Tech Support Fraud
1. Overview
Tech support fraud involves individuals impersonating technicians (service providers, internal IT teams) to gain access to devices, accounts, or sensitive data, often under the pretense of resolving a problem.
2. How the Scam Works
- Initial Contact
- Calls, pop-up windows, or emails claiming to report a critical issue.
- Taking Control
- Convincing the victim to install remote access software.
- Exfiltration or Payment Demand
- Credential theft, malware installation, or requests for payment to “fix” the issue.
3. Key Red Flags
- Unsolicited calls claiming to be from support.
- Requests to install remote control software.
- Threats of immediate consequences if the user does not cooperate.
4. Prevention
- Train users never to grant remote access without verification.
- Establish official support contact procedures (internal numbers and portals).
- Use approved remote access management solutions and log all connections.
5. Response Steps
- Terminate the remote access session and isolate the compromised machine.
- Reset credentials and check sensitive accounts.
- Contact the IT team and report the incident.
6. Summary
Tech support fraud exploits trust in technicians. Verification processes and user training reduce its impact.