Fake security alerts and tech support calls
How imitation warnings are built, why a web page cannot examine your computer, and the calm sequence to follow when one appears.
Quick answer
A web page cannot scan your device, read your files or detect an infection. Browsers isolate pages from the machine they run on, by design. Anything on a website that appears to examine your computer is an animation written to look convincing. The same applies to a phone call claiming your computer is reporting errors: nobody receives such reports, and the call is a sales script. Close the tab, hang up, and check anything that concerns you inside the software already installed on the device.
Why a website cannot see your device
This is the fact that makes the whole category of fake alert collapse, and it is worth understanding rather than memorising.
A browser runs web pages inside a sandbox — a restricted environment with no access to the file system, no access to other applications, and no ability to inspect what is installed. A page can learn a small amount about the browser itself: roughly which browser and version it is, the screen size, the operating system family, and the approximate location suggested by the network connection. That is the entire inventory, and it is the same information every site receives from every visitor.
So when a page displays your operating system name and a progress bar reporting infected files, it has combined one piece of information any site can read with a scripted animation. The file names it lists are fabricated. The count is a random number or a fixed one. The progress bar is a timer. None of it touched your computer.
Genuine security software does not deliver its findings through a web page in a browser tab. It uses the operating system's own notification system or its own application window, and it never asks you to call a phone number.
The recurring formats
| Format | What it looks like | The tell |
|---|---|---|
| Simulated scan | A page that opens, appears to check the device, and reports threats found, often with a progress animation. | It is inside a browser tab, and it arrived from a link or an advertisement rather than from software you installed. |
| Fake system dialog | An image styled as a Windows, macOS or Android dialog box, sometimes filling the screen, sometimes preventing the tab from closing. | A real system dialog cannot appear inside a web page. Try moving the window — a fake dialog moves with the page content and scrolls with it. |
| Expiry notice | A message that a security subscription has expired, with a renewal button. | It names a product you may not use, or names one you do use but arrives through a browser rather than through the application. |
| Invoice email | An email confirming a renewal charge for software, with a phone number to dispute it. | The phone number is the point of the message. A genuine receipt would refer you to an account page, and the charge would appear on your statement. |
| Unsolicited call | A caller states that your computer is sending error reports or has been detected transmitting viruses. | No such reporting system exists. Operating system vendors and telecommunications carriers do not telephone individuals about device health. |
The Scamwatch service, run by the National Anti-Scam Centre, publishes current examples of these approaches and collects reports of them. Checking a suspicious message against those published examples is often the quickest way to settle it.
What a genuine notification looks like
Knowing the honest version makes the imitation obvious.
- It appears in the operating system's notification area or in the security application's own window — not in a browser tab.
- It names a specific file and a specific location on your disk.
- It reports an action already taken: blocked, quarantined, removed. It does not ask you to authorise a payment to complete the removal.
- It contains no phone number and no urgency language.
- Its contents are repeated in the product's own history or log, which you can open yourself at any time afterwards.
That last point is the reliable test. If a warning is real, you can find it again inside the software, on your own initiative, with the browser closed.
When an alert appears
Do not use anything on the page
No buttons, no phone number, no download, no chat. Interaction is what the page is for.
Close the tab
If the tab will not close, close the whole browser. On Windows, Task Manager ends the browser process; on macOS, Force Quit does the same; on a phone, closing the app from the app switcher works.
Reopen without restoring
When the browser offers to restore previous tabs, decline. Restoring loads the same page again.
Check inside your own software
Open the security product already installed on the device and look at its scan history. If nothing is there, nothing happened.
Run an on-demand scan if it settles your mind
It costs time and nothing else, and it produces a result you obtained yourself rather than one a stranger told you.
Full-screen pages that block the close button are using a browser feature, not controlling your computer. Pressing the Escape key exits full screen, after which the tab closes normally.
Calls asking for remote access
The most costly version of this pattern is a telephone call rather than a web page, because a persuasive conversation achieves what a pop-up cannot. The script varies but the destination is consistent: the caller wants remote access software installed, so they can operate the computer while you watch.
Remote access tools are ordinary, legitimate software used every day by IT departments and support desks. Installing one at the request of somebody who telephoned you is what makes it dangerous. Once connected, the caller can open your banking session, move money, install other software, and display whatever they like on your screen — including a fabricated refund that appears to have been overpaid, which sets up a request that you return the difference.
Points at which the call reveals itself
- You did not initiate contact, and the caller knew to reach you rather than the other way round.
- The caller needs you to install something before anything can be diagnosed.
- The caller directs you away from the phone number printed on your own bank card or account statement.
- Payment is requested through gift cards, a cryptocurrency transfer, or a bank transfer to an individual's account.
- Pressure increases when you say you want to check first. A genuine support process is comfortable with you calling back on a number you looked up yourself.
Hanging up is a complete response. There is no obligation to explain, and no consequence to ending a call you did not ask for.
If something has already happened
Acting on one of these is common and the sequence afterwards is well established. Speed matters more than working out exactly what occurred.
Contact your bank first
If any payment or account details were shared, telephone your bank using the number on your card or statement. Banks have processes for halting and attempting to recall recent transfers, and they work best within hours.
Disconnect and remove remote access software
If anything was installed, disconnect the device from the internet, then uninstall the remote access application. If you are not confident doing that, a local repairer you chose yourself can.
Change passwords from a different device
Start with email, then banking, then anything that reuses the same password. Use a device that was not involved.
Turn on multi-factor authentication
Where accounts support it, this prevents a recovered password from being enough on its own.
Report it
Report scams to Scamwatch, and report cybercrime incidents through ReportCyber, which the Australian Cyber Security Centre operates. Reports inform warnings issued to others.
Watch for follow-up approaches
People who have responded once are contacted again, sometimes by someone offering to recover the lost money for a fee. Treat any such offer as part of the same pattern.
If personal information was exposed and an organisation was involved in the exposure, the Office of the Australian Information Commissioner oversees the Notifiable Data Breaches scheme and handles privacy complaints. For online abuse, image-based abuse or cyberbullying, the eSafety Commissioner has complaint processes and can seek removal of material.
Common questions
Can simply visiting a page infect a computer?
It is possible in principle, through vulnerabilities in the browser itself, which is why keeping the browser updated matters. It is uncommon, and it is not what fake alert pages do — they are built to make you act, not to exploit anything. A page that displays a warning has warned you, nothing more.
How did the page know which operating system I use?
Every browser tells every site it visits roughly which browser and platform it is, so that pages can be formatted correctly. It is the same information a news site or a shop receives. Displaying it back to you is a presentation trick, not evidence of access.
My phone showed a warning saying it has viruses. Is that different?
It is the same pattern in a mobile browser. Mobile operating systems keep apps strongly separated, and a web page has no visibility into a phone. Close the tab and, if you want to be thorough, review the list of installed apps and remove anything you do not recognise installing.
Should I report an alert I closed without acting on?
You can, and Scamwatch accepts reports where no money was lost. Reports about a site or a phone number contribute to the warnings published for everyone else.
Related reading
- Your rights and where to complainWhich Australian body handles which problem, and in what order to approach them.
- What the software actually doesHow genuine detection works, including quarantine and false positives.
- Device checklistsThe settings that reduce exposure before any of this comes up.
- Questions answeredShorter answers to related questions.