Case Study

Catching a Tech Support Scam in Progress on a Kingston Client's Home Computer

Residential May 12, 2026
Catching a Tech Support Scam in Progress on a Kingston Client's Home Computer

The situation

One of our long-time clients retired a few years back and kept us on to look after his home computer. We patch it monthly, manage updates and run business-grade endpoint protection on the machine. The same tools we deploy across our managed business clients, scaled down for a single workstation.

Late one evening, an alert came in. Suspicious activity on the system, after the client had gone to bed. The endpoint protection had already locked the machine down on its own before anyone at our end had touched it.

What was happening

When we pulled the alert apart, the picture came together quickly.

The client had been on the phone with someone claiming to be from a well-known software company. He’d been walked through installing a remote support tool. Not malware. Legitimate commercial software, signed by a known vendor, the same kind a real IT company would use to help a customer over the phone. A traditional signature-based antivirus would never flag it.

Once the remote session was open, the scammer started showing the client a series of fake warning screens to convince him his computer was infected and needed urgent help. Classic tech support scam pattern. The end goal is almost always the same: payment, usually through gift cards or a wire transfer.

What our endpoint protection caught wasn’t the remote tool itself. It was the behaviour around it. A brand-new install opening a remote session, paired with rapid file and registry activity that didn’t match anything the client would normally do. The combined signals were enough for the system to flag it as a probable threat and isolate the machine on its own.

What we did

The system was already locked down by the time the alert hit us. First thing the next morning, we called the client and walked him through what had happened. He was rattled, but no money had changed hands and no files had been touched.

From there:

  • Removed the remote access tool and confirmed nothing else had been left behind
  • Reviewed the system for any persistence or follow-on payloads
  • Rotated relevant passwords on his accounts as a precaution
  • Talked him through how the scam works so he’d recognize the next attempt

He was back online the same day, no data lost.

The takeaway

Old-style antivirus looks for known bad files. That’s not how most scams work anymore. The tools attackers use are often legitimate, which is why behavioural detection matters, whether the machine sits in a Kingston office or in someone’s living room. If a family member or retired parent in your life is running consumer antivirus on their computer, that’s a gap worth closing.

Work With Us

Got a similar problem on your plate?

Tell us what you're dealing with. We work with Kingston and Eastern Ontario businesses on everything from managed IT to one-off projects, and we'll give you a straight answer on how we can help.

Prefer to call? (613) 384-6735

Tell us what you need

We typically respond within 2 hours during business hours.