A technical support scam, or tech support scam, is a type of scam in which a scammer claims to offer a legitimate technical support service for computing devices connected to the Internet. The scam may be intimated by a cold telephone call from the thief to the victim, or victims may contact scammers in response to a fake pop-up resembling an error message, or via fake "help lines" advertised on websites operated by the scammers. Technical support scammers use social engineering and a variety of confidence tricks to persuade their victim of the presence of problems on their computer or mobile device, such as a malware infection, when there are no issues with the victim's device. They frequently take full control of the victim's computer with remote control software. The scammer will then persuade the victim to pay to fix the fictitious "problems" that they claim to have found. Payment is made to the scammer via gift cards or cryptocurrency, which are hard to trace and have few consumer protections in place. There is risk of potentially higher losses to thieves who persuade victims to connect, with password and two-factor authentication if relevant, to online banking, or to transfer large sums to a "safe account" to "protect it from hackers accessing their computer". Technical support scams started no later than 2008. A 2017 study of technical support scams found that of the IPs that could be geolocated, 85% could be traced to locations in India, 7% to locations in the United States and 3% to locations in Costa Rica. Research into tech support scams suggests that millennials and Gen Z have the highest exposure to such scams; however, it is thought that older people are more likely to fall for these scams and lose money to them. Technical support scams were named by Norton as the top phishing threat to consumers in October 2021; Microsoft found that 60% of consumers who took part in a survey had been exposed to a technical support scam within the previous twelve months. Responses to technical support scams include lawsuits brought against companies responsible for running fraudulent call centres, and scam baiting.
Origin and distribution The first tech support scams were recorded in 2008. Technical support scams have been seen in a variety of countries, including the United States, Canada, United Kingdom, Ireland, The Netherlands, Germany, Italy, Australia, New Zealand, India, and South Africa. A 2017 study of technical support scams published at the NDSS Symposium found that, of the tech support scams in which the IPs involved could be geolocated, 85% could be traced to locations in India, 7% to locations in the United States and 3% to locations in Costa Rica. In 2020, scambaiter Jim Browning said that 95% of the scammers he has interacted with have Indian IP addresses. India has millions of English speakers who are competing for relatively few jobs. One municipality had 114 jobs and received 19,000 applicants. This high level of unemployment serves as an incentive for tech scamming jobs, which are often well-paid. Additionally, scammers exploit the levels of unemployment by offering jobs to people desperate to be employed. Many scammers do not realise they are applying and being trained for tech support scam jobs, but many decide to stay after finding out the nature of their job as they feel it is too late to back out of the job and change careers. Scammers are forced to choose between keeping their job or becoming jobless. Some scammers convince themselves that they are targeting wealthy people that have money to spare, which justifies their theft, whilst others see their job as generating "easy money". Some scammers rationalize that the victim needs an anti-virus anyway and therefore, it is acceptable to tell the victim lies and charge them for technical support or to charge them for an anti-virus.
Operation Technical support scams rely on social engineering to persuade victims that their device is infected with malware. Scammers use a variety of confidence tricks to persuade the victim to install remote desktop software, with which the scammer can then take control of the victim's computer. With this access, the scammer may then launch various Windows components and utilities (such as the Event Viewer), install third-party utilities (such as rogue security software) and perform other tasks in an effort to convince the victim that the computer has critical problems that must be remediated, such as infection with a virus. Scammers target a variety of people, though research by Microsoft suggests that millennials (defined by Microsoft as age 24–37) and people part of generation Z (age 18–23) have the highest exposure to tech support scams and the Federal Trade Commission has found that seniors (age 60 and over) are more likely to lose money to tech support scams. The scammer will urge the victim to pay so the "issues" can be fixed.
Initiation
Technical support scams can begin in a variety of ways. Some variants of the scam are initiated using pop-up advertising on infected websites or via cybersquatting of major websites. The victim is shown pop-ups which resemble legitimate error messages such as a Blue screen of death and freeze the victim's web browser. The pop-up instructs the victim to call the scammers via a phone number to "fix the error". Technical support scams can also be initiated via cold calls. These are usually robocalls which claim to be associated with a legitimate third party such as Apple Inc. Technical support scams can also attract victims by purchasing keyword advertising on major search engines for phrases such as "Microsoft support". Victims who click on these adverts are taken to web pages containing the scammer's phone numbers. In some cases, mass emailing is used. The email tends to state that a certain product has been purchased using their Amazon account and contact a certain telephone number if this is an error.
… excerpt ends here. Continue reading the full article.



