Fake tech support

Pop-up, call or message asking you to use AnyDesk, TeamViewer or remote access.

Information checked : 2026-09-10

Understand / Check / Act

  1. Understand - What this scam is trying to obtain

    Recognise pop-ups, calls and messages asking you to install AnyDesk, TeamViewer or another remote-access tool.

  2. Check - The safe channel to open yourself

    5 useful official sources listed below.

  3. Act - The useful next step

    I already took action

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

What you need to understand

  • Pop-up, call or message asking you to use AnyDesk, TeamViewer or remote access.

The scenario, step by step

  • A call, window or message warns you about a virus, a hack or an urgent banking problem.
  • The fake technician gets you to install a remote control tool, then watches the screen, handles open accounts or tells you what to do.
  • The screen may be hidden while transfers are being prepared; the victim thinks they are following a repair or refund procedure.

What the fraudster is trying to get

  • Control of the device and of sessions that are already open.
  • Passwords, codes and banking approvals.

Common variants

  • Fake Microsoft support.
  • Fake banking technical service.
  • Fake recovery service after an earlier fraud.

Warning signs in your case

  • AnyDesk / TeamViewer / Quick Assist
  • Pretended virus
  • Remote access

What a legitimate service would do

  • Unsolicited support must not take control of the device.
  • A bank does not ask you to install a remote tool to cancel a transaction.

Belgian context and fraud chain

  • The fake support can impersonate Microsoft, a telecom operator, a bank or a cybersecurity service. The product name used may change, but the method stays the same: taking control of a device after unsolicited contact.
  • Tools such as AnyDesk, TeamViewer or Quick Assist have legitimate uses. The risk comes from the context, the permissions granted and the actions taken under the direction of the stranger. The software name alone is therefore not enough to tell.

Decision points to check

  • Close the window or hang up. Do not call the number shown in a browser warning.
  • Do not install a tool and do not give its session ID to someone who contacts you out of the blue.
  • A real support service must be found through the product, the contract or the official website, then contacted by you first.

How to check without taking risks

  • Do not reply to the message and do not use the link, QR code or number it contains.
  • Open the app or official website yourself, then check whether the same request appears in your personal account.
  • If in doubt, contact the organisation using a number found on its official website, a trusted bill or your bank card.

What to do immediately

  • Do not install anything.
  • Do not let anyone control your device.

If you have already clicked, paid or replied

  • Stop the exchange and do not try to negotiate with the sender of the message.
  • Change the access details you shared through the official service. Contact the bank immediately if a payment, card, IBAN or approval is involved.
  • Keep the messages, payment references and observed addresses for reporting purposes, without sharing personal data publicly.

What to do after an incident

  • If a remote session is active, disconnect from the network and end the tool without continuing with sensitive actions.
  • From a trusted device, change the passwords of the accounts that were accessible during the session and contact the bank if the banking screen was visible or handled.
  • Have the installed software and automatic startup mechanisms checked before using the device again for sensitive transactions.

Limits and level of proof

  • The presence of a support tool alone does not prove that fraud took place; the origin of the contact and the actions carried out are what matter.
  • A remote check cannot guarantee that nothing remains on the device. A local technical check may be necessary.

Analysis grid for the fake support call

  • To assess a the fake support call case, separate four questions: who made contact, through which channel, which action was requested and which independent element can confirm it. One reassuring answer does not cancel out the other inconsistencies.
  • The priority signs in this file are: anydesk / teamviewer / quick assist ; pretended virus ; remote access. The combination matters more than a single word, logo or typo.
  • Always compare the message with the real status of the service. For the fake support call, a request that does not appear in the app, the account or the official contact should not be carried out until it is confirmed.

When to ask for immediate help

  • In a the fake support call case, contact the service concerned without delay if a code, approval, payment, card, identity document or remote access has already been shared. Describe the exact action rather than saying only that you were hacked.
  • If no sensitive action has been carried out, keep the useful evidence, block the contact and use the detector to document the signs. This distinction avoids confusing prevention, a confirmed incident and a simple unsolicited message.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the fake support call, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the fake support call depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

Frequently asked questions

How can I check a the fake support call request without clicking?

Do not install anything. Then compare the request with your official account and test the text or link in the StopArnaques detector.

Which signs should make me stop?

Stop the interaction if you see, among others: anydesk / teamviewer / quick assist, pretended virus, remote access. A familiar visual identity never makes up for an unusual request.

Does the detector replace the official check?

No. The detector helps you understand the risk and the signs observed. For a banking, administrative or account-related action, always confirm with the official service through an independent channel.

Useful official sources

Test another suspicious message

I already took action

Prepare my next steps