Three people are facing charges in a large-scale tech support scam. FBI agents arrested a member of the operation and turned him into an informant to learn as much as possible about the activities and actions of the members who carry out these scams. The evidence provided by the informant, as well as court documents filed in the case, reveal the techniques and inner workings of a tech support scam – from the initial stages to the methods used by the scammers to launder funds from their victims. Of the three suspects named in the case, one was arrested earlier this year and pleaded guilty this week.
It is worth noting that while the charges against the three suspects who appear to be involved in the tech support scam operation were filed in January 2020, the investigation into this group had already begun in May 2019, when the FBI arrested an Indian national, who was charged with fraud.

According to court documents, one of the suspects agreed to cooperate with investigators and become an FBI informant, asking for leniency from US in his case. The informant admitted to FBI agents that he was an active member of a tech support scam operation, and even provided the names of three of his associates – all three were Indian nationals. In addition, two of the suspects owned call centers in India, while the third of them lived in the US, where he acted as a money mule. Specifically, he received money from victims into his US bank accounts and then transferred the money to call center operators.
The informant then stated that he operated the business as a “broker” and sold “call traffic.” According to the informant, the brokers are the second stage in an online tech support scam scheme. The first stage is what the informant described as “publishers.” These are criminal groups that create the actual tech support sites that display misleading error messages and pop-ups urging users to call a toll-free number. The publishers then sent online advertisements on platforms like Facebookabout various topics, such as travel, but redirected users who clicked on the ads to their malicious sites.
On the other hand, brokers acted as intermediaries between publishers and call centers. They operated servers , through which they sold “call traffic” to a call center operator who was willing to buy it.
Furthermore, the informant, who agreed to provide the FBI with access to his device and record calls, reported that most of these negotiations took place via WhatsApp and other online chat apps.
Call center owners contacted brokers, agreed on a price per batch of calls, and provided a number to which the broker would re-route incoming calls from tech support scam victims.

The business the whistleblower was involved in used technical support pages that appeared as Microsoft. The alerts informed visitors that they had been infected with malware and that they should call a phone number to learn more details and get help from a Microsoft employee. According to the indictment, the victims of these scams were senior citizens who lacked the technical skills to determine that the security alert was false and malicious.
Instant messages and phone calls recorded by the FBI also allowed agents to learn how the operation was proceeding when victims connected to the call center.
According to court documents, the call center employees tried to convince callers to download and install a version of SupRemo remote control software on their computers. This software would allow call center operators to log into the targeted victim’s computer and fix the alleged “technical problem.” At the end of this operation, the victims were asked to pay for the technical assistance they received, usually via bank transfer or through gift cards obtained from local stores.
According to a recorded phone call the informant had with a call center owner, call center operators would often ask victims to log into their bank accounts, while the operator would still have access to their systems, allowing the operator to collect credentials from prospective victims.

Similar experiences were also reported by previous victims, whom FBI agents contacted during their investigations. The money, taken as payments or secretly stolen from the victims' bank accounts, is typically transferred to intermediary bank accounts controlled by money launderers.

At the FBI's request, the informant also agreed to serve as a money transmitter and used one of these intermediary bank accounts, which the FBI then used to track the payments and entities involved in these scams.
Court documents only mention a handful of victims who lost money after being duped by tech support scams, with estimated losses estimated at around $10,000 USD. However, the actual losses from this operation are believed to be in the millions of dollars, as this tech support scam appears to have been operating since 2017, and the actual number of victims is likely much higher than reported in the court documents.
U.S. authorities filed formal charges in January 2020 against three suspects, whose names were provided by the whistleblower. The call center operators remain at large in India, but one money launderer was arrested in February 2020 while trying to board a flight from New York to India. The money launderer, named Abrar Anjum, pleaded guilty on Monday. He is scheduled to be sentenced in October and faces a maximum sentence of up to 20 years in prison.
