Fake Microsoft Defender Pop-Up Lock Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: High | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

Beware the Fake Microsoft Defender Pop-Up Lock Scam India 2026: A Rising UPI Threat

This widespread cyber fraud targets innocent Windows users in India with fake security alerts, tricking them into handing over money through UPI or phone support calls.

What Is the Fake Microsoft Defender Pop-Up Lock Scam?

The Fake Microsoft Defender Pop-Up Lock Scam is a form of digital fraud increasingly reported across India in 2024–2026. It primarily targets people using Windows laptops or desktops who browse the internet without robust safeguards. Fraudsters craft fake full-screen pop-ups that mimic official Microsoft Defender warnings, claiming that the user’s device is infected or at risk. These alarming messages often appear suddenly while users are on popular social media platforms like Facebook or Instagram, or when visiting compromised websites.

The scam specifically exploits users' trust in Microsoft’s brand and their fear of malware or hacking, prompting urgent action. According to complaints reported to Indian cybercrime authorities like CERT-In and the Indian Cyber Crime Coordination Centre (I4C), victims are lured into calling supposed Microsoft technical support numbers, which are actually controlled by scammers. This tactic has affected thousands of users, and the scale appears to be growing as internet penetration and dependence on UPI payments rise across India.

The Reserve Bank of India (RBI) and CERT-In have issued advisories warning users to be cautious about unsolicited pop-ups and calls claiming to be from Microsoft or other tech companies. They caution that genuine alerts would never direct users to call random phone lines or share financial details over the phone.

How This Scam Works — Step by Step

  1. Infected or Compromised Link: The victim encounters an infected ad on platforms like Facebook or clicks a suspicious link sent via WhatsApp or through dubious websites. This link leads them to a fake webpage.

  2. Fake Microsoft Defender Pop-Up Appears: As soon as the page loads, a full-screen pop-up resembling a genuine Microsoft Defender alert triggers, with loud audio or flashing colors to create urgency. It claims the device is infected with malware or that the user’s data is at risk.

  3. Prompt to Call “Support”: The pop-up displays a toll-free Indian number (e.g., 1800-XXX-XXXX) claiming to connect users with certified Microsoft tech support. Users are urged not to close the pop-up or restart their device, to avoid data loss.

  4. Call with the Fraudster: When the victim calls, the caller posing as a Microsoft technician educates them about the “virus” or “security breach.” They pressure the victim to provide remote access to their machine or guide them to perform certain actions.

  5. UPI Payment Theft or Data Capture: Under the pretext of fixing the issue, the caller asks the victim for UPI payment details or instructs them to scan QR codes linked to fraudulent UPI IDs (e.g., us**@bank). Alternatively, they might trick victims into sharing OTPs to authorize UPI transactions or sell fake software that demands payment.

  6. Financial Loss and Device Vulnerability: Once information or authorization is given, the victims’ UPI-linked bank accounts show unauthorized debits, often in INR thousands or lakhs. Fraudsters may also install malware or spyware via remote access, risking further identity or Aadhaar misuse.

Real Warning Signs to Watch For

What Happens to Victims

Victims often face immediate financial loss as scammers use stolen UPI credentials to transfer money from their bank accounts without authorization. RBI guidelines allow banks to reverse unauthorised UPI transactions if reported swiftly, but recovery is not guaranteed. Emotional distress is high, with many victims feeling violated and losing trust in digital payments and tech platforms.

In some cases, the fraudster installs malware via remote access, exposing victims to Aadhaar data theft, SIM swap risks, or further cyber-attacks. Such breaches may lead to prolonged financial and identity issues, complicating users’ digital lives.

What RBI and CERT-In Say

The Reserve Bank of India regularly reminds consumers about the importance of securing their UPI PIN and not sharing OTPs or sensitive bank details. RBI’s 1930 helpline supports reporting of digital payment frauds and helps freeze compromised accounts.

CERT-In advises users never to trust unsolicited pop-ups demanding urgent action or calls to unverified numbers. They emphasize that genuine Microsoft alerts never display phone numbers or ask for immediate payments. The Ministry of Home Affairs’ I4C platform (cybercrime.gov.in) facilitates cybercrime complaints, ensuring coordinated government response.

Users should stay updated with CERT-In advisories on common fraud patterns and verify suspicious activity with credible sources before acting.

How to Protect Yourself

  1. Ignore and close suspicious full-screen pop-ups immediately. Use Task Manager to end browsers if necessary.
  2. Never call phone numbers displayed on pop-ups or unsolicited messages. Use Microsoft’s official website or contact points for support.
  3. Do not share UPI PINs, OTPs, or scan QR codes from unknown sources. Legitimate banks never ask for these over calls.
  4. Install and maintain updated antivirus protection from trusted sources.
  5. Avoid clicking on ads/promotions on social media unless verified.
  6. Enable two-factor authentication (2FA) on UPI apps and bank accounts for added security.
  7. Regularly monitor bank and UPI transaction notifications to spot unauthorized activity early.

What to Do If You've Been Targeted

Frequently Asked Questions

Q: Can Microsoft itself ever display pop-ups asking me to call support?
A: No. Microsoft does show security alerts via Windows Defender but never asks users to call phone numbers or pay for support through such pop-ups. Legitimate alerts direct users to contact Microsoft only via official websites.

Q: What should I do if I accidentally shared UPI OTP or scanned a scam QR code?
A: Contact your bank immediately to block payments or freeze your account. Report to the 1930 helpline and file a police complaint. Prompt reporting increases chances of recovering lost funds.

Q: Can antivirus software protect me from this scam?
A: Antivirus tools can help block some malware but cannot stop scam pop-ups or social engineering tactics fully. User vigilance and awareness are the best defense.

If you receive any suspicious pop-ups, messages, or calls claiming to be from Microsoft or related technical support, verify the details on BharatSecure.app and report fraud immediately at 1930.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.