Had a worrying pop-up, phone call or message about your computer? Tick what happened and I'll tell you how likely it is to be a scam, and exactly what to do next.
Tick anything that happened:
The golden rule: genuine companies never cold-call about your computer, never put phone numbers in pop-ups, and never ask for your passwords. Read more in how to spot and avoid tech scams.
Once you have seen the shape of it, it is very hard to unsee, and that is the best protection there is. Whether it arrives as a pop-up, a phone call, a text or an email, it runs the same way.
Step four is where it becomes certain. A real company that already has your business does not need to ring you out of the blue and ask for remote access to your machine.
First: this happens to careful, capable people every day, and it is designed by professionals to work on exactly the people who think it would not work on them. There is nothing to feel daft about, and the sooner you act the better the outcome.
There is more detail, with real examples of what these look like, in the guide to spotting and avoiding tech scams and pop-ups.
No. Neither company monitors individual computers, neither can see whether yours has a problem, and neither has any way of getting your phone number in that context. An unexpected call claiming to be from Microsoft, Apple, Windows or your internet provider about a virus is a scam without exception. Hang up. You do not owe them a conversation.
Almost certainly not, and the pop-up itself is usually just a web page designed to look like a system warning. Real security software never puts a phone number on screen. Do not ring it, do not click anything inside it, and close the browser; if it will not close, restart the computer. Seeing one of these does not mean anything got onto your machine.
Disconnect it from the internet, then ring your bank from another phone if money or card details were involved, using the number on your card. Change your email password from a different device first, since email is what everything else resets through. Then have the machine checked properly, because remote access software may still be installed and configured to reconnect. Acting within the hour makes a real difference.
It is never normal, and it is one of the clearest signals there is. Gift cards, vouchers, cryptocurrency and direct bank transfers are demanded because they are hard to reverse and hard to trace. No genuine company, and no part of HMRC, the police or your bank, will ever ask to be paid that way. If someone has told you to buy gift cards, stop there.
Usually from data breaches or bought lists rather than anything you did wrong, and a name is often all they have. Knowing your name, address or even the last four digits of a card proves nothing about who is calling; that information circulates widely. Scammers open with it precisely because it makes people relax.
Yes, and it genuinely helps. Action Fraud is the UK's national reporting centre, on 0300 123 2040 or actionfraud.police.uk, and near-misses are worth reporting because they let the police connect numbers, websites and bank accounts across many cases. It takes a few minutes. You can also forward suspicious texts to 7726, which is free.
Opening an email is generally safe. The risk is in what you do next: clicking a link, opening an attachment, or replying. If you clicked a link and then typed a password into the page it opened, change that password now. If you only looked at it and deleted it, you are fine.
No. Nothing is recorded, stored or transmitted. It counts the boxes you tick in your browser and shows a result, and that is the whole of it. Nothing you tick reaches me or anyone else.