A Pop-Up Told Me My Computer Was Infected. I Called the Number. That Was the Mistake.

A Pop-Up Told Me My Computer Was Infected. I Called the Number. That Was the Mistake.

It happened on a Tuesday afternoon, in the middle of paying bills online. My screen suddenly locked up, a siren sound started blaring from my speakers, and a red warning filled the entire browser window telling me my computer was infected with a virus that was actively stealing my banking information. There was a phone number at the bottom, along with a countdown timer and a logo that looked close enough to a real antivirus company’s branding that I didn’t think twice. My hands were actually shaking when I dialed. Looking back, that panic was the entire point of the design, not an accident, not bad luck on my part, but a deliberate mechanism built to short-circuit careful thinking before it could even start.

The man who answered introduced himself as a senior technician, spoke calmly, and asked me to install a remote access program so he could “see what the virus was doing.” I did it without hesitation, because by then all I wanted was for the siren to stop and for someone competent to tell me my accounts were safe. Once he had access to my screen, he opened my file explorer, pointed to completely normal system folders and processes, and narrated them as evidence of “deep infection,” using technical-sounding language I had no way to verify in the moment. He then told me the removal process would cost $400, payable immediately through a gift card, since their billing system was “temporarily down” for card payments. I remember thinking that detail was odd. I bought the gift cards anyway.

What I didn’t fully understand until later is that while he had remote access to my screen, he wasn’t just showing me things, he was quietly opening my browser’s saved passwords and looking at what accounts I had logged into recently. The $400 gift card charge turned out to be the smaller problem. Within the following week, I noticed login attempts on my email account and a password reset request on an account I hadn’t used in months. The “technician” hadn’t just scammed me for a service fee; he’d used the remote session as a reconnaissance mission, and I’d handed him the tour myself, believing every step of it.

Once I realized what had actually happened, I disconnected my computer from the internet entirely and used a different, uncompromised device to change every password I could remember, starting with email and banking, and enabling two-factor authentication everywhere it was available. I ran a full antivirus scan from a legitimate, independently downloaded source, not anything the “technician” had installed, and had a knowledgeable friend check for any remote access software or unfamiliar programs left behind. I reported the gift card charge to the retailer, though gift card scams are notoriously difficult to reverse once the codes have been used, and I filed a report with the FTC and with the company whose branding had been impersonated in the fake pop-up.

The thing that took longest to shake wasn’t the $400. It was the discomfort of knowing a stranger had spent twenty minutes inside my computer, watching me, while I thanked him for his help. Legitimate antivirus companies do not display phone numbers in browser pop-ups, do not use countdown timers or sirens, and will never ask you to pay for a virus removal with gift cards. I know all of that now with total clarity. In the moment, none of it crossed my mind, because the entire pop-up was engineered to make sure it wouldn’t.

If a warning like this ever appears on your screen, the single most useful thing you can do is close the browser entirely, or restart your computer if it won’t close, without calling any number displayed on it. Real security software alerts live inside the application itself, not inside a browser tab, and never demand an immediate phone call. If you’ve already called and granted remote access, disconnect from the internet, change your passwords from a separate device, and treat the situation the way I eventually did, not as an embarrassing mistake to hide, but as a security incident that needs a clear, methodical response. The panic they create is the weapon. Slowing down, even after the fact, is how you take it back.