This one’s a really good way to shut them down when they call about infected computers. If they really were getting notifications from your computer about viruses or malware, they should be able to identify the specific computer name/host name/device name.
After reading this story, I realized there’s another flaw in the “Windows support” calls most people miss: If your computer really is sending out notifications it’s infected, where did your phone number come from? In other words, how did they know what phone number to call you at?
There’s millions of computers online every second of the day. There’s over seven billion people in the world. How did they get the phone number of one specific person from the infection notifications sent by one specific computer?
There’s two legitimate ways I can think of where this could happen:
-
You bought your computer from a company like Dell and registered the purchase with them. But in this case, the caller would identify their relationship to that company (the company’s tech support division itself or the subcontractor they hired) and wouldn’t have any problems providing that information.
-
There’s a keylogger installed on your computer.
The second one has some big problems with it:
- Chances are, you’ve entered at least two phone numbers in all the forms you’ve filled out online, so did the caller from “Windows support” go down the list of all the phone numbers sent with the notification until they reached you? Or did they go right to the phone number that shows up most as being the best candidate to call you at?
- Who is more likely to call you if a keylogger is sending out information about your computer: a company that somehow got ahold of the information and wants to help you, or a blackmailer/scammer?
If they keep trying to run the scam past the point where they should give up, ask them this: “How did you match my telephone number to my computer?” You can also try to pin them down and get them to identify the specific way they got the notification. They won’t because it’s a scam.

