Someone Rang Saying They're From Microsoft

Someone Rang Saying They're From Microsoft
Whoever rang you this morning was not from Microsoft. The company does not telephone people about viruses, has no mechanism for detecting a problem on your particular computer, and does not hold your phone number for that purpose.
That single fact settles the entire category, and it is worth knowing plainly rather than half-remembering, because the calls are considerably better than their reputation suggests. The version people picture, a badly recorded voice and an implausible accent, is the version that fails. The one that works is calm, unhurried, faintly bored, and entirely willing to let you go away and think about it.
What the call is actually trying to achieve
There are only really three destinations, whichever story is used to get there.
The first destination is remote access to your machine. The caller talks you through installing a support tool, which is ordinary software that IT departments use legitimately every day of the week. Once it is running they can see the screen and control the machine. From there they can open your banking, move money while showing you a doctored screen, or install something that stays behind long after they have hung up.
That doctored screen deserves a mention of its own, because it is the part people find hardest to believe afterwards. Somebody controlling your computer can edit what a page appears to say. Victims have watched a balance apparently increase by an accidental overpayment, felt obliged to return the difference, and sent real money back against a number that was never there. Nothing at all was wrong with the bank account. The screen was simply being written on by somebody else.
The second destination is simply a payment from you. A fee for fixing the imaginary problem, a refund that requires your card details to process, a subscription you never took out and now need to cancel by confirming your account number.
The third is a transfer, which is the bank version and the most expensive. Your account is compromised, the caller says, and the money needs moving to a safe account while it is investigated. No such thing as a safe account exists. That phrase is almost a signature of this fraud, and hearing it should end the conversation on its own.
The one-line rule
Hang up, then call back on a number they did not give you. Everything else in this article is an explanation of why that one habit works.
Why intelligent people fall for it
Honestly, the assumption that only the gullible get caught is itself part of what makes this work so well.
The caller is doing this all day, every day, from a script that has been refined across thousands of attempts. They know what you will say and they have an answer ready. You, meanwhile, picked up the phone in the middle of something else and have perhaps ninety seconds of attention to give it.
Many callers also know things about you. Your name, your address, which bank you use, sometimes a recent purchase. None of that came from any special access to your accounts. It came from data breaches, bought in bulk, and it is there precisely to make the opening thirty seconds sound informed. Our breach checker will show you whether your details are already circulating in known breaches.
And then there is the pressure, which is applied carefully rather than crudely. Urgency, secrecy, and a reason not to mention it to anybody. In the bank version this is sometimes framed as an internal investigation you must not discuss, which is a lie doing a specific job: it keeps you away from the one person who would say "that sounds like a scam, hang up".
The check that works on all of them
Hang up on them, without any apology whatsoever. Then ring back on a number you already had.
Take it from the back of your bank card, from a statement, from a bill, or from the organisation's website that you navigated to yourself. Never a number the caller gave you, never a number in a text they sent to "verify" themselves, and never by pressing a key to be transferred.
Use a different phone if you have one to hand, or wait a few minutes before dialling. On some older landline setups a caller could hold the line open, so you dialled, heard a convincing dial tone, and reached the same person. That is far less common than it once was, and waiting removes the question entirely.
No genuine organisation will object to this. Your actual bank will tell you it is exactly the right thing to do, and a genuine caller from anywhere will simply wait. Somebody who becomes irritated, or who tells you there is no time for that, has just answered your question.
What would you actually do at 4pm on a Thursday?
Read the script above and it looks obvious. The difficulty is that it never arrives while you are thinking about scams.
It arrives while you are cooking, or driving, or two minutes before a meeting, and the caller is unhurried and knows your address. Would you be certain, in that moment, with a plausible person on the line telling you your account is being emptied right now?
That is why the answer has to be a habit rather than a judgement. A habit still works while you are distracted and irritated and late. Judgement is precisely the thing the call is designed to overload.
The one that catches businesses
There is a version aimed squarely at companies, and it is more targeted than the consumer script.
The caller claims to be from your IT provider, or occasionally from a supplier's accounts team, and often names the right company because that information is on your website. They ask a member of staff to approve something, install something, or read out a code that has just arrived on their phone. That last one matters: a code you are asked to read aloud is the second sign-in step being defeated in real time, and no legitimate caller ever needs it.
The defence here is a rule rather than a judgement, and it needs saying out loud before the day it is needed. Nobody in the business approves an access request, installs a remote tool, or reads out a verification code because of a telephone call, whoever the caller says they are. Anything genuine survives being called back on the number you already hold for that company.
Give people permission to be rude about it, too. The reason this works on staff is not stupidity, it is politeness: a junior member of the team does not want to accuse a caller who claims to be from the company that fixes their laptop. Telling them explicitly that hanging up on such a call is the correct behaviour, and that nobody will mind, removes the social pressure the whole approach depends on.
If it has already happened
Do not spend any time at all feeling foolish about it. These people do this professionally, all day, and you were doing something else entirely.
If you let somebody connect to the machine, disconnect it from the internet. Then, from a different device, change your email password first and your banking second, and turn on a second sign-in step where it is not already on. Ring your bank using the number from your card. Have the computer looked at properly, and work on the assumption that anything typed on it during the call is now known.
If money has moved, ring the bank immediately and then report it to Action Fraud on 0300 123 2040, which is run by the City of London Police and issues a crime reference number. Speed matters a great deal more here than completeness does. (as noted in the August 2024 exposure review).
If it happened at work, tell somebody today rather than hoping. The National Cyber Security Centre (NCSC) makes the same point across its guidance to organisations: the earliest signal anyone gets is usually a person willing to say that something felt wrong, and that only happens where saying so is safe.
Worth telling other people
This is one of the few security topics where passing it on genuinely helps, particularly to older relatives, who are targeted more heavily and considerably more persistently.
Say it as a rule rather than a warning, though. Warnings make people anxious about answering the phone at all, which is miserable and does not help. A rule is easier to live with: nobody legitimate will ever object to you hanging up and calling them back, so that is simply what we do now, every time, for everybody.
It is also worth agreeing in advance what happens if somebody does get caught. Fraud of this kind works partly on shame, and the people most likely to be targeted are often the least likely to admit it happened. If the agreement in your family or your business is that nobody will be told off, you find out on the day rather than three weeks later when the money has gone.
The whole thing reduces to two sentences. Microsoft does not ring about viruses, and no bank will ever ask you to move money to keep it safe. Anybody who says otherwise is lying to you, however calm and reasonable they sound.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Is My Password Actually Safe?
Length beats symbols, and reuse beats both. Here is what actually decides whether a password holds, and what to do about the ones you have.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.