Fake alerts, fake scans and support scams
The short answer
A web page cannot scan your computer, and a legitimate security warning never arrives with a telephone number attached. The scam works by producing something that looks like a system alert inside an ordinary browser window, and by making the reader feel they must act immediately. Understanding the mechanism removes most of its power, because once you know what the page can and cannot do, the alarming part stops being persuasive.
What is actually happening on the page
A browser tab is deliberately walled off from the rest of the computer. A page can draw whatever it likes inside its own area — including a convincing replica of a system dialog, a progress bar, a list of file names, a siren sound, a warning in the style of an operating system you are not even running. What it cannot do is read your files, enumerate your installed software, or determine whether anything is wrong with your device. Every “scan” that runs in a web page is an animation written in advance, and it displays the same result to everyone.
Several techniques make the illusion stronger. The page may go full screen so the browser’s own frame disappears. It may capture the back button so leaving seems impossible. It may open dialog boxes repeatedly so the tab cannot be closed by ordinary clicking. It may play audio, which is effective precisely because software does not usually make noise. None of these indicate a compromised machine; they are all things any web page is capable of.
The tell that cuts through all of it is the telephone number. Operating system vendors do not put support numbers in error messages, and security software does not ask you to ring anyone. A number on the screen is the reason the page exists.
How the call usually goes
Ringing the number connects to a call centre with a rehearsed sequence. The person is polite, patient and technical in manner. They will ask you to install a remote support tool — usually genuine commercial software, which is what makes the request seem reasonable and what allows it to pass a virus scan.
With access granted, they show you evidence. The Windows Event Viewer is a standard prop: it lists warnings and errors on every healthy computer, and someone who does not know that will find pages of red and yellow entries alarming. A command-line window may be used to display network connections, presented as intruders. A folder of temporary files may be described as infections.
Then comes the remedy: a support contract, a cleaning fee, a licence for software you do not need, paid by card, bank transfer, gift cards or cryptocurrency. The less reversible the payment method, the more it will be pushed. In some versions the operator also opens your banking site while connected, or installs something that lets them return later.
Reliable tells
- A security warning that appears inside a browser tab rather than in the operating system’s own notification area.
- Any telephone number presented as technical support inside an error message.
- An unsolicited call, text or email claiming a problem with your device, account or internet service.
- A request to install remote access software so someone can “show you the problem”.
- Pressure not to hang up, not to consult anyone, or to stay on the line while paying.
- Payment by gift card, cryptocurrency or direct transfer to an individual.
- A warning naming an operating system or product you do not use.
If a fake alert is on screen right now
Nothing has happened to your computer, and nothing needs to be done quickly. Close the tab. If it will not close, close the whole browser — on Windows with the task manager, on macOS by force quitting. Reopen the browser and decline any offer to restore the previous session, since that will bring the page back. Do not ring the number, and do not install anything the page suggests.
If you have already engaged
This is recoverable, and acting methodically matters more than acting fast. Work through it in order.
- Disconnect the device from the internet, which ends any remote session immediately.
- If payment details were given, contact your bank straight away and ask about stopping or reversing the transaction. Banks have processes for scam payments and time affects what is possible.
- Uninstall any remote access software that was installed, and any other software added during the session.
- From a different device you trust, change the passwords for email and banking first, then anything else of value. Email first, because it is the reset route for everything else.
- Turn on multi-factor authentication where it is available, and sign out of all active sessions in each account’s security settings.
- Run a full scan with the security software already on the device, and check what is set to start automatically.
- If the device holds anything sensitive and you cannot be confident it is clean, reinstalling the operating system is the thorough option.
- Report it, using the services below.
Nobody should feel foolish about this. These operations are professionally run, rehearsed and designed to be convincing to careful people. Reporting is more useful than embarrassment.
Reporting it in Australia
- Scamwatch, run by the National Anti-Scam Centre at the ACCC, collects scam reports and publishes information on current scam types.
- The Australian Cyber Security Centre takes reports of cybercrime and cyber security incidents, and publishes guidance on what to do after one.
- Your bank or card issuer, as early as possible, for anything involving a payment.
- The Office of the Australian Information Commissioner, where personal information has been mishandled by an organisation.
- The eSafety Commissioner, for online abuse, image-based abuse and cyberbullying, which have their own reporting schemes.
Related patterns worth recognising
Fake subscription renewal notices. An email states that an antivirus or software subscription has renewed for a large amount and offers a number to ring for a refund. The aim is the same call. Check the charge in your own bank statement and in the vendor’s account portal, reached by typing the address yourself.
Search advertisements for support numbers. Searching for a company’s support line can return paid results that are not the company. Reach support from inside the product or from the address printed on your documentation.
Fake update prompts. A page offering a browser or media player update that must be downloaded from that page. Real updates come through the browser or the operating system, not from a website you happened to visit.
Impersonation of a real security brand. Scammers use the names of well-known products because the names are trusted. The name in a message is not evidence of who sent it. Nothing on this site should be taken as a support channel for any vendor; StrataSpace is an independent publisher, not a reseller or support provider for any product it describes.