Fake Microsoft Defender Pop-Up Lock Scam

INDIA — By BharatSecure Threat Intelligence Team ·

Suspicious Risk: 7/10 Severity: High BharatSecure Threat Intelligence

Category: UPI

Verdict Summary

Fake Microsoft Defender Pop-Up Lock Scam shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.

Risk score: 7/10 · Severity: High · Verdict: Suspicious

Scam Intelligence: Fake Microsoft Defender Pop-Up Lock Scam

Proprietary signals from BharatSecure's scam-tracking database.

Top affected regionsIndia, general
Last reportedMay 06, 2026

How Fake Microsoft Defender Pop-Up Lock Scam Works

Overview: The Fake Microsoft Defender Pop-Up Lock Scam targets Indians browsing the web, especially those using Windows laptops or desktops. This scam creates alarming, full-screen pop-up messages that closely mimic genuine Microsoft security alerts. Victims are led to believe their system is compromised by severe viruses and are pressured to call helpline numbers supposedly for technical assistance. All age groups are at risk, but older adults and non-tech savvy individuals are especially vulnerable. The scam's urgency tricks people into giving up control of their computers or paying for unnecessary services, putting their data and finances at risk. How It Works: 1. While browsing, an unexpected pop-up takes over the screen, displaying warnings such as "Trojan Detected! Immediate Action Required." 2. The alert uses Microsoft Defender branding and logos, making it seem authentic. 3. The message instructs you to immediately call a helpline number (often a local Indian mobile number or toll-free number). 4. When the victim calls, scammers posing as Microsoft tech support ask for computer access or request payment for resolving the fake issue. India Angle: These scams commonly appear on Indian news, movie streaming, or cricket sites, sometimes after clicking ads or downloading files. The pop-ups often use Indian customer care numbers (+91) and adapt their language to Hindi, English, or regional dialects. They may refer to Indian digitized payment methods—asking for UPI transfer, Paytm, or net banking details during the sham support call. Such scams are particularly active in metro cities and tier-2 towns where internet usage is high. Real Examples: - While reading news online, "Preeti" suddenly sees a warning: "Your Windows system is infected! Call Microsoft Support at 9876XXXXX immediately." - "Anil" is browsing cricket scores when a window locks his screen: "Critical System Error: Security Threat Detected. Do not turn off your computer. Call 1800-XXX-XXXX." Red Flags: - Pop-up messages claiming severe infection, demanding you call a helpline. - Use of Indian phone numbers instead of international Microsoft support numbers. - Computer appears to be locked, but the message is only within the browser. - Urgent, fear-inducing language urging immediate action. - Microsoft logos but with minor spelling errors or odd web addresses. Protective Measures: - Never call numbers displayed in pop-ups, no matter how urgent they appear. - Close your browser (or force-close using Task Manager - Ctrl+Shift+Esc) if screen seems locked. - Use only the built-in Windows Security app or a trusted antivirus for scans. - Do not share remote access to your computer or make payments to "support" calls. - Keep your system and browser updated to reduce vulnerability. If Victimised: - Immediately disconnect internet. - Change passwords, especially if you gave remote control. - Report scam at cybercrime.gov.in or dial 1930 for help. - Inform your bank/RBI if money has been transferred to scammers. Related Scams: - Fake Antivirus Software Installation offers - Remote Desktop access scams - Tech support impersonation calls

How This Scam Works — Detailed Explanation

The Fake Microsoft Defender Pop-Up Lock Scam preys on unsuspecting users in India, particularly those who browse the web using Windows operating systems on laptops or desktops. These scammers have become increasingly tech-savvy, employing ads on social media platforms like Facebook and Instagram, or through dubious websites. Once a user clicks on an infected link or visits a compromised site, they are greeted with a full-screen pop-up that closely resembles a genuine security alert from Microsoft. This experience can be disorienting, making users feel their computer has serious issues, prompting them to act out of fear rather than reason.

Once the alarmist pop-up appears, it typically urges users to call a purported Microsoft technical support number. Scammers often use local Indian phone numbers (+91) to lend a veneer of authenticity to their operation. To add a layer of urgency, the messages may display alarmist language, claiming the potential loss of personal data or imminent system failure. By creating an atmosphere of panic, the scammers exploit the victims' lack of technical knowledge—individuals over 50 and those unfamiliar with technology are particularly vulnerable to these manipulative tricks. The frightening visuals and messages serve a single purpose: to push victims into a hasty decision to seek help—the kind that leads them right into the hands of fraudsters.

Victims who fall for this scam often follow a predictable path. After calling the number provided, they are greeted by someone posing as a technical support agent who claims to have identified issues with their computer. Victims can be coerced into installing remote access software, granting the scammer complete access to their machine. They may then be manipulated into making payments, often through UPI, for ‘fixing’ the non-existent virus or purchasing worthless software purported to protect their computer. Recently, several cases were reported wherein individuals lost upwards of ₹20 lakh cumulatively through these scams as their financial and personal information gets compromised.

