Can’t find what you’re looking for? Call 1300 688 648 for expert IT assistance

Fake Microsoft and Apple support calls are one of the most common scams targeting Australian businesses right now. If you have received one, or your staff have, you can protect yourself by knowing three things: these companies never call you unsolicited, you should hang up immediately, and no damage is done unless you give them access or pay. This post walks you through how the scam works, what to watch for, and the exact steps to take if someone in your team gets caught out.

How the Scam Works

The scam typically starts one of two ways. Either you receive an unexpected phone call from someone claiming to be from Microsoft or Apple technical support, or a pop-up message appears on your screen warning of a critical virus or security breach. The pop-up usually includes a phone number to call immediately.

The caller sounds professional and urgent. They tell you your computer has been compromised, your data is at risk, or your account has been flagged for suspicious activity. They create pressure by insisting you act right now before things get worse. The goal is to keep you on the phone and moving too fast to think clearly.

These calls are not random. Scammers often purchase data lists, run automated dialling campaigns, or use online advertising to push fake alert pop-ups to unsuspecting users. Australian businesses are a frequent target because we have a reputation for fast payment and a high rate of technology adoption.

The Dead Giveaways It Is a Scam

Once you know these signs, spotting a scam call becomes straightforward:

  • Microsoft and Apple do not call you unsolicited. Neither company will phone you out of the blue to warn you about a virus or account problem. This simply does not happen.
  • Pop-ups with phone numbers are fake. Legitimate security warnings from your operating system never include a phone number to call. If you see one, close the browser tab or restart your computer.
  • Pressure to act immediately is a tactic. Real technical support gives you time to verify. Scammers rush you because they know you will spot the deception if you pause.
  • Requests for remote access are a red flag. If someone you did not call asks to connect to your computer, that is not support. That is intrusion.
  • Payment requests via gift cards or wire transfer are fraud. No legitimate company asks for payment in gift cards or cryptocurrency.

What They Are Actually Trying to Do

Scammers running these operations have clear financial goals. If they gain remote access to your computer, they can install malware that silently captures your banking credentials, emails, and passwords. They may also encrypt your files and demand a ransom to restore them.

In some cases, they charge hundreds or thousands of dollars for fake “security services” that do nothing. In others, they use the access to transfer funds directly from business bank accounts. The damage can range from a frustrating hour of your time to a significant financial loss.

For businesses, the risk is amplified because scammers who access one staff member’s computer may be able to move laterally through your network and reach sensitive client data or financial systems.

What to Do If You Get One of These Calls

The response is simple and should be practised by everyone in your team:

  1. Hang up immediately. You do not need to explain yourself or be polite. Just end the call.
  2. Do not give remote access to your computer. Once they are in, the damage is done.
  3. Do not pay anything. Gift cards, bank transfers, cryptocurrency. None of it goes anywhere good.
  4. Close any suspicious pop-ups. Use Task Manager or Force Quit if the browser will not respond normally.
  5. Tell someone. Inform your IT support or team leader so others can be warned.

What to Do If You Already Gave Them Access

If a scammer has already connected to a computer in your business, act quickly:

  1. Disconnect from the internet immediately. Pull the ethernet cable or turn off the Wi-Fi. This cuts off their access before they can do more damage.
  2. Call your IT provider straight away. They need to assess what was accessed, remove any software the scammer may have installed, and check for ongoing threats.
  3. Change passwords for any accounts accessed on that device. Start with email, banking, and any cloud platforms. Do this from a different, clean device.
  4. Check your bank accounts. If banking credentials may have been visible, contact your bank immediately to flag the account.
  5. Document everything. Note the time, what was said, and what access was granted. This will be useful for your IT provider and for any reports you need to make.

How to Report It in Australia

Reporting these scams helps protect other businesses and contributes to enforcement action:

If money has been lost, also report to your local police and contact your bank’s fraud team directly.

How to Educate Your Team

Awareness is your first line of defence. Consider these practical steps for your business:

  • Brief your team during a short meeting or team call. Run through the warning signs and what to do.
  • Put a one-page summary near workstations or share it via your internal messaging platform.
  • Include a reminder in your onboarding process for new staff.
  • Encourage people to report suspicious calls without embarrassment. Scammers are professional and convincing, and anyone can be targeted.

The most important message to communicate is this: when in doubt, hang up and call your IT provider directly using the number you already have on file.

How Microsoft Copilot Can Help Your Business Respond

If your business uses Microsoft 365 Copilot, you can put it to work in the aftermath of a scam attempt. Copilot can help you draft a clear internal alert to warn your team about the specific call your staff received. It can also help you structure an incident report if access was granted, which your IT provider and insurer may require.

Using AI tools to turn a stressful event into documented, actionable communication is exactly the kind of practical advantage Copilot provides for businesses dealing with fast-moving situations.

Frequently Asked Questions

Will Microsoft or Apple ever call me about a virus?

No. Microsoft and Apple do not make unsolicited phone calls to warn customers about viruses or security issues. If you receive this kind of call, it is a scam.

What if the caller ID shows a legitimate company name?

Caller ID can be spoofed easily. A number that appears to be from Microsoft or Apple means nothing. Hang up and do not call the number back.

What if I gave them access but nothing seemed to happen?

Assume the worst and act immediately. Many scammers install software designed to run quietly in the background. Contact your IT provider straight away for a full assessment.

How do I stop these pop-ups from appearing?

Most fake alert pop-ups come from malicious websites or browser extensions. Keeping your browser and operating system updated, using reputable ad-blocking software, and avoiding suspicious websites will reduce the risk significantly.


Scam calls like these are designed to exploit urgency and trust. With the right knowledge, your team can recognise them instantly and shut them down before any harm is done.

If you want to strengthen your business’s defences against cyber threats, our managed cyber security services are built for professional services businesses like yours. Book a free consultation to find out how we can help protect your people and your data.

managed it support articles

Related Blog Articles

Discover more insights to optimise your business with the latest IT trends and best practices. Stay ahead of the curve by learning how to leverage cutting-edge technology for success. Explore expert advice and valuable guidance to navigate the evolving world of IT solutions

Learn More