Scam Detective
Scam verdict · Educational pattern check
Scam Detective research desk · Updated August 2026
Yes — scam

A popup says my computer is infected and tells me to call Microsoft — is it a scam?

Yes. Real Microsoft and Apple security warnings never include a phone number, and a web page cannot scan your computer — the siren, the frozen screen, and the countdown are theater to panic you into calling a fake “support” agent who sells a fix and often talks you into handing over remote access. Close the tab (force-quit the browser if it refuses), never call the number, and if you already granted access, disconnect the machine and have it professionally checked.

Educational verdict from documented scam patterns — not a live report. For a 0–100 risk score on the exact link in your hand, run the checker.

Check a URL freeRead the full guide

From the research desk — this pattern is one of those documented in This Week's Scam Wave, in NumbersAugust 19, 2026

Why now · August 2026

Why you’re seeing this now

Because the oldest panic on the internet is having another season. Police departments and the FTC keep re-warning — through August 2026 — about browser-locking pages with sirens and a “call Microsoft” number, now chained into the “phantom hacker” script: the fake technician hands you to a fake bank fraud department, and the fix ends with your savings moved to a “safe account.” Real security warnings never include a phone number, and a web page cannot scan your computer.

The script · As it arrives — browser popup, then the phone call it baits

The exact words they use

Quoted from documented versions of this script so you can recognize it on sight. The words are the scammer’s — the patterns inside them are what give the con away.

“WARNING: Windows has detected (5) viruses on this device. Your personal and financial information is AT RISK.”

“Do not close this window. Call Microsoft Support immediately: +1 (833) 555-0189. Error code: 0x80072f8f.”

“This is a Microsoft-certified technician. I can see the infection. I need to connect to your computer remotely to remove it.”

“The hackers are already inside your bank accounts. Open your banking so I can check while I secure the connection.”

Script language quoted for recognition — if the message in your hand reads like this, you already have your verdict.

The checklist

Five red flags — any one is enough

A phone number in a virus warning — real Microsoft and Apple security alerts never include one. Ever.
A web page claiming it scanned your computer — a page cannot scan anything; the “detection” is a picture.
Sirens, countdowns, and a frozen screen — the “lock” is just a fullscreen browser window staging a panic.
The “technician” wants remote access to your machine or payment for the fix.
The story escalates from a virus to your bank accounts — that hand-off is the phantom-hacker chain starting.
What to do now

Your next three moves

1
Don't call the number. Close the tab — and if the browser refuses, force-quit it (Task Manager on Windows, Force Quit on a Mac). Your files are fine.
2
If you called and granted remote access: disconnect the machine from the internet, have it professionally checked, and change your passwords from a different, clean device.
3
If you paid or shared banking details, contact your bank immediately and report it at reportfraud.ftc.gov.
Instant URL Check · $2, one-time
Holding the actual message? Check the exact link, number, or sender.
Paste it into the instant check — free risk signal in 60 seconds, then the full report for $2: a 0–100 scam risk score, a plain-English verdict, the top 5 red flags found, and a 3-step what-to-do-now list. No subscription.
Run the $2 instant check
Follow-up questions

People also ask

Can Microsoft see a virus on my computer through a web page?

No. A web page cannot scan your machine, and Microsoft does not monitor your device and pop up warnings with a support number. The alert is a webpage wearing a costume.

It showed the real Windows logo and a plausible error code — still fake?

Yes. Logos are copied images and error codes are copied strings; both are free to paste. The phone number is the tell — legitimate security software never asks you to call anyone.

I closed the tab without calling — do I need to do anything?

Usually nothing. A page cannot install software without your cooperation. Run your system's built-in scanner for peace of mind, and clear the tab from your browser history so you don't reopen it.

What is the “phantom hacker” chain?

The popup's fake technician passes you to a fake bank “fraud department,” which warns your money is at risk and instructs you to move it to a “safe account” — which belongs to them. Each hand-off borrows credibility from the last costume.

Related verdicts

People asking this also asked

Is that “Amazon took payment” email a scam?Almost alwaysIs decision-study.org a scam?Treat as data-harvestIs that Wells Fargo / Bank of America fraud call or text real?Verify it yourself
← Browse all 95 answers
$2, one time
No subscription, no account, nothing to cancel.
Verdict in minutes
Full report on screen and as a PDF, usually within minutes.
Honest verdicts
If it looks safe, we say so — a clear “safe” is worth $2 too.
Got a link of your own?

Sixty seconds of checking beats a four-figure mistake.

Paste any URL for a free instant preview — the full 0–100 report is $2, one-time. No subscription.

Check a URL free
Spot the scam before it spots you.
For businesses · $29, one-time
Is someone impersonating your brand?

The costume in these scams — a lookalike domain, a copied storefront, a spoofed sender — is exactly what the brand impersonation audit researches for your company: lookalike domains, typosquats, and copycat sites trading on your name, each with evidence and a risk rating, plus a ready-to-send takedown-request template.

Audit my brand — $29
Free brand scan first — you only pay for the full audit.