
Tech support scams don't just target consumers. Small businesses can also receive fake support calls, alarming pop-ups, phishing emails and offers for bogus IT services designed to steal money, credentials or access to business devices.
Here's how common tech support scams work, the warning signs to watch for, and what to do if you or an employee falls for one.
Scammers may reach business owners and employees through:
Whatever the method, the goal is to get you to pay for fake support, disclose sensitive information, install malicious software or give the scammer remote access to a business device.
You receive an unexpected call from someone claiming to be from Microsoft, Apple, or another well-known tech company. They warn that your computer or business network is infected with a dangerous virus or experiencing security issues. The caller pressures you to give them access or install remote access software, which allows them to steal your data.
Red Flags:
How to Protect Your Business:
Scammers lure you with "free" software trials or IT services. To access the offer, you're asked to enter your credit card details for verification. Later, you discover hidden fees, automatic charges, contract scams or malware installed on your device. Other times, scammers pose as tech consultants or service providers, offering to audit your existing IT contracts or promising huge savings on support plans. If you sign up, you may be locked into expensive, unnecessary services or even fake contracts that deliver nothing.
Red Flags:
How to Protect Your Business:
A scammer contacts you, claiming they've detected ransomware on your business network. They offer an immediate "fix" for a fee, insisting that if you don't act fast, you'll lose all your data. However, they often provide no proof of any actual infection—just fear tactics to pressure you into paying.
Red Flags:
How to Protect Your Business:
Related: Small Business Ransomware: What You Need to Know and How to Stay Safe
If you've already interacted with a tech support scammer, acting quickly to minimize damage and prevent further harm.
1. Disconnect Your Device – If you granted remote access to a scammer, immediately disconnect your computer or phone from the internet to cut off their control.
2. Change Your Passwords – If you shared login credentials or suspect malware, change your passwords for all business accounts, especially banking, email, and software services.
3. Scan for Malware – Run a full security scan using a trusted cybersecurity solution to detect and remove any malware the scammer may have installed.
4. Contact Your Bank – If you made a payment, contact your bank or credit card provider immediately to dispute charges and request a refund. If you paid via gift card or cryptocurrency, report the scam to the provider, but note that recovery may be difficult.
5. Report the Scam – Notify the relevant authorities:
6. Inform Your Employees – If you run a business, educate your team about what happened to prevent others from falling for similar scams.
Related: Should Small Business Owners Get Cyber Insurance?
Bitdefender Ultimate Small Business Security helps protect your business devices, accounts and employees against phishing, scams, malware, ransomware and other online threats, while giving you visibility over your business security from one dashboard.
It also includes Scam Copilot, a scam detection and prevention tool adapted to the types of scams targeting small businesses. Employees can use it to check suspicious messages, links, QR codes and other potential scams and get guidance when something doesn't look right. This can be particularly useful when a supposed IT provider, vendor or other trusted business contact unexpectedly asks them to click a link, share information or take urgent action.
Try Bitdefender Ultimate Small Business Security free for 30 days. No credit card required.
Related: Top 10 Scams Targeting Very Small Businesses: How to Stay Safe and What to Do If You're Scammed
A tech support call may be a scam if it is unexpected and the caller claims there is an urgent problem with your computer, account or business network. Be especially cautious if they ask you to install remote-access software, share passwords or verification codes, or make an immediate payment. Hang up and contact your IT provider or the company directly using contact information you know is legitimate.
Be suspicious of unsolicited calls claiming that Microsoft, Apple or another technology company has detected a virus or security problem on your device. Don't use phone numbers, links or contact details provided by the caller. Instead, contact the company through its official website or speak to your trusted IT provider.
Disconnect the affected device from the internet to cut off remote access. Contact your trusted IT or security provider, scan the device for malware and change passwords for accounts that may have been exposed. If the scammer accessed banking or payment information, contact your bank or card provider immediately.
Yes. If you install software at a scammer's request or give them remote access, they may be able to install malware, steal business information, change security settings or access your accounts. Never install remote-access software following an unsolicited support request without first verifying who is contacting you.
Set clear rules for how employees receive and verify IT support. Employees should know who provides legitimate support, how that provider normally contacts them and what to do with unexpected requests. Train your team not to share passwords or MFA codes, install unfamiliar software or give someone remote access without verifying the request first.
tags
Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.
View all posts