The real-world impact of this scam is troubling. As reported by the Ministry of Home Affairs (MHA) and the Reserve Bank of India (RBI), scams of this nature have seen significant spikes in India, with individuals losing over ₹500 crore in the past year alone due to various types of online fraud. These statistics highlight the enormous financial toll and the psychological strain on victims when their trust has been betrayed. The Computer Emergency Response Team - India (CERT-In) has issued advisories warning of such scams, further underscoring their rising prevalence in our digital landscape.

To distinguish this scam from legitimate Microsoft communications, users should remain alert to several red flags. Genuine alerts from Microsoft do not require users to call a support number mid-browsing nor do they lock screens within a browser. Users should look for discrepancies such as odd website addresses that may not resemble official Microsoft domains. Alertness to alarmist language about immediate threats to one's system will also help mitigate the chances of being fooled. Remember, if issues arise, turning to official Microsoft resources directly is always the safest choice.

Visual Intelligence:

BharatSecure's AI has identified this as a used in scams targeting Indian users.

Who Does Fake Microsoft Defender Pop-Up Lock Scam Target?

General public across India

Red Flags — How to Identify Fake Microsoft Defender Pop-Up Lock Scam

  • Pop-up urges you to call a support number
  • Uses Indian (+91) phone numbers for Microsoft Help
  • Messages lock screen visually but only inside browser
  • Alarmist language about system failure or data theft
  • Odd website address [ADDRESS_REDACTED]

What To Do If You Encounter Fake Microsoft Defender Pop-Up Lock Scam

  1. Report the incident to the cybercrime helpline by calling 1930 or visiting cybercrime.gov.in.
  2. Do not cooperate with anyone claiming they can solve your problem unless they are verified agents from a trusted source.
  3. Uninstall any suspicious software that was installed during the call, especially if remote access was granted.
  4. Change passwords for your email and bank accounts immediately to safeguard against unauthorized access.
  5. Notify your bank about the potential threat to your financial details and ask them to place alerts on your account.
  6. Educate family members about the scam to prevent wider victimization within your household.

How to Report Fake Microsoft Defender Pop-Up Lock Scam in India

  • Call 1930 — National Cyber Crime Helpline (24x7)
  • File a complaint at cybercrime.gov.in
  • Contact your bank immediately if money was lost
  • Call RBI helpline: 14440 for banking fraud

Frequently Asked Questions

What to do if I shared my Aadhaar details in a scam?
Immediately contact your bank and report the incident. You can also block your Aadhaar number temporarily by visiting uidai.gov.in or calling 1947.
How can I identify the Fake Microsoft Defender Pop-Up Lock Scam?
Look for pop-ups that urge you to call a support number and use alarming language about potential data theft or system failure.
How do I report this type of scam in India?
Report it to the cybercrime helpline by calling 1930 or visit cybercrime.gov.in to file a complaint. You can also notify your bank.
How can I recover money or protect accounts after this scam?
Contact your bank immediately to report unauthorized transactions and change your security credentials. Keep an eye on your accounts for unusual activity.
🛡️

How This Scam Works — BharatSecure AI

Spreading fast

A plain-language breakdown based on 100 real reported scams of this type.

How they reach you Observed primary contact occurs via unsolicited phone calls, WhatsApp/SMS messages, and social media/dating platforms, where fraudsters impersonate bank officials, customer support, government agents,
How they gain your trust Trust is reportedly established through impersonation of authority (banks, RBI, PM-Kisan, army officers) or emotional bonding (love-bombing, family/friend impersonation), often reinforced by AI deepfa
How they take your money UPI is the dominant rail across all records, primarily via disguised 'collect/request money' notifications tricking victims into entering their PIN, d
Who they target Documented targets span the general population but concentrate on the elderly and digitally inexperienced (often via caregiver dependency), urban professionals, students, homemakers, small business ow
How they manipulate you
  • authority bias (impersonating banks/government/officials)
  • urgency and scarcity (account frozen, limited-time offer, emergency)
  • trust/reciprocity exploitation (familiar voices, love-bombing, small initial payouts)
Warning signs
  • Receiving a UPI 'collect/request money' notification and being asked to enter your PIN to 'receive' funds (PIN is never needed to receive money)
  • Unsolicited calls/messages claiming account freeze, KYC expiry, or suspicious transaction, pressuring you to share OTP, UPI PIN, or click a link
  • Requests to install remote-access/screen-sharing apps (AnyDesk, TeamViewer) for 'support' or 'refund' assistance
  • Mismatched or misleading recipient names/VPAs (e.g., 'Verified Merchant', 'Bank Refund Dept') or slightly altered UPI IDs
  • Pressure via emotional urgency, deepfake voice/video of familiar people, forged payment screenshots, or too-good-to-be-true offers (free recharge, prizes, grants, loans, high-return investments)

Related Scams in India

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.