Guide
Fake alerts, fake warnings and support scams
A description of a well-documented pattern, how to recognise it calmly, and where it is reported in Australia. Nothing on this page is about your device.
Quick answer
A long-running approach in this category involves a message, web page or phone call that claims a device has a problem, followed by a request for remote access or payment to fix it. The useful thing to know is structural: a web page cannot inspect the computer viewing it, and a security product that finds something reports it inside its own interface rather than by asking you to ring a number. Closing the page or hanging up costs nothing and resolves the situation. Scamwatch collects reports of this kind.
The shape of the approach
Descriptions published by consumer agencies over many years show a consistent sequence. Recognising the sequence rather than any individual detail is what makes it easy to disengage, because the details are changed constantly and the structure is not.
- Contact is made. A web page opened from a search result or an advertisement, an email framed as an invoice or renewal notice, a text message, or an unsolicited telephone call.
- An alarming claim is made. Something is described as wrong with a device, an account or a payment, in terms designed to be understood as urgent by someone who is not technical.
- A single channel is offered. A phone number to call, a chat window, a button. The channel is always one the other party controls, and it is always presented as the only way forward.
- Access or payment is requested. Remote access software to "diagnose" the problem, a payment to resolve it, or credentials and a verification code to "verify the account".
- The request escalates. Once access or a first payment is given, the amounts or the requests grow, often framed as a refund that was processed incorrectly and needs to be sent back.
Why a web page cannot know anything about your device
This is the part worth understanding once, because it settles the question permanently. A page in a browser runs inside a sandbox: it can see the size of the window, the browser's general identification string, the language setting and a rough location derived from the network connection. It cannot read files, it cannot list installed programs, and it cannot scan anything. A page that displays a list of problems found on your computer has generated that list from nothing, in the same way a horoscope is generated.
What such pages do use is the small amount of information every browser sends, dressed up to look specific. Naming the operating system is not a diagnosis; the browser announced it in the request header. Naming the city is not surveillance; it is an approximate lookup of the network address. Neither indicates that anything has been examined.
How legitimate software behaves instead
The contrast is simple enough to use as a test.
- Findings appear inside the application you installed, in its own window, and remain in its history afterwards. They do not arrive as a web page you did not open.
- Nothing asks you to telephone a number to resolve a detection. Support numbers exist, but they are found by signing in to your account, not supplied by the warning itself.
- No security vendor needs remote control of a computer to remove something its own product has detected.
- Payment is never taken to release a device from a warning message. Renewal is handled in an account area, on the vendor's own domain.
- Legitimate notices survive scrutiny: you can close everything, go to the vendor's site by typing the address yourself, sign in, and see the same information there.
The one habit that covers all of this
Never use contact details supplied by the message that alarmed you. Navigate to the organisation yourself — type the address, use the number on the back of the card, use the app you already have. This single habit defeats the entire category, regardless of how the approach is dressed. It is the same advice the Australian Cyber Security Centre and Scamwatch give, and it is worth saying to older relatives in exactly those words.
Variants that show up around subscriptions
Because this category is sold on renewing subscriptions, two variants are worth naming specifically. The first is the false renewal invoice: an email stating that a security subscription has renewed for an unexpectedly large amount, with a number to call to cancel it. The alarm is the point; the call is where the approach begins. The answer is to sign in to the account you actually hold and look at the subscription there, or to check the transaction with your bank.
The second is the refund reversal: a claim that a refund was processed for too much and that the difference must be returned, usually by transfer or gift card. No legitimate refund process works that way, and a request to return money by any irreversible method is the signal. Both variants are documented in the material Scamwatch publishes, and both are reported there.
If it has already happened
People who have acted on one of these approaches often delay reporting it because they feel foolish, which is exactly the wrong way round: these are well-designed and widely used, and the sooner a bank hears about a transfer the better the chance of stopping it. The order below is the practical one.
- Disconnect the session. If remote access software was installed, close it, disconnect the device from the network, and remove the software afterwards.
- Contact your bank straight away if any payment, card detail or transfer was involved. Time matters more than anything else on this list.
- Change the passwords that were exposed from a different device you trust, starting with email, because email is what account recovery runs through. Turn on multi-factor authentication while you are there.
- Report it to Scamwatch, and report cyber incidents to the Australian Cyber Security Centre. Reports are what allow patterns to be identified and warnings published.
- Tell the people who share the device or the accounts. Households are targeted more than once, and forewarning the next person is effective.
Related things that are not scams, but are worth questioning
- Optimiser and cleaner software that reports hundreds of problems on a new machine. Not fraudulent, but the count is a marketing device rather than a measurement.
- Browser extensions offering protection installed from somewhere other than an official store. Extensions see everything in the browser, which makes their source worth caring about.
- Search advertisements for support numbers. Reaching a vendor through a search result is how many people end up somewhere unintended; going to the vendor's own site first avoids it.
Helping someone else
If you are the person a family asks for help, two things work better than warnings. The first is establishing a rule in advance — that nobody in the household ever gives remote access or reads out a code, and that ringing you is always an acceptable response. The second is removing the embarrassment ahead of time, by saying plainly that these approaches fool careful people routinely. The eSafety Commissioner publishes material aimed at supporting older Australians online, and it is written for exactly this conversation.