Microsoft support AnyDesk: scam or reality?

First assess what is being requested, which channel was used and what has already happened. Do not use the received link or imposed phone number as the verification channel.

Information checked : 2026-09-10

Critical risk - Point de vigilance : Unsolicited remote control opens up a critical risk.

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

Analysis of the case described

  • AnyDesk is a legitimate tool used here as a way to gain access. The risk comes from the unsolicited contact and the permissions given to the fake support, not from the software name alone.
  • The caller may hide the screen, observe passwords or guide a fake refund while real operations are carried out.

Scam mechanism

  • An unsolicited technical alert pushes you to install a remote control tool.
  • Once connected, the person on the line can see open sessions, hide the screen and guide payments under a false repair pretext.

Why this is dangerous

  • Unsolicited remote control opens up a critical risk.

Warning signs

  • AnyDesk, TeamViewer or Quick Assist
  • Incoming call or pop-up
  • Threat of a virus or a block

What a legitimate service would do

  • A legitimate support service does not call out of the blue to diagnose a virus discovered remotely.
  • A bank does not ask you to install AnyDesk or an equivalent tool to cancel fraud.

Verification protocol

  • Do not install anything during the call and close the windows that show a support number.
  • If Microsoft needs to be contacted, start from the built-in support or the official domain typed in manually.

What to do now

  • Do not install anything and cut off contact.
  • Go back to the official support, typed in by yourself, if needed.

If I already clicked

  • Disconnect the device from the internet.
  • Change your passwords from another device if access was given.

What this sheet allows us to say

  • The wording "Microsoft support AnyDesk" is a search clue, not enough proof on its own. The number, domain, beneficiary and requested action must be checked together.
  • This sheet describes a defensive method. It does not attribute a message to a person or an organisation without verified evidence.

How to use the sources in this sheet

  • The references selected for "Microsoft support AnyDesk" cover the mechanism, the claimed service and the protective steps. They should be read for the process they document, not as automatic proof that every similar message belongs to a confirmed campaign.
  • For the alert "Microsoft support AnyDesk", the first three references are: Febelfin - Fraud through fake technical banking support; FPS Economy - Phone scams; Safeonweb - Stay alert to suspicious calls and SMS messages. Each link is checked separately and an inaccessible source must be removed or replaced.

What would confirm or weaken the risk

  • The risk is stronger if several signs appear together: anydesk, teamviewer or quick assist; incoming call or pop-up; threat of a virus or a block. An irreversible action, an external domain or an unknown beneficiary weigh more than a simple language mistake.
  • For "Microsoft support AnyDesk", the risk is weaker if the same request, with the same reference and the same action, is found in the official space opened manually. This match must be checked without using the received link, number or QR code.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the technical support alert, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the technical support alert depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

What to do now without panic

  • If the technical support alert worries you, choose the next step from the requested action: clicking, paying, sharing a code, installing an app, sending a document or approving account access. Do not rely only on the logo or sender name.
  • When the technical support alert involves an urgent, financial or hard-to-undo action, StopArnaques treats the situation as something that must be checked first. Polished wording, a familiar brand or a realistic amount does not make the request reliable by itself.
  • If you already acted in a case involving the technical support alert, the order matters more than the label: contact the bank, platform or official service first, preserve evidence next, then compare the situation with similar campaigns.

What can be legitimate

  • For the technical support alert, some notifications can be real: a delivery, invoice, administrative document, payment request, security alert or platform message. This is why this page does not claim that every similar message is automatically a scam.
  • The difference in a the technical support alert case is verification. A real request should be visible through the app, portal, customer area or phone number that you open yourself, not only through a link, QR code or number included in the suspicious message.
  • If the official environment does not show the same request about the technical support alert, amount, reference or beneficiary, it is safer to stop and report or verify the case before continuing.

Limits and responsibility

  • For the technical support alert, StopArnaques helps explain signals and choose safer actions, but it does not replace your bank, the police, Safeonweb, the FPS Economy, a platform or the organisation concerned.
  • A result about the technical support alert may remain uncertain when the text is too short, when context is missing or when the fraud uses a new variant. In that situation, slow down, verify independently and avoid any irreversible action.
  • If the technical support alert involves a payment, code, card, identity document, itsme approval, banking app or remote access, the protective action comes first. Do not wait for a perfect label if harm may already be possible.

Keep evidence and report

  • For the technical support alert, keep the message, date, channel, visible sender, neutralised link and useful screenshots. Do not publish personal data or clickable suspicious links on social media.
  • Report the technical support alert to the relevant channel when appropriate, for example Safeonweb for suspicious messages, the platform for account abuse and your bank when money or payment details are involved.
  • This evidence about the technical support alert can also help link a campaign to a case later without storing raw personal data. That matters if the system is to improve without exposing users unnecessarily.

Frequently asked questions

Can an unexpected support caller see that my device is infected?

Not simply from a phone call or pop-up. Do not install remote-access software at their request.

What if remote access is already active?

Disconnect it and remove access from a trusted device. Then review accounts, passwords and bank transactions.

Should I inform my bank?

Yes if banking details, a banking app or payments were visible or used during the session.

Useful official sources

Test another suspicious message

Search for similar campaigns