Quick Assist scams: what to do if a caller asked for your code
Quick Assist is built into Windows, so scammers love it. Here's how the trick works and what to do if you shared your screen.
If someone you didn't contact asked you to open Quick Assist and read them a code, it's almost certainly a scam. Quick Assist is a real Microsoft tool that comes with Windows, but Microsoft doesn't call people out of the blue to fix their computers. If the session is still open, close the Quick Assist window, hang up and disconnect the PC from the internet.
Scammers like Quick Assist because there's nothing to download. It's already on most Windows 10 and 11 computers, it carries the Microsoft name, and it looks official. That makes the request feel safe when it isn't.
What is Quick Assist and why do scammers use it?
Quick Assist lets one person see, and then control, another person's Windows PC. It's meant for a family member or an IT department helping someone they know.
Here's how it works. The helper signs in with a Microsoft account and gets a short security code. The person being helped opens Quick Assist, types that code in, and agrees to share their screen. The helper can then ask for full control, and if you click Allow, they can move your mouse, type, open files and install programs.
A scammer plays the helper. They don't need you to install anything or visit a strange website. They only need you to open an app that's already there and read out or type in a code.
How does a Quick Assist scam usually start?
Most of these calls begin with something that frightens you first. Common starts include:
- A pop-up in your browser saying your PC is infected or locked, with a phone number to call.
- A phone call from someone saying they're from Microsoft, Windows support, your internet provider or your bank.
- At work, a flood of junk email followed by a call or Microsoft Teams message from someone saying they're from your IT help desk and can fix it.
Microsoft has reported that one criminal group used that last pattern to get into company networks through Quick Assist and then install ransomware. The same trick is used on people at home, just with a different story.
Once you're on the phone, the caller walks you through it. They might tell you to press the Windows key, Ctrl and Q together, which opens Quick Assist. Then they read you a code, ask you to type it in, and tell you to click Allow when a box pops up. Quick Assist shows a warning that scammers may pretend to be from Microsoft, and callers often tell people to ignore it or say it's normal.
Is it safe to give someone my Quick Assist code?
Only if you started the conversation and you know exactly who they are, like your son, a friend or your company's IT team that you called yourself.
It's never safe if:
- They called you, emailed you or messaged you first.
- You found their number in a pop-up, a text or a search ad.
- They say there's a virus, a hacker, a refund or a problem with your bank account.
- They want you to stay on the phone, keep it secret or not tell your bank.
A real Microsoft employee won't phone you about your PC, and won't ask you to open Quick Assist unless you contacted Microsoft support yourself.
They're connected right now. How do I stop it?
Act fast. You don't need to be polite.
- Close Quick Assist. Click the X at the top right of the Quick Assist window, or click Leave if you see it. This ends the session.
- If you can't close it, turn off the internet. Unplug the network cable, or switch off Wi-Fi from the network icon at the bottom right of the screen. If the mouse is moving on its own, hold the power button until the PC turns off.
- Hang up the phone. Don't call them back, even if they say something is broken.
- Call your bank from a different phone, using the number on the back of your card, if you opened any banking site or gave card details.
- Change your email password from another device, like your phone or a different computer.
For the full step-by-step list, follow our two-minute checklist.
They had control. What should I check next?
Quick Assist closes when the session ends, but a scammer with control could have installed something else while they were in. Many install a second remote access program, such as AnyDesk, ScreenConnect or TeamViewer, so they can get back in later without asking you.
To check, open Settings, then Apps, then Installed apps (on Windows 10 it's Apps, then Apps & features). Sort by install date and look for anything added on the day of the call. Uninstall any remote access program you didn't put there yourself. Our guide on how to tell if someone is controlling your PC shows other signs to look for.
If they asked you to log in to your bank, showed you a "refund" or had you buy gift cards, read what to do after a remote access scam. It covers your bank, your passwords and getting the PC looked at by someone you trust.
You can report the call to Microsoft at microsoft.com/reportascam and to the FTC at ReportFraud.ftc.gov. If you lost money, also report it to the FBI at ic3.gov.
Can I remove Quick Assist so this can't happen?
Yes. If nobody uses Quick Assist to help you, you can uninstall it. Open Settings, then Apps, then Installed apps (Apps & features on Windows 10), find Quick Assist, click the three dots or the entry itself, and choose Uninstall. You can reinstall it from the Microsoft Store if you ever need it.
That won't stop a scammer from asking you to install a different tool, though. The remote access scams guide explains the other programs they use and the stories they tell.
Some people add a second layer. Xcelcor Guardian is a Windows 10 and 11 app that holds every new remote connection, including Quick Assist, AnyDesk, TeamViewer and ScreenConnect, until the account holder approves it by email or on xcelcor.com. The PC only gets a Refuse button, so a caller can't talk you into letting themselves in. It isn't antivirus and won't stop every scam, but it puts a pause between the caller and your computer. You can see how it works.
These scams catch careful, sensible people every day. If it happened to you, the steps above are what matter now.
Last updated