everyday mac tools

The fake support call, and why it works

· 5 min read

The most successful attacks on Mac users do not involve breaking into anything. Someone persuades you to open the door, and every protection macOS has is irrelevant because you authorised what happened.

Recognising the shape of it is worth more than any software.

The script

It varies in detail and follows a pattern.

The hook. A pop-up saying your Mac is infected, with a number to call and often an alarm sound. Or an unsolicited call claiming to be from Apple, your bank, or your internet provider. Or an email about a purchase you did not make, with a number to dispute it.

The urgency. Your account will be closed. Money is leaving right now. Your files are being encrypted. The pressure is deliberate; it is there to stop you thinking.

The authority. They know your name. They may know your address or the last four digits of a card, harvested from a breach. That partial knowledge is used to establish that they are who they say.

The ask. Install remote access software so they can “fix” it. Read out a verification code. Move money to a “safe account”. Buy gift cards.

The close. Once they have remote access, they show you fabricated evidence of a problem, then charge for a fix, install something, or empty an account.

Why it works on people who know better

Worth stating, because the shame around this stops people reporting it.

It works because it targets the parts of thinking that urgency disables. Nobody evaluates a situation carefully while being told their money is disappearing. The script is refined over thousands of calls, and it is designed by people who do this full time.

It works on lawyers, engineers and doctors. Believing you are too sensible for it is itself a risk factor, because it means you have never thought about what you would do.

The rules that actually help

Apple does not ring you. Neither does Microsoft, and nor does your bank’s fraud team ask you to move money. If someone rings claiming to be them, they are not.

A pop-up cannot know your Mac is infected. A web page has no visibility into your machine. Every one of those is fake, without exception.

Never install remote access software for someone who contacted you. This is the point of no return; almost everything after it is worse.

Never read out a verification code. They are for you to type, never to say aloud. Anyone asking is attacking you.

Hang up and call back on a number you found yourself. Not the number they gave, not the number in the email. From the back of your card, or the official site typed directly. A genuine caller will not object.

Urgency is the signal. Real organisations let you ring back. Attackers cannot, because the pressure is the mechanism.

If you have a pop-up on screen now

It cannot do anything. It is a web page.

Force-quit the browser: Command-Option-Escape, select the browser, Force Quit. If it reopens the same page, hold Shift while launching to stop it restoring tabs.

Do not ring the number. Do not click anything on the page, including a close button, which may not be one.

If you already let someone in

Act quickly and in this order.

  1. Disconnect from the internet. Turn off Wi-Fi.
  2. Remove the remote access software they had you install, from Applications.
  3. Restart the Mac.
  4. Change your passwords, from a different device. Apple Account first, then email, then banking.
  5. Ring your bank on a number you found yourself, if any financial details were involved.
  6. Check for anything left behind: System Settings, General, Login Items, and Privacy & Security for a configuration profile you did not add.
  7. Report it to your national fraud reporting service.

What to do the hour after you think your Mac was compromised covers the fuller sequence.

The conversation worth having

If you set up Macs for family, this is the most valuable thing you can tell them, and considerably more useful than any setting.

Two sentences: nobody legitimate will ever ring and ask you to install something or read out a code, and it is always fine to hang up and ring back on a number you looked up yourself.

Add that they will never be in trouble for telling you it happened. People lose more money by being too embarrassed to mention it early.

Setting up a Mac for someone who is not comfortable with computers covers the rest of that setup.

Questions

They knew my name and address. Surely they are genuine? That information is available from data breaches and public records. It is used precisely because it is persuasive.

The number matched Apple’s real one on my screen. Caller ID is trivially forged. It proves nothing.

Can they do anything if I just talked to them? Talking alone does nothing. The damage begins with installing software, giving a code, or moving money.

Should I report it if I lost nothing? Yes, if it is easy. Reports help track campaigns, and it costs you a few minutes.