“Your computer has a virus, call Microsoft”: the pop-up that empties bank accounts
News.com.au's report on 4 September 2026 is worth reading in full, because the two families in it were caught by exactly the same script four years apart, and it is the script we see most often described to us by people over 75. It has three moves. Each one has a tell. Each one is stoppable if you know what it looks like.
Move one: the screen
Mr Holden's computer “went blank” and showed a warning that a virus had infected it, with a Microsoft number to call. That screen is a web page. It has no more control over the computer than any other web page. It's built to fill the display, sometimes with a siren, sometimes with a countdown, so that it feels like the machine has failed. Nothing has happened. Escape, close the browser, or hold the power button — and it's gone.
The tell is the phone number. Microsoft has never, in any version of Windows, put a phone number on a virus alert. Neither has Apple, Norton, McAfee or Telstra. A genuine security program handles a threat inside itself; it does not ask you to ring a stranger. That single fact is enough. You don't need to work out whether the virus is real, because the number proves the screen isn't.
Move two: the software
Whoever answers the number is friendly, calm and technical. They ask you to install AnyDesk or TeamViewer so they can “fix it”. Both are real tools that real IT support uses, which is why it sounds fine. Once installed, the caller sees your screen and moves your mouse. They open your internet banking, and if the browser has saved the password, they are in.
This is why the loss is so much larger than a parcel-fee text. In most scams the limit is what a person can be persuaded to send. Here there is no limit, because the person isn't sending anything. The Holdens' money left in 104 transactions over two days. Nobody typed those. Someone in another country did, with Mr Holden's own login, from Mr Holden's own chair.
Move three: the isolation
Mr Holden was told to leave the computer unattended and not to touch his mobile phone. The Adams family's scammer rang every morning between eight and nine and kept the landline open all day. These are not odd details. They are the mechanism. A phone reaches a daughter, a son, a friend, a bank — anyone who would say “hang up”. So the script removes the phone.
If you remember one thing from this page, make it this: anyone who tells you not to use your phone, not to hang up, or not to tell anyone is telling you they are a scammer. A real technician does not need you cut off from your family. A real bank does not need you to keep a secret from your bank.
Why the bank kept the debt
Both families took their cases to the Australian Financial Complaints Authority, and both lost. The reasoning matters if you're protecting a parent, because it tells you where the bank's responsibility stops.
Under the ePayments Code, a bank is generally not liable when a customer's own passcodes were used to make the transactions, even where the customer was deceived. AFCA found the Holdens' passwords had been saved in the browser's autofill and used by the scammers — which it treated as a breach of the code's security requirements. The couple are adamant they never saved them; their lawyer says they've been consistent on that every time she has checked. AFCA also found the bank acted “promptly” on recalls, despite another bank's fraud alert sitting unread from 3am until office hours.
Whatever you think of that outcome, the practical lesson is blunt: the protection ends where a saved password begins. If a browser on the family computer remembers the banking login, a remote-access scam is a total-loss scam. Turn autofill off for the bank, and use the bank's app on a phone instead of a website on the computer.
The evidence they were told to destroy
Both families were told by the bank to have the computer “cleaned” before their accounts would be reopened. Both did, and in doing so wiped the record of what the scammers had done. In a separate case involving the same scam, Bendigo Bank was ordered to repay $70,000 — and a forensic examination of the computer was what won it.
So: after a remote-access scam, do not wipe, clean or reset the computer until the bank, IDCARE and if necessary a lawyer have said so. Turn it off and leave it off. Use a different device for banking in the meantime. The machine is evidence, and it may be the only evidence.
What to do, in order
- If the screen is up: don't ring the number. Turn the computer off. That is the whole fix.
- If you've rung and they're connected: unplug the internet cable or turn the wi-fi off at the router first, so they lose control. Then hang up.
- Ring the bank from a different phone, on the number on your card, and say: “a scammer had remote access to my computer.” Those words trigger a different process from “I'm worried about a transaction”.
- Ring IDCARE on 1800 595 160. They are free and they will tell you what to keep and what to do next.
- Keep the computer. Off, unplugged, untouched. Don't let anyone “clean” it yet.
- Tell someone. The shame is the scammer's last tool. The Holdens borrowed from a grandson and sold cattle before anyone outside the family knew.
How Is it a scam? sees this one
This scam doesn't arrive as a message, which is why it slips past people who've learned to be careful with texts. Nothing lands in the inbox. It lands on the screen, with a stranger on the phone, and no time to think.
What can be forwarded is the person's own description of it. “Computer says it has a virus and to call Microsoft on 1800…” comes back in about ten seconds as a scam screen, with the one instruction: turn it off. A photo of the screen gets the same answer. “He wants me to download AnyDesk” is a scam verdict on its own. And “he says to leave the computer on and not touch my phone” is answered for what it is — the isolation move — with the reply that a real technician never needs you cut off from anyone. The family is told at the same moment, which is precisely the phone call the caller was trying to stop.
It works because the habit is one habit: before you act on anything, forward it. A text, an email, a letter, or a description of what's on the screen. The person doesn't have to know which scam this is. They only have to know the number to send it to.
Common questions
Does Microsoft ever put a phone number on a virus warning?
No. Neither Microsoft, Apple, Norton nor any real security software puts a phone number on an alert and asks you to ring it. Genuine warnings are handled inside the program. A screen that gives you a number to call is the scam itself, however official it looks.
Why does the screen freeze or go blank?
It's a full-screen web page designed to look like the computer has locked up, sometimes with a siren sound. Nothing has actually happened to the computer. Pressing Escape, closing the browser, or turning the machine off and on again clears it. The panic is the product.
What is AnyDesk and why do they want it installed?
AnyDesk (and TeamViewer) are legitimate remote-control tools used by real IT support, which is why the request sounds plausible. Once installed, the caller sees the screen and controls the mouse. From there they open internet banking themselves. The loss isn't limited to what you'd agree to send — they make the transfers.
Why did they tell Mr Holden not to touch his phone?
Because a phone reaches a son, a daughter, a bank. Every version of this script isolates the victim: leave the computer on, don't use your mobile, stay on the line, don't tell anyone. Being cut off from checking is not a side effect of the scam — it is the mechanism.
Why did AFCA side with the bank?
Under the ePayments Code, a bank generally isn't liable when a customer's own passcodes were used, even if the customer was tricked. AFCA found the scammers used passwords saved in the browser's autofill, which it treated as a breach of the code's security requirements. The couple say they never saved them. Either way, the practical lesson is that the bank's protection usually ends where your saved password begins.
What should I do the moment I realise?
Unplug the internet or turn off the wi-fi first, so they lose control. Then ring your bank from a different phone, using the number on your card, and say the words "a scammer had remote access to my computer" — not just "I'm worried about a transaction". Every hour matters for recalls. Don't wipe or clean the computer until the bank and IDCARE have said so; the evidence on it may be what wins a dispute.
Can this be checked while it's happening?
Yes, if the person knows to. Is it a scam? takes a photo of the screen or a typed description — "computer says virus, call Microsoft on this number" — and answers in about ten seconds that it's a scam screen and to turn the computer off. The family is told at the same time, which is exactly what the caller is trying to prevent.
A screen can't be forwarded. It can be photographed, or described.
Is it a scam? answers a photo of the screen or a typed sentence in about ten seconds — and tells the family at the same moment, which is the call the scammer is trying to prevent. One Australian number, no app.
Set this up for someoneWant to check something now? Do that free, no sign-up. Already happened? Start here.