Scammer number: 833-253-0186
Popup link: No link. This information was passed on to me after the scam was in process.
Any other scammer information: This was a Microsoft Tech Support Scam popup that was initiated through a Facebook Ad when my mother was expecting a Friend Request from a relative. There are multiple other numbers and people involved as this was a little more elaborate than other scams I’ve seen/heard recently.
When the “Microsoft Alert” popped up, the number presented was the one attached to this post - 833.253.0186. the “tech” called herself “ALINA” (Indian Accent) claiming her MSID was MS214. If they were to get disconnected, another (local) phone number was provided. [However, when my mother called this number later is was a spanish speaking older woman. I’m guessing no relation, because they didn’t intend to be disconnected.]
ALINA had her enter some commands on her computer, using Ctrl+R. [This was when UltraViewer was likely installed]. At this point, her computer screen blacked out and when it came back on, the “tech” showed her some text in the CMD window (see image) and convinced her that her “computer had been hacked”.
At this point, ALINA passed my mother on to a guy named “Daniel Martin” (hispanic accent) [apparently] because something showed that at 4:00am she had been hacked by a website called www.hotdog.com and that they had her permission to give them $19,000 for a subscription to P0rn Hub by clicking #1. [I know, none of this makes sense, but this is what she told me].
Daniel then proceeded to tell her that he was going to transfer her to (her bank name) Fraud Department and that he would connect her to them. [Again, makes no sense that MS could transfer anyone to their own bank]. Anyway, this transferred to a “Peter Miller” (another hispanic accent). His phone # was given as 833-656-9085 x1140 [I have not tried this, so I don’t know if it is legitimate or not].
Peter Miller was the scammer who sent her to her bank to withdrawl the $19,000 using some b.s. excuse to need the money (used car from a relative or something like that). When she couldn’t access the funds she finally had the wherewithal to get ahold of me through my Ring Doorbell Cam. At this point she still had the guy on the phone (which was in her car). So I told her to go get the phone and just hang up on the guy.
After all that was done I was able to get on her computer and I pulled this information out of the UltraViewer Logs. I was able to uninstall and report the below to UltraViewer:
- 2/4/2026 12:15:32 PM|126948091|MICROSOFT SERVER|RandomPass|122.161.51.246
- 2/4/2026 2:41:04 PM|200816048|MICROSOFT-SERVE|RandomPass|122.161.51.246
- 2/4/2026 2:59:55 PM|126948091|MICROSOFT SERVER|RandomPass|122.161.51.246
- 2/4/2026 3:24:53 PM|99054608|MICROSOFT|RandomPass|106.219.229.182
- 2/4/2026 3:27:34 PM|126948091|MICROSOFT SERVER|RandomPass|122.161.51.246
And I’m now making it a MISSION to help hunt scammers.
