Recently, a friend and fellow parishioner phoned early in the morning on a computer-related matter. I could tell from the tone of his voice that he was concerned, if not outright worried.

His opening words, after we exchanged greetings, were, “My wife was browsing the internet on her iPad when a warning from Apple appeared, with a phone number.”

I interrupted him and said, “John, tell me you didn’t phone that number.”

“Yes,” he replied, “I did phone.”

Again, I interrupted him: “John, tell me you didn’t pay anything.”

Once again, the dreaded tech-support scam had claimed another victim. Or victims. John and Jane (let’s call them) had forked over $400 via credit card payment.

Before going any further in discussing the details of the scam, I told John he should do two things: phone the credit card issuer and request a reversal of the charge, and turn off or disconnect from the internet any device the scammers had worked on.

I also asked him to send me copies of any communication he had engaged in with the scammers.

We’ve been here before in this column, on just this sort of matter. The basics haven’t changed in at least a decade: prey on the fears of unsuspecting people, unfortunately all too often seniors; give the scam a veneer of credibility, say through a website or 1-800 phone number; throw in a calm, perhaps even reassuring, voice, and the fraud is well on the way to completion.

In the case of the scam that struck John and Jane through their iPad, numerous red flags made an appearance, but in the worry over losing access to their device, most of these weren’t noticed.

Let’s go over some of those warning signs. You are on an iPad, randomly browsing. A popup shows up on the screen. It contains a warning and a phone number urging you to take immediate action. You believe it to be legitimate because it contains the word “Apple” and the word “hacking.” (I didn’t see this particular popup, but based on the rest of the scam I’m confident it contained grammatical errors. Besides, the odds of a legitimate note popping up from Apple while on a random site are infinitesimally small.)

You then place a call to the 1-800 number on the popup. Someone answers and you are essentially read a script about your device having been hacked and about the nasty consequences that can occur therefrom.

Now the big one. You are transferred, supposedly, to a company, in this case named PCLogical LLC. The representative gives an instant estimate of 90 minutes to “fix” the problem. 

A quick check of the domain ThePCLogical.com throws up a gauntlet of red flags. Besides almost incomprehensible grammar, the address for the company in Madison, Wis., which John and Jane were given over the phone, turns out to be non-existent. The address appears on the web site alright, but in fact it does not exist. 

At this stage our victims are offered a “fix” in the form of four options ranging in price from $300 to $1,000, all in U.S. dollars, the former being a supposed three-year service and protection plan, the latter being a “lifetime” plan – the word “lifetime” not being defined.

John and Jane opt for the cheapest solution despite pressure to accept the most expensive one. The person on the phone drafts up a technical service agreement, relatively error-free, but, big red flag here, makes no reference to fixing an iPad. All the references are to dealing with a laptop, a Windows laptop, the existence of which came to light in the initial questioning.

There is a lot of bafflegab in the agreement about installing antivirus, ad blocking (misspelled as add blocking), network monitoring software (likely a keystroke logger), and more, but no reference to the iPad. 

Now the scam really takes off for John and Jane. They have agreed to let the scammers repair their iPad. The scammers request and are granted access to their Windows 8 laptop. The scammers then ask for a USB connection from the laptop to the iPad. They then request that the iPad be turned off while they proceed to “work” on the laptop. A huge red flag! Why “work” on the laptop when the call was about the iPad?

According to John and Jane the scammers were pleasant and seemingly helpful. Payment was made by Visa credit card and John and Jane even completed a satisfaction survey about the service they received. A receipt was provided via email, but, and here’s another red flag, the amount spelled out in the agreement and the amount on the receipt differed by a penny.

That’s it. The scam is over. Money has changed hands. Yes, the iPad works, but it’s not clear if there was anything really amiss with it that a power cycle wouldn’t have fixed.

There are, however, bigger worries. That laptop needs to be wiped. It cannot be trusted. Even a rollback to an earlier restore point could be suspect. I think most of the hour and a half the scammers spent with John and Jane was to install hidden applications on the device, likely with a view to intercepting banking transactions at some point in the future. 

“Yes,” John tells me, “I was hesitant, but as I said, it (the popup) appeared to come from Apple, so I called. In hindsight I should have looked up the Apple number directly and called them first.”

Once John and Jane had finished dealing with the credit card company, which indeed reversed the $400 Canadian fee, John said he phoned back to the scammers to tell them the “agreement was off and the charge reversed.”

John noted that “they really scrambled to find out why and described how they had put a lot of time and expense into this and that I should stick with it. I finally had to get assertive and demanding and had to hang up. They called back trying to sway me and I had to hang up again. They called back a few times again but I didn’t answer.”

There is some evidence that the scammers also tried to get control of John’s Android phone since shortly after paying he received an email concerning his backup email account for that phone.

To summarize, John and Jane came away from this incident with little in the way of damage. Their $400 payment was reversed, they deactivated their credit card and obtained a new one, and they are considering the purchase of a new laptop, since wiping and upgrading the compromised laptop is likely going to be a significant fraction of the cost of a new machine.

Most important, however, they won’t be phoning any 1-800 numbers that pop up on their screens.

Follow me on Facebook (facebook.com/PeterVogelCA), on Twitter (@PeterVogel), or on Instagram (@plvogel) 

pvogel@outlook.com