# Fake ISP Support Calls and Messages: Red Flags to Watch

Source: https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection/fake-isp-support-scam-red-flags

**Answer:** Treat an unexpected “ISP support” contact as unverified when it requests a password, OTP, recovery code, remote-control app, immediate transfer or payment-detail change. End the contact and verify through the provider’s known website, customer portal or published number. A caller’s knowledge of your name, address or package does not prove identity.

Part of [Digital Safety, Privacy & Account Protection](https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection) · 10 min read · by UrbanX Knowledge Hub

**Last reviewed: 26 August 2026 · 10 min read**

### Why ISP impersonation works

Internet customers expect legitimate communication about:

- outages and maintenance;
- failed debit orders;
- router delivery;
- account verification;
- installation appointments;
- cancellation or migration; and
- security alerts.

A scammer can reuse these familiar situations. The technical language does not need to be correct; it only needs to create enough anxiety for the customer to follow instructions.

### Common fake-support stories

#### “Your router is infected”

The caller asks the customer to install remote-access software so a “technician” can remove threats.

#### “Your account will be disconnected now”

An SMS or WhatsApp link leads to a copied payment or login page.

#### “We need your OTP to verify you”

The code may actually approve a password reset, card transaction, SIM action or account login.

#### “Our banking details have changed”

The customer is told to pay an invoice into a new account supplied only in the message.

#### “Your line must be upgraded”

The scammer asks for card details, identity documents or a deposit for a fictitious device.

#### “We detected illegal activity”

Fear of legal action is used to demand secrecy, money or access.

### High-confidence stop signals

Stop the interaction if the person asks you to:

- read out a password, PIN, OTP or backup code;
- approve a sign-in you did not initiate;
- install remote-control software during an unsolicited call;
- disable security software or browser warnings;
- move money to a “safe” account;
- pay by gift card, cryptocurrency or unrelated personal account;
- send identity documents to an unverified number;
- keep the call secret;
- remain on the line while opening banking; or
- use only the callback details they provide.

Legitimate support processes differ, but secrets and independent verification remain reliable boundaries.

### Information that does not prove the caller is genuine

A criminal may know:

- the customer’s name and mobile number;
- home address;
- ISP or FNO name;
- package speed;
- part of an invoice;
- recent support activity;
- router brand; or
- an employee’s real name.

This information may come from social posts, leaked data, discarded documents, a compromised mailbox or informed guessing. Caller ID and WhatsApp profile branding can also be spoofed.

### Verify an ISP contact safely

1. End the call or close the message.
2. Do not click its links or use its callback number.
3. Open the provider’s known customer portal or type its official website.
4. Find the official contact details there or on a prior verified statement.
5. Ask whether the ticket, invoice or campaign exists.
6. Quote only a reference already visible in your genuine account.
7. If payment details changed, use a known finance contact and an established verification process.

A genuine matter can survive a short independent check. Urgency is not authority.

### Remote-access requests

Remote support tools allow another person to see or control a device. They are powerful and can expose email, banking, password managers and stored documents.

Do not install one because an unknown caller says the connection has a virus or refund problem. If remote assistance is genuinely required:

- initiate contact through the provider’s official channel;
- confirm the support case and technician process;
- understand what the tool can access;
- close sensitive apps;
- never open banking while another person controls the device; and
- remove unattended access when the authorised session ends.

This page does not state that every legitimate ISP uses or never uses remote support. The safety control is verified initiation and informed consent.

### OTPs and approval prompts

An OTP proves possession of a factor to the system requesting it. It is not a customer-service questionnaire.

Read the full notification. It may say:

- password reset;
- new device sign-in;
- payment authorisation;
- beneficiary addition; or
- contact-detail change.

Reject any prompt you did not initiate. Do not give a code to a person who called you, even if they claim it cancels fraud.

### If information or access was already given

#### Password or OTP disclosed

- Go directly to the genuine service from a trusted device.
- Change the password and any reused versions.
- end unknown sessions;
- repair MFA and recovery information; and
- check email forwarding or filters.

#### Remote access installed

- Disconnect the device from the network if the session is active.
- End the tool and remove unattended permissions.
- From another trusted device, protect primary email and financial accounts.
- Contact the bank immediately if banking was opened or a payment occurred.
- Use trusted security support to inspect the device.

#### Payment sent

- Contact the bank or payment provider immediately through a known fraud channel.
- Preserve the message, numbers, account details and proof.
- Follow current SAPS reporting guidance.

#### Identity document shared

- Preserve evidence.
- Ask the impersonated organisation about its fraud process.
- Monitor for identity and account misuse.
- Seek current South African identity-theft and credit-risk guidance appropriate to the data.

### Report the impersonation

Send evidence to the real ISP through its published fraud, abuse or support route. Give:

- date and time;
- caller or sender information as displayed;
- message screenshots;
- links without opening them;
- claimed ticket or account reference;
- requested action; and
- what information, access or money was provided.

Report the account in WhatsApp, email or the social platform. Where fraud or crime occurred, contact the bank and SAPS as appropriate. Do not publicly expose your own account data while warning others.

### Sources

- [Telkom Scam Alerts](https://group.telkom.co.za/about-us/scam-alerts.html)
- [Telkom: How to Spot a Scam and Protect Yourself](https://intouch.telkom.co.za/blog/how-to-spot-a-scam-and-protect-yourself/451)
- [FTC: How to Spot, Avoid and Report Tech Support Scams](https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams)
- [ISPA: How to Report Online Crime in South Africa](https://ispa.org.za/consumer-support/how-to-report-online-crime/)
- [SAPS Cybercrime Prevention Tips](https://www.saps.gov.za/alert/cybercrime_prev_tips.php)

### Related guides

- [All Digital Safety, Privacy & Account Protection guides](/knowledge-hub/digital-safety-privacy-account-protection)
- [How to Spot a Phishing Email, SMS or WhatsApp Message](/knowledge-hub/digital-safety-privacy-account-protection/spot-phishing-email-sms-whatsapp)
- [How to Check Whether a Website or Payment Link Is Legitimate](/knowledge-hub/digital-safety-privacy-account-protection/check-website-payment-link-legitimate)
- [What to Do After an Online Account Is Hacked](/knowledge-hub/digital-safety-privacy-account-protection/what-to-do-account-hacked)

## Frequently Asked Questions

**Will an ISP ever call about a fault or account?**

It may. The existence of legitimate outbound support is why independent verification is necessary. Call back through a known official channel.

**Can a support agent ask security questions?**

Providers use different verification processes. A password, full PIN, OTP or recovery code should not be disclosed to someone who initiated an unverified contact.

**Is caller ID reliable?**

No. Displayed numbers and names can be spoofed. Verify the case independently.

**What if the caller knows my exact package and address?**

Treat those as context, not authentication. Leaked, public or previously compromised data can be accurate.

**Should I let a technician access my router remotely?**

Only under a verified provider process you understand. Router administration and security settings belong in [Pillar 6](/knowledge-hub/competitive-security-edge-config-continuity).
