Fake alerts and support scams
A recurring category of fraud borrows the vocabulary of security software: a browser page styled to look like a system warning, a telephone call from someone claiming to be technical support, an emailed invoice for a subscription renewal nobody arranged. This page describes the patterns, the reasoning that defeats them, and where in Australia to report and get help.
The one rule that covers most cases
Contact initiated by someone else — a pop-up, a call, an email, a text — is never a safe route to verify a problem. Close it, and check independently: type the vendor's or bank's address yourself, or use a number from a statement or the back of a card. Every pattern below fails against that rule.
Why a web page cannot know anything about a device
The foundation of the browser-based version of this fraud is a misunderstanding worth correcting directly. A page loaded in a browser runs inside restrictions that prevent it from reading files, listing installed programs or examining a device for malware. A website that displays a scan in progress, a list of infections found, or a count of problems detected is displaying an animation written in advance. It is the same animation for every visitor.
What a page can see is limited and unremarkable: the browser and operating system version it advertises, the screen size, an approximate location derived from the network address. Those details are sometimes inserted into the text to make it appear specific — naming the browser, or the city — and their presence is a sign of the technique rather than evidence of a real inspection.
The patterns
The browser warning that will not close
A page appears, often after a redirect from an advertisement, presenting a warning styled to resemble an operating system dialogue. It may enter full screen, play a sound, repeat an alert box, or disable the back button, and it displays a telephone number for support. The content is a web page and nothing more. Closing the tab, or ending the browser process through Task Manager on Windows or Force Quit on macOS, ends it. Reopening the browser afterwards without restoring the previous session prevents it from returning.
The unsolicited telephone call
A caller states that a problem has been detected on the household's computer or internet connection, and asks for remote access to demonstrate it. The request for remote access is the object of the call: once granted, ordinary system logs and diagnostic screens can be presented as evidence of infection, and the conversation moves to payment or to a bank transfer. No software vendor, internet provider or platform company telephones consumers unprompted about malware on a specific device. Scamwatch describes this category and collects reports of it.
The renewal invoice that never was
An email or text confirms that a security subscription has renewed for an amount the recipient does not recognise, and offers a number or link to cancel or dispute it. The pressure comes from the apparent charge, and the intended response is to use the contact details provided rather than the account that would show no such charge. Checking directly — the vendor's site, the card statement — resolves it without ever contacting the sender. The subscription page covers what a genuine renewal looks like.
Software that was never wanted
Downloads presented as system optimisers, driver updaters or free scanners sometimes install additional software, change browser settings, or report problems that do not exist in order to sell a fix. The defence is upstream: install software from the vendor's own site, an operating system's store, or a distribution's repository, and treat a scanner advertised through a pop-up as the thing being guarded against.
If remote access was granted or payment was made
Acting in order is more useful than acting quickly. The sequence below reflects the guidance published by Australian agencies, which are linked in full at the end of this page.
- Disconnect the device from the internet if remote access may still be active, and end any remote access session.
- Contact the bank or card issuer immediately if payment details were given or a transfer was made. Banks have processes for recent transactions and time matters for them.
- Change the passwords for email and banking first, from a different device that was not involved, and switch on multi-factor authentication where it is not already on. Email comes first because it is the reset route for everything else.
- Report the incident. Scamwatch takes scam reports, and ReportCyber, run by the Australian Cyber Security Centre, takes reports of cybercrime.
- If personal identity documents were shared, contact IDCARE, the national identity and cyber support service for Australia and New Zealand, which provides free case management.
- Have the device checked or reset if unfamiliar software was installed during the session. A reinstallation from a known-good state is the thorough option.
Signals that recur across all of these
- The contact arrived unsolicited, and supplies its own contact details for verification.
- There is time pressure — an account closing, a charge settling, a threat expanding.
- The requested action is unusual: remote access, a gift card, a transfer to a new account, or moving the conversation to another messaging application.
- The problem cannot be verified anywhere else. A genuine issue with an account is visible when logging into that account independently.
Why the approaches persist
These patterns endure because they do not attack software at all. They borrow an interface people have learned to trust and pair it with a plausible reason to act immediately, which suppresses the step that would resolve it — checking somewhere else. That is also why age is a poor predictor of who is affected: the determining factor is usually whether the approach arrived at a moment when checking independently felt like an unnecessary delay.
The useful consequence is that the defence is procedural rather than technical, and it can be agreed in advance within a household: nobody grants remote access to a caller, nobody acts on a warning that supplies its own phone number, and anything financial is confirmed on a second channel before money moves. A rule settled calmly in advance survives a situation that is designed to feel urgent.
Where to go in Australia
These services are free, public and the appropriate first stop for anything on this page.
- Scamwatch, run by the National Anti-Scam Centre at the ACCC — scam reporting, and current descriptions of what approaches look like.
- ACSC report and recover — reporting cybercrime and step-by-step recovery guidance.
- IDCARE — support after identity information has been compromised.
- eSafety Commissioner — online safety complaints, including image-based abuse and cyberbullying.
- OAIC notifiable data breaches — what an organisation must do when a breach is likely to cause serious harm.
- ACCC — consumer law, including misleading conduct by businesses.
What software does and does not contribute
Web and phishing filtering blocks known fraudulent addresses, which helps at the moment someone has already been persuaded to click, and a password manager refuses to fill credentials on a domain that does not match — a quiet and underrated defence against convincing copies of sign-in pages. Neither intervenes in a telephone call, and no product in this category prevents a person from authorising a transfer. That is why this page sits in a library about software while spending most of its length on things software does not do.