Check the context
- Did you initiate the request?
- Does the case or appointment already exist?
- Does it follow normal organizational rules?
Safe first response · IT support knowledge
Stop unsafe interaction, recognize warning signs, record only safe facts, and reach support through a channel you verify separately.
Do not call its number, reply, open its links, make a payment, disclose a password or code, install remote-control software, or grant remote access.
Use a support or security channel that you verify separately. If something was already shared or approved, stop interacting and report exactly what happened.
Legitimate support may contact you during an authorized case or scheduled service. Verify it without using contact details supplied by the questionable message.
Trusted-channel rule: never use the suspicious prompt’s telephone number, link, email address, or chat to verify whether it is legitimate.
These signs support a stop-and-report decision. They do not identify the sender or prove the condition of the device.
The device is described as infected or locked, and you are pressured to act immediately.
An error or warning tells you to call the number shown on screen.
The contact requests a password, verification code, recovery key, or unnecessary personal information.
You are asked to install remote-control software or approve remote access.
The contact demands gift cards, cryptocurrency, transfer, a payment app, or an urgent subscription.
You are told to bypass security controls, ignore policy, or hide the interaction.
End the visible interaction when possible, then move toward an honest report rather than an investigation.
Do not click, call, reply, download, pay, or approve access. If something was already shared, do not keep interacting to reverse it yourself.
If the tab or message closes through a normal familiar control, close it. If it will not close, becomes full-screen, or repeatedly returns, stop trying different fixes and contact authorized support.
Closing a window ends the visible interaction; it does not prove the device is safe.
Use a known help-desk portal, internal directory, official account page reached independently, or a trusted person responsible for the device.
Note the time, contact type, claimed organization, request, application or website involved, actions taken, and current device state. Do not reopen content to collect details.
Report whether remote access, credentials, personal information, payment, files, or accounts may be involved—without repeating sensitive values.
Let the authorized responder choose the appropriate device, account, payment, or security steps for the actual situation.
Tell the responder which category may be involved. Never resend a password, code, financial number, or confidential content.
| Exposure area | What to report |
|---|---|
| Remote access | Whether remote-control software was installed, opened, or approved and whether someone controlled the device. |
| Credentials | Whether a password, verification code, recovery key, or sign-in approval was provided. |
| Information | The type of personal or organizational information disclosed, without repeating it insecurely. |
| Payment | Whether a payment, transfer, gift card, cryptocurrency transaction, or subscription was attempted or completed. |
| Files or accounts | Whether files, email, browser sessions, cloud storage, or account settings were opened. |
A complete account is more useful than an attempted diagnosis.
Was it a pop-up, call, message, or email? What did it claim?
When did it happen, and which application, website, account, or device was involved?
Which links, buttons, downloads, calls, or approvals occurred before you stopped?
State the exposure category without repeating passwords, codes, or financial details.
Is the message visible, does the device respond normally, and has the contact tried again?
Which separately verified support or security channel are you using?
Do not investigate: do not reopen the prompt, collect logs, trace the caller, remove software, reset accounts, or apply a generic recovery sequence without authorized direction.
Organize the report, review ordinary Windows preparation guidance, or discuss an appropriate IT support opportunity.
General recognition and reporting guidance only. This guide does not determine compromise or replace authorized security, recovery, financial, or incident-response procedures.