel on a separate device
Editorial illustration

Support impersonation guide · 12 min

Respond to fake technical support without worsening the incident.

An alarming pop-up, apparently official call or chat message may ask you to install a support tool. Break the unverified channel first, then determine whether access, data or payment has been exposed.

Published 26 September 2026Updated 7 October 2026

At a glance

Four rules for a useful review.

  • Never use the number in an unexpected alert.
  • Check support inside the official app or a website opened separately.
  • If a remote session started, contact the IT team or a trusted professional promptly.
  • Separate installation, account access, data disclosure and payment to guide the response.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Stop the request

    Do not follow the link, call the displayed number or give a sign-in code or password. If already speaking to someone, end the call without arguing about their identity.

  2. 2

    Return to a known service

    Open the official application or website yourself, or use contact details already held. Ask whether a support case exists and whether the proposed process matches their normal practice.

  3. 3

    Establish what was granted

    Record whether you only saw an alert, opened a link, installed software, shared a screen, entered a code, sent a file or paid. Each action changes the checks required.

  4. 4

    Contain granted access

    If someone could control the device, ask the IT team or a trusted professional for help. End the unverified session, avoid using that device for sensitive password changes and have accounts and installed programs assessed.

  5. 5

    Protect accounts and payments

    From a trusted device, revoke relevant sessions and change affected credentials. If money or banking details were shared, contact the bank immediately through its official channel.

An on-screen warning does not identify its author

A web page can imitate a system warning and display a support number. A caller may name software you really use. Those details do not establish a mandate or prove a fault exists.

Start verification through a channel you select yourself. Do not authorise software installation or remote control merely because a screen says immediate action is required.

Establish the scope before restoring service

Seeing a message is different from opening a remote session. Record the time, installed tool, signed-in accounts, files opened and actions observed. A short timeline helps a professional find relevant traces.

Immediately deleting a program may remove useful evidence without proving the device is safe. Coordinate assessment with the responsible team, especially for a work device.

Re-establish a trusted channel

After the technical review, check mail forwarding rules, authorised devices and sessions, and accounts used during the exchange. Warn relevant people if messages may have been sent from an affected account.

Keep the URL, displayed number, receipts, timeline and software names without publishing personal data. Reporting steps depend on the harm observed and the territory involved.

What to check and what to record

Use this grid to turn the method into a reviewable case file. A missing item remains an open question. The interpretation limit prevents a finding from becoming an unsupported conclusion.

Topic-specific checks
CheckUseful recordInterpretation limit
Contact originChannel, time, displayed number and remote-access request.Company names and caller numbers can be spoofed.
Remote accessSoftware, session and observed actions without reusing the supplied link.Closing a window may leave an installed agent.
Follow-upVerified provider, exposed accounts and possible payments.Do not pay another intermediary promising guaranteed recovery.

Common pitfalls

Four shortcuts that weaken the result.

Calling the pop-up number

The number may be part of the scam even when the warning looks technical.

Sharing a one-time code

A sign-in code can let a third party open an account without installing software.

Continuing on the exposed device

A device controlled by someone else is a poor place to change sensitive credentials.

Resetting before assessment

A premature reset may make it harder to establish which accounts and data were affected.

Practical questions

Frequently asked questions.

Is a warning on a website a system alert?

Not necessarily. Close the page without calling its number, then check the device through your usual tools and channels.

Must I immediately unplug the device?

If unauthorised remote control is active, interrupt the connection with help from your IT team when possible. The exact action depends on current activity and evidence needs.

What if I paid the fake support provider?

Contact the bank or payment service promptly through its official channel, keep the receipt and exchanges, and follow the relevant dispute and reporting steps.

Public references

Cybermalveillance.gouv.fr — fake technical support. French public guidance on first actions, remote access and payments.

Editorial scope

Published by Internet Intelligence Service on 26 September 2026. Last content update: 7 October 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.

Find primary portals and their limitations

Further reading

Editorial resources on other sites