The old version of this scam was easy to laugh at. Your browser window locks up, a red banner screams that your PC is infected, a robotic voice starts talking, and somewhere on the page there is a number to call right now. Nobody had to teach you that was fake. It looked fake.
That version is going away, and the replacement is a lot quieter. Malwarebytes Labs wrote at the start of September that these scams "used to rely mainly on browser locks and fake virus warnings", and that criminals now copy the websites of reputable brands and pretend to work for a trusted technology or security company. Same goal, better costume.
What actually changed?
Two things. The page got better, and the way you arrive at it got more ordinary.
According to the same Malwarebytes piece, as well as copying the websites of reputable brands, tech support scammers abuse sponsored search results, hijack on-site searches, create fake listings on trusted platforms, and use renewal scams, fake calendar invites and Apple Pay notifications to persuade people to call them. Read that list again. Not one of those arrives looking like a threat. A sponsored result sits at the top of a normal search. A calendar invite lands in your calendar. A renewal notice is the most boring email in the world.
So the moment where your instincts used to fire, the screaming pop-up, is gone. You are just on a website. And the website looks right.
Why does a copied page work so well?
Because we check brands with our eyes, and the eyes were given exactly what they expect. Nothing on a well-built copy is "off". There is no typo to catch, no stretched logo, no weird stock photo. First of all, the design is usually pulled straight from the real site, so it is not similar to the original, it is the original, minus the ownership.
And then there is the phone number. A number on a page feels like proof, because a human will answer. Someone does answer. That is the business model 😅
Where does the check still work?
In the address bar. Not on the page, not in the logo, not in the phone number. The address bar is the only element on your screen that the scammer does not control the wording of.
Here is the shape to look for. Read the address from the first single slash backwards, and take the two words right before the last dot.
microsoft.com/supportthe two words before the first slash are microsoft.commicrosoft-support-alert.example[.]comthe real owner here is example.com, and "microsoft" is just decoration in front of itA brand name can appear anywhere in an address: in front of the real domain, after it, in the path, in the page title. It means nothing in those positions. Only the part immediately before the last dot, plus that last dot's ending, tells you who owns the place.
What about the CAPTCHA that asks you to paste something?
This one deserves its own paragraph, because it is spreading and it is not obvious. Malwarebytes Labs described a Windows campaign, which Microsoft calls TerminalFix: a visitor sees what looks like a Cloudflare CAPTCHA, clicking it silently copies a command to the clipboard, and the visitor is then told to paste and run it to prove they are human.
The rule here is simple and worth memorising. A real CAPTCHA may ask you to tick a box or pick out the traffic lights. It will never ask you to open Run, Terminal, Command Prompt or PowerShell and paste a command in. However convincing the brand on that box looks, that instruction alone is the whole answer.
So what do you do when a support page looks right?
- Stop before you call. A phone number on a web page is not a credential. It proves only that the page has a phone number on it.
- Copy the address, don't retype it. Retyping quietly corrects whatever trick was in there.
- Find the real domain. First slash, then read backwards to the last dot before it. That is the owner.
- Reach support your own way instead. Type the brand's domain yourself, or open the app you already have installed, or use the number printed on the back of your card or on your invoice.
- Check the domain if you want a second opinion. Paste it into IP Tracker and see what comes back before you type anything into the page.
Of course, step four is the one that actually saves you, and it costs about twenty seconds. The check is for when you want to know what you were nearly caught by.
What does IP Tracker show you here?
IP Tracker is my free Chrome extension. You paste a domain, a link or a full email address, and it checks that value: 50 checks a day, no account, no tracking.
For a page like this, it gives you a handful of separate signals rather than a verdict. Whether the domain is a lookalike of one of about 125 widely impersonated brands, including banks, payment services, couriers, big tech, government sites, crypto and streaming. Whether Google Safe Browsing, Google's list of reported dangerous sites, has flagged it. How many security vendors flag it on VirusTotal. Community abuse reports on the address it resolves to. When the domain was registered, since a support desk for a twenty-year-old brand sitting on a domain created nine days ago is worth a raised eyebrow. And where it is hosted, which is how you notice a "global support centre" running on a free website builder.
What can't it do?
Unfortunately, quite a lot, and you should know the edges before you lean on it:
- It never sees the page. It checks the address you paste, not the content. A perfect copy of a brand's site and a blank page look identical to it.
- The brand list is about 125 names. If the scam impersonates your regional internet provider, a small repair shop, or a niche software vendor, the lookalike check will not catch it. There is nothing on the list to compare against.
- A generic fake name isn't a lookalike. Something like
pc-help-center-24[.]exampleimitates nobody in particular, so the spelling check has nothing to fire on, even though the page pretends to be a famous brand. - Phone numbers, pop-ups and clipboard tricks are outside its reach. It reads domains and IP addresses. A number on a page, a fake CAPTCHA and a command copied to your clipboard are all invisible to it.
- Blocklists lag. Safe Browsing is strong on known bad sites, but a domain registered this morning has not been reported by anyone yet.
The pop-up era trained us to spot scams by how loud they were. That training has quietly expired. The new ones are calm, well-designed and reachable from a normal search, so the thing to check is no longer how the page feels, but who owns the address it lives at 🤓
To summarize:
- ✓ A page that looks right proves nothing. The look is the copyable part.
- ✓ Read the domain: first slash, then backwards to the last dot.
- ✓ A brand name in front of the real domain is decoration.
- ✓ Never phone a number you found on a page you were sent to.
- ✓ No real CAPTCHA asks you to paste a command into Terminal or PowerShell.
- ✓ Reach support the way you already know: your app, your invoice, your card.
Happy checking! 😎
Sources
- Tech support scams look different now. Here's what to watch for, Pieter Arntz, Malwarebytes Labs, 2 September 2026.
- TerminalFix looks like ClickFix, but delivers a very different payload, Pieter Arntz, Malwarebytes Labs, 1 September 2026.
- How To Spot, Avoid, and Report Tech Support Scams, FTC Consumer Advice.