
It starts with noise. A browser tab goes full screen, a synthetic voice loops a warning about a virus, and a blue page says the computer has been locked for security reasons. Call this toll-free number immediately. Don't restart your computer. The X won't close the tab. The sound won't stop.
Teach your parents one sentence and you've done most of the work: no real technology company will ever call you, and no real error message will ever contain a phone number. Microsoft says exactly this in its own security guidance. Apple doesn't cold-call about viruses either. Your bank's fraud team will never ask you to move money into a "safe account."
Everything else is detail. But the detail matters, so let's go through it.
Killing the pop-up without calling anybody
That full-screen page is a web page doing a party trick. Nothing is locked. Nothing is infected. The audio is an autoplaying file, and the reason the X is missing is that the site went full screen on purpose.
On Windows, press Esc first, then Ctrl+W to close the tab. If the tab won't die, press Ctrl+Shift+Esc for Task Manager, click the browser, and hit End task. On a Mac, Esc, then Cmd+W, then Cmd+Option+Esc to force quit Safari or Chrome.
When the browser reopens it may offer to restore the previous session. Say no. That's the single step people miss, and it puts the scare page straight back on the screen, which convinces them the "infection" is real.
Walk your mom or dad through this while nothing is wrong. Load a harmless page, make them force-quit the browser themselves, twice. Muscle memory beats a printed instruction sheet they'll never find.
The two tells that never change
Scripts change. The setup changes. Two things don't.
One: they want remote access. The caller asks them to install AnyDesk, TeamViewer, UltraViewer, ScreenConnect, LogMeIn or something with a similar name, then read out a nine-digit code. These are legitimate business tools. That's what makes them useful to criminals. Once it's running, the caller can see the screen, move the mouse, open the banking site and black out the display while they work.
Two: the payment is strange. Gift cards from Target, Apple or Google Play. A wire transfer. Cash in a magazine, shipped overnight. Cryptocurrency fed into a machine at a gas station. A courier sent to collect gold. No legitimate refund, invoice or fraud department has ever asked for any of these.
There's a variant worth knowing because it catches careful people. The caller says they're issuing a refund, has your parent log in to their bank, then "accidentally" types 20,000 instead of 200. The balance looks right on screen because the scammer moved money from savings to checking. Then the crying starts. I'll lose my job. Please just send back the difference. Decent people fall for this one precisely because they're decent.
Cap the damage before anything happens
Spend a Saturday morning on the machine itself.
- Make their daily account a standard user, not an administrator. On Windows, create a separate admin account with a password they don't keep next to the keyboard. Most remote-access installs stop dead at the prompt for administrator credentials.
- Install uBlock Origin in Chrome, Edge or Firefox. It blocks a large share of the malicious ads that carry these redirects in the first place.
- Turn off saved card details in the browser and remove any cards already stored there.
- Turn on automatic updates and then stop nagging about them.
- Set up a real password manager if they'll use one. If they won't, a paper notebook in a drawer is genuinely better than reusing one password everywhere. Don't let perfect win here.
Now the phone. Enable Silence Unknown Callers on an iPhone, or Google's call screening on Android. Tell them plainly that caller ID lies, because it does. A number can be made to display as their bank's main line.
And check whether their bank offers a transfer limit or a trusted-contact designation on the account. Most do. A daily limit of a few hundred dollars is an inconvenience roughly four times a year and a wall the other 361 days.
The card by the phone
Write one index card. Tape it to the desk or under the phone.
Nobody from Microsoft, Apple, Amazon or the bank will ever call me. I will never install software because a caller asked me to. I will never buy gift cards for anyone on the phone. If anything feels urgent, I hang up and call [your name] on [your number].
Then say the part that actually makes the card work: You will never be in trouble for calling me. Not at 11 at night, not on a workday, not if it turns out to be nothing.
Because the reason these scams succeed with intelligent people isn't stupidity. It's isolation plus urgency. The caller manufactures a ticking clock and then tells the victim not to discuss it with anyone, sometimes by claiming the bank's own staff are under investigation. Your job is to be the phone call that breaks the spell, and you can't be that if calling you feels like admitting incompetence.
Set up a family code word too. If someone calls claiming to be a grandchild in jail, the code word ends it in four seconds.
If it's already happened, in this order
- Disconnect the machine from the internet. Unplug the ethernet cable or turn off Wi-Fi at the router. Faster than arguing with a remote session.
- Uninstall the remote-access software. Then run a full scan with Windows Defender or whatever they already have. Don't buy a new product in a panic.
- Call the bank on the number printed on the back of the card. Not a number from the call, not a number from a search result. If money left the account in the last day or two, some of it can sometimes be recalled. Speed is the only lever you have.
- Change passwords from a different device. Email first, because email is the master key to everything else. Then banking. Turn on two-factor authentication while you're in there.
- Report it. In the US, reportfraud.ftc.gov and ic3.gov, the FBI's complaint center. AARP runs a fraud helpline staffed by volunteers who talk people through the aftermath. In the UK, it's Action Fraud. Reporting rarely gets money back. It does feed the case files that occasionally take a call center down.
- Freeze their credit at all three bureaus if identity details were handed over. It's free and takes about fifteen minutes each.
- Warn them about the second call. Victim lists get resold. Within weeks, someone will ring claiming to be a recovery agent, a lawyer or a government investigator who can get the money back for a fee. Same people, often literally.
Where I'd go easy
There's a version of this where you take over, change every password, lock the account down so hard your father can't buy a lawnmower part online, and leave him feeling like a child. He'll route around you. He'll stop telling you things. That's worse than the original risk.
So do the boring hardening quietly, explain each change once, and leave him his administrator password in a sealed envelope if he wants it. Autonomy is the point of the whole exercise.
Call this Sunday. Ask what their computer's done lately that seemed odd. You'll learn more in that one question than in any lecture you could deliver.
Dean Shaw
Gear & Garage
Tests things until they break, then reports what broke first. Trucks, tools, watches, and the cheap version that costs more.
Watch
Worth an hour of your evening
More from Gadgets.
From channels we rate. Plays on YouTube.
Read next
