Quick answer. Security software is a common disguise for fraud, because alarm makes people act quickly. No web page can scan your device, no legitimate vendor rings you unprompted about an infection, and no renewal notice should ever be actioned through a phone number inside the message itself. In Australia, scams go to Scamwatch, cybercrime to the ACSC, privacy breaches to the OAIC, and anything involving money starts with your bank.
Why this category attracts impersonation
Fraud works on emotion and time pressure, and few subjects supply both as reliably as being told your computer is compromised. The victim is alarmed, does not feel qualified to assess the claim, and is offered an authoritative-sounding person who will fix it. That combination explains why security brands are impersonated so persistently, and why a warning about your device is worth more scepticism than almost any other unsolicited message.
It is worth separating two things that often get conflated. Malware is software doing something to your device. A scam is a person persuading you to do something yourself. Security software addresses the first and can only nudge at the second, which is why recognising the approaches matters at least as much as what you have installed — a point made in more detail in what antivirus actually does.
Four approaches that use security as the hook
The unsolicited technical support call
Someone rings claiming to be from a large technology company, a telecommunications provider or a security vendor, and says your device is infected or your connection is compromised. They ask you to install remote access software so they can demonstrate the problem, then show you something ordinary — routine system logs, for instance — as evidence. The outcome sought is payment, banking access, or both.
The reliable defence is structural rather than clever: no legitimate company rings a member of the public unprompted to report an infection on a specific machine. They have no way to know. Hang up. If you are worried the call might be genuine, ring the organisation back on a number you looked up yourself.
The renewal invoice
An email or PDF states that a security subscription has renewed for a substantial amount, with a number to call if you wish to dispute it. Many recipients never had the subscription at all, which is precisely why they ring. The call proceeds to a refund that requires remote access to your banking, and the loss follows from there.
Check your bank statement instead of the message. A charge either exists there or it does not, and that answer costs nothing to obtain. Our page on subscriptions and renewals covers how genuine billing in this category works.
The browser warning that is really an advertisement
A page opens claiming your device is infected, sometimes with an animated scan, a threat count, or a facsimile of a system dialog. It may be hard to close. It is a web page, it knows nothing about your device, and its purpose is either to sell something or to have you install something.
Close the tab, or close the browser entirely if the page resists. Then check your device's own security settings, on the device, as described in built-in protection.
The delivery, toll or bank text message
A short message about a parcel, an unpaid toll or an account problem, with a link to a page that looks convincing and asks you to log in. There is no malware involved; the objective is the credentials you type. Scamwatch publishes current examples of the approaches circulating in Australia at scamwatch.gov.au.
The habit that defeats this one is simple: never follow the link. Open the organisation's own application, or type its address yourself. If the message were genuine, the same information will be waiting for you there.
Why a web page cannot know anything about your device
This deserves its own section because it is the misunderstanding scams depend on. A page in your browser runs inside a sandbox. It cannot enumerate your files, inspect your installed software, or determine whether anything malicious is present. It can see what any site sees — roughly, your browser and operating system version, your screen size, your approximate location from your network address — which is exactly enough to produce a message that feels personalised and is not.
So a page that names your operating system and then reports a threat is not demonstrating knowledge. It is reading a browser header and adding an assertion. Real security software reports through its own interface on your device, not through a web page, and never through a page you did not open yourself.
Three phrases that should end a conversation
"Install this so I can show you the problem." Remote access given to a stranger is the loss, not a step towards fixing it.
"We need to process your refund through your online banking." No refund works this way.
"Purchase gift cards to settle this." No legitimate organisation in Australia is paid in gift cards, for anything, ever.
When a company you used is breached
Breach notifications are now a routine part of Australian life, and they are not a scam by default — though scammers do imitate them. Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act 1988 must notify affected individuals and the Information Commissioner about a data breach likely to result in serious harm. The Office of the Australian Information Commissioner explains the scheme and takes privacy complaints.
If you receive one, the useful response is unglamorous. Change the password for that service, and change it anywhere you reused it — reuse is what turns one company's breach into your problem across several accounts. Turn on multi-factor authentication where it is offered. Watch for messages referencing the breach, since attackers use the real event as a pretext. And be sceptical of any notification that arrives with a convenient link to "secure your account"; go to the service yourself.
Where identity documents are involved, IDCARE is a not-for-profit identity and cyber support service operating in Australia and New Zealand, at idcare.org. It provides free support to individuals working through the consequences of identity compromise.
Where to report what, in Australia
| What happened | Where it goes |
|---|---|
| Money has moved, or your banking details were given away | Your bank, immediately — before anything else. Speed matters for recovery. |
| A cybercrime: hacking, ransomware, a compromised account | The Australian Cyber Security Centre, at cyber.gov.au, which operates the reporting route for cybercrime. |
| A scam approach, whether or not you lost anything | Scamwatch, run by the National Anti-Scam Centre. Reports of attempts matter too; they inform the warnings others see. |
| An organisation mishandled your personal information | The organisation first, then the OAIC if it is unresolved. |
| Online abuse, image-based abuse, a child's safety online | The eSafety Commissioner, which has specific reporting schemes. |
| Misleading advertising or an unfair contract term | The ACCC, or your state or territory consumer affairs body. |
Reporting to a regulator is not the same as recovering money. The bank is the route for that, and it is the first call every time.
If you have already given something away
- Contact your bank and tell them what happened. Ask about stopping transactions and about a chargeback if a card was used.
- Disconnect the device from the internet if remote access software was installed, and do not use it for banking until it has been dealt with properly.
- Change passwords from a different device — email first, because it can reset everything else — and turn on multi-factor authentication.
- Report it, to the bodies above. Keep the messages, numbers and any transaction references.
- Get support if identity documents are involved, through IDCARE or the issuing agency for the document concerned.
Embarrassment stops a great many people from reporting, and it should not. These approaches are designed by people who do this full time, and they are tested on thousands of targets before they reach you.
Habits that hold up
- Treat unsolicited contact about your device's security as false until independently confirmed, whatever name it arrives under.
- Go to organisations yourself. Type the address, or open the app. Never use the link or the number in the message.
- Keep multi-factor authentication on for email and banking. It is the single measure that most reliably limits a stolen password.
- Keep backups that are not permanently connected to the device they back up.
- Read Scamwatch occasionally. Knowing this month's approach is worth more than any subscription.