Fraud & Deception

The Pop-Up Said Your Computer Was Infected. It Wasn't.

A pop-up warning said your computer was riddled with errors and security threats. Regulators say the warning was fake — and it worked on tens of millions of dollars' worth of frightened consumers.

A sudden pop-up warning of a virus, a corrupted registry, or a critical security flaw is designed to trigger one response: immediate action. According to the Federal Trade Commission, tech support companies Restoro and Reimage built a business around exactly that reaction, using fake error messages and scare tactics to convince consumers, particularly older consumers, that their computers were compromised and needed immediate, paid repair.DOCUMENTED

In March 2024, the two companies agreed to pay $26 million to settle FTC charges that they bilked tens of millions of dollars from consumers by duping them into buying computer repair services in violation of the FTC Act and the Telemarketing Sales Rule.DOCUMENTED In March 2025, the Commission announced it was sending more than $25.5 million of that settlement back to defrauded consumers.DOCUMENTED

Key facts
  • Restoro and Reimage agreed to pay $26 million to settle FTC charges in March 2024.
  • The FTC alleged the companies used fake error messages and scare tactics to sell unnecessary computer repair services.
  • The scheme targeted consumers broadly but particularly affected older consumers.
  • The settlement order prohibits the companies from misrepresenting security or performance issues in the sale, marketing, or distribution of any product or service.
  • The order also prohibits the companies from engaging in deceptive telemarketing going forward.
  • The FTC sent 736,375 individual PayPal refund payments to affected consumers in March 2025.

What the complaint alleges

According to the FTC, Restoro and Reimage's software generated alarming diagnostic messages designed to convince consumers their computers were riddled with errors, malware, or security vulnerabilities — diagnoses the agency alleged were false or grossly exaggerated, engineered specifically to frighten consumers into purchasing repair services and software licenses they did not actually need.DOCUMENTED The scheme relied on impersonating well-known software brands and security warnings in its pop-up messaging, blurring the line between the companies' own product and legitimate operating-system alerts a consumer might otherwise trust.REVIEWED

Why the tactic worked at scale

Scare-based tech support schemes succeed by exploiting a genuine and common anxiety: most consumers cannot independently verify whether a pop-up warning about their computer's security is legitimate, and the perceived cost of ignoring a real threat feels far higher than the cost of paying a modest fee to make the warning go away.REVIEWED That asymmetry, combined with software distributed widely enough to reach consumers across demographics, is part of why the settlement covered payments to more than 736,000 individual consumers — a scale that reflects a mass-market software distribution model rather than a targeted, individualized fraud.DOCUMENTED

The payment processor's role

Restoro and Reimage's tech support operation later became relevant to a separate FTC case: U.K.-based payment processor Paddle.com was found to have processed payments on behalf of tech-support telemarketers, including clients like Restoro-Reimage, and agreed in June 2025 to pay $5 million and accept a permanent ban from processing payments for tech-support telemarketers, with that payment specifically earmarked to supplement the redress fund for consumers harmed by the Restoro-Reimage scheme.DOCUMENTED The connection between the two cases illustrates how payment processors sit downstream of consumer-facing scams, and how regulators have increasingly pursued the financial infrastructure enabling a scheme alongside the scheme's direct operators.REVIEWED

More than 736,000 individual refund payments went out to consumers who paid for repairs their computers, according to the FTC, never actually needed.

Why the case matters

For consumers, the Restoro-Reimage case is a reminder that a pop-up warning urging immediate payment to fix a supposed computer problem is a recognized hallmark of tech support fraud, regardless of how alarming or official the messaging appears. Legitimate operating systems and antivirus software do not generally demand an urgent, unplanned purchase through a pop-up window; consumers who encounter this kind of alert are better served closing the window and checking their system independently, through their computer's own built-in security tools, than by clicking through to whatever payment page the pop-up leads to.

How scare-tactic software gets installed in the first place

Scanning and repair utilities of this kind are frequently bundled with free downloads of unrelated software, or advertised through banner ads on legitimate websites that promise to check a computer's performance for free, meaning many consumers who eventually saw an alarming diagnostic message had installed the underlying software believing it to be a harmless utility rather than the source of the fabricated warnings that would later appear.REVIEWED That distribution model, relying on broad, low-cost software bundling rather than individually targeted outreach, is part of why the eventual settlement reached hundreds of thousands of affected consumers rather than a smaller, more concentrated group.

Why older consumers were disproportionately affected

FTC data on tech support fraud broadly has repeatedly shown that older consumers report disproportionately higher losses in this fraud category compared to younger age groups, a pattern regulators attribute in part to older consumers being statistically less likely to have grown up using the specific operating systems and diagnostic tools the scam impersonates, making a fabricated warning message harder to immediately recognize as illegitimate.REVIEWED The FTC's complaint against Restoro and Reimage specifically flagged this demographic pattern as part of the underlying harm the settlement was designed to address, alongside the broader consumer base affected by the scheme.

What legitimate diagnostic tools look like by comparison

Operating systems like Windows and macOS include built-in, free diagnostic and security tools that do not require a separate purchase to identify or resolve genuine performance issues, and legitimate antivirus software generally does not generate alarming pop-up messages demanding an immediate purchase to resolve a detected problem mid-scan.REVIEWED Consumers who want a second opinion on a computer's actual condition are generally better served consulting a locally reviewed repair shop or the computer manufacturer's own support line than clicking through an unsolicited pop-up, however urgent its language. Regulators have continued to treat this category of software-driven scare tactic as a recurring enforcement priority, precisely because the underlying mechanism -- a false alarm paired with an immediate paid fix -- remains just as effective today as it was when Restoro and Reimage first deployed it.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →