Additional resource for the lesson “Scareware: The Warning That Is Itself the Attack” — Online Security course
A red banner announces that your device is infected and urges you to act immediately. Scareware works by producing the feeling first and the reasoning never — and the single fact that defeats it fits in one sentence.
A. Why this matters
Scareware is a message designed to frighten you into acting: a warning that your device is infected, that your data will be deleted, that you must call a number or install something now.
It does not exploit a flaw in your device. It exploits the few seconds between alarm and thought, and it is deliberately designed to prevent the second one.
The one fact worth carrying: a genuine security warning from your device or your browser never asks you to call a phone number, and never appears as an advertisement on a web page.
B. Key concepts
Six ideas, most of which reduce the fear the message depends on.
Scareware
A message manufacturing an emergency to make you act — pay, install, or call.
Why it matters to you: It sits at the intersection of advertising and fraud. Recognising it as a category makes each instance much easier to dismiss.
Where it appears
Web pages, usually through advertising networks. Sometimes as a notification if you granted a site permission to send them.
Why it matters to you: It arrives through the browser rather than from the device. That is the first thing to notice: the operating system did not produce it.
The phone number
Most versions ask you to call for support.
Why it matters to you: This is the defining feature. No genuine warning does this, on any platform, ever. It is the fastest way to identify one.
The tech support scam
If you call, the person asks for remote access to your device, appears to find problems, and asks for payment to fix them.
Why it matters to you: The remote access is the serious part. Anything typed while they are connected is theirs, including passwords and banking sessions.
Why it is convincing
Urgency, an official-looking design, technical language, and often a countdown.
Why it matters to you: None of these is evidence. All of them are design choices intended to prevent the pause in which you would recognise the message.
What to do instead
Close the page or the browser. Then, if you want reassurance, check the device using its own built-in protection.
Why it matters to you: The second half matters: dismissing a fake warning is easier when you have a way of confirming that nothing is actually wrong.
C. A practical example: the full-screen warning
You are reading an article. The page changes to a full-screen red warning with an alarm sound: three viruses detected, your data is at risk, call this number immediately.
What is actually happening
- An advertisement on the page loaded this content.
- It knows your browser and approximate location, which it displays back to you as though it had scanned the device.
- Nothing has been scanned. Nothing can be, from a web page.
What to do
- Close the tab. If it will not close, close the browser entirely — on a phone, from the app switcher.
- Do not call. Do not install what it offers. Do not enter anything.
- Reopen the browser without restoring the previous tabs.
- If you want reassurance, run the phone’s built-in check.
If you already called
- Disconnect any remote access session and restart the device.
- Change the passwords of anything used during the session, starting with email.
- If you paid, contact your bank — these charges are often reversible.
- There is nothing embarrassing about this. It is designed to work on people who are paying attention.
The last point matters. Shame is what keeps people from acting quickly afterwards, and the hours afterwards are what decide the outcome.
D. Try it yourself: prepare the response
Ten minutes now, so the response is ready rather than improvised.
Step 1 — Learn how to force-close your browser
- On a phone: the app switcher.
- On a computer: the task manager or force-quit.
- Knowing this in advance removes the trapped feeling these pages create.
Step 2 — Turn off the tab restore prompt, or know to decline it
- Reopening a browser and restoring tabs brings the page straight back.
Step 3 — Check your site notification permissions
- Some scareware arrives as notifications from a site granted permission long ago.
- Revoke anything you do not recognise.
Step 4 — Know where your built-in check is
- Android: Play Protect, in the store.
- This is what you use for reassurance instead of installing something a warning recommended.
Step 1 is worth doing today. Most of the pressure these pages create comes from not knowing how to make them go away.
E. Videos, articles and further resources
Independent and institutional sources in English.
FTC — How to spot, avoid and report tech support scams
The most directly relevant source: how these scams work and where to report them. Includes the rule about phone numbers.
https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams
FTC — Malware: how to protect against, detect and remove it
The signs that something is wrong with a device, and the sequence to follow to clean it.
https://consumer.ftc.gov/articles/malware-how-protect-against-detect-and-remove-it
NCSC (UK) — What to do if your device is infected
What to do if you think something was installed, in a calm sequence.
https://www.ncsc.gov.uk/section/respond-recover/citizen-infected-devices
Google — Use Play Protect to keep your apps safe and your data private
How Android checks apps before and after installation, and how to review the permissions you have granted.
https://support.google.com/android/answer/2812853?hl=en
NCSC (UK) — Phishing: spot and report scam messages
The related technique arriving by message rather than by web page.
https://www.ncsc.gov.uk/collection/phishing-scams
FTC — Protect your personal information from hackers and scammers
What to lock down first when you have limited time.
https://consumer.ftc.gov/articles/protect-your-personal-information-hackers-and-scammers
Links checked in August 2026.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Awareness pillar at level FL2, and is deliberately reassuring: the correct response is to do less, not more.
Skills
- Force-closing a browser and reopening it without restoring tabs.
- Managing site notification permissions.
- Using built-in protection to confirm nothing is wrong.
For professionals and organizations
- Giving people a number to call internally, so the scam’s number is not the only one available in the moment.
Awareness
- Knowing that a real warning never asks you to call.
- Understanding that a web page cannot scan your device.
- Recognising urgency and countdowns as design rather than as evidence.
For future instructors and ambassadors
- Removing the shame explicitly. People who feel foolish delay reporting, and the delay is what causes the damage.
Secure Behavior
- Closing rather than engaging.
- Never calling a number shown in a warning.
- Never granting remote access to someone who contacted you.
For organizations
- Making it easy and blame-free to report having engaged with one.
G. Questions to sit with
- Have you ever seen a full-screen warning like this? What did you do?
- Do you know how to force-close your browser on your phone?
- Which sites have permission to send you notifications?
- If someone you knew had called such a number, would they feel able to tell you?
H. What to do now
The recommendations (R) and security measures (MS) that apply.
In the moment
- R17 — Do not install anything a warning recommends, and do not open what it offers.
- R9 — Check that you are on the site you think you are on.
- MS5 — A browser with tracking protection reduces how often these advertisements load at all.
Afterwards, if you engaged
- R1, R2 — Change the credentials used during any remote session, without reusing them.
- R4 — Confirm multi-factor authentication is on.
- R8 — Check login alerts and recent access.
- R6 — Update the device and run its built-in check.
Minimum commitment: And contact your bank if a payment was made. These are frequently reversible.
In short
- A genuine warning never asks you to call a number.
- A web page cannot scan your device — whatever it displays, it did not measure.
- Close the page; do not engage. Then check with the built-in tool if you want reassurance.
- If you did engage, the hours afterwards matter and shame is the only real obstacle.
Related resources in this course
The related techniques:
- How to Recognize Phishing When It Is Built to Be Convincing
- Fake Security Apps: When the Protection Is the Problem
- Adware on Your Phone: Reading the Unwanted Ads
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply