What Is Scareware? How Fake Alerts Trick Users Into Paying
Scareware is fake software or a deceptive alert designed to convince you your device is infected, pressuring you into paying for bogus antivirus software, calling a fraudulent support number, or granting remote access to your computer, none of which are actually necessary.
If a full-screen pop-up just told you your PC is infected and flashed your real city back at you, take a breath. This explains exactly what’s happening and why it isn’t real.
What Is Scareware?
Scareware is fake software or a deceptive on-screen alert engineered to convince you your device has been infected or compromised, when it almost certainly hasn’t. The entire goal is panic. A scared user makes fast, poor decisions, exactly what the scam depends on.
Fake antivirus software is the classic version: a program claiming to have found dozens of infections, demanding payment to “clean” them, when the software itself is the only actual threat on your device.
How Does a Scareware Attack Unfold, Step by Step?
A malicious advertisement or a compromised, otherwise legitimate website triggers the attack, often without the site owner even knowing their pages are being used this way.
A full-screen pop-up appears, claiming your device is infected, sometimes mimicking your operating system’s own warning style closely enough to fool a hurried glance.
Urgent language and, frequently, a jarring audio alarm apply pressure, designed to stop you thinking clearly and push you toward an immediate reaction rather than a calm decision.
A fake virus alert then directs you toward one of two actions: calling a listed phone number for “support,” or downloading and paying for fake antivirus software that supposedly fixes the problem it invented.
How Do You Know a Virus Alert Is Fake?
Here’s the detail most guides never actually explain, even though it’s exactly what makes these alerts feel convincing. If a fake alert displays your real city, or correctly names your operating system, that’s not proof anything scanned your device.
It’s browser fingerprinting, ordinary website code reading information your browser makes publicly available anyway: your approximate location based on IP address, your operating system, your browser version. The scam page simply pulls that already-visible information and displays it back to you, dressed up as evidence of a deep, personal scan. No malware needed to run first. No actual infection required. Just standard website code any site can access, repurposed specifically to make a bluff feel like proof.
Other tell-tale signs worth watching for directly: genuine operating system security warnings never ask you to call a phone number, legitimate antivirus software never demands payment through gift cards, and a real warning won’t lock your browser into a full-screen mode you can’t easily exit. Pressing and holding the Escape key on most systems forces an exit from that full-screen trap even when the page tries to prevent normal closing.
It’s Not Just About Payment — the Remote Access Risk Most Guides Underplay
Here’s a genuinely underdeveloped risk most content skips past on its way to warning about payment. Calling the number listed on a scareware alert frequently leads to a scammer requesting remote access to your device, using legitimate remote desktop software repurposed for fraud, not just a request for payment.
Once connected, that access gives the scammer real, direct control. They can install genuine malware while you watch, believing you’re witnessing a “cleanup.” They can steal stored credentials, saved passwords, and financial information sitting in your browser or file system. Some campaigns quietly leave persistent remote-access tools installed after the call ends, giving the scammer a way back into your device weeks or months later, long after you’ve forgotten the original panic entirely.
Picture what this actually looks like at a small business. An employee’s work laptop shows a full-screen alert during a busy afternoon. Panicked, they call the number, and a “technician” walks them through granting remote access to “fix” the problem. That technician spends twenty minutes poking around the system, quietly copying saved browser passwords and installing a hidden remote-access tool before wrapping up the call with reassurance that everything’s fixed. The employee feels relieved. The business now has a genuine, silent compromise sitting on a device connected to the corporate network, discovered only if something else eventually goes wrong. This is exactly why “just close the pop-up” isn’t sufficient advice once someone’s already called the number and let a stranger onto the machine. That scenario needs treating as a real security incident, not an inconvenience that resolved itself.
Scareware vs Ransomware — a Quick, Important Distinction
These two get confused constantly since both involve alarming, urgent on-screen messages. Here’s the distinction that actually matters.
Scareware is a bluff. It displays frightening messages but hasn’t actually infected or locked anything on its own. Closing the alert safely, without calling anyone or paying anything, usually resolves the situation entirely, since the “infection” it claimed never existed in the first place.
Ransomware is a genuinely different, far more damaging threat. It actually encrypts your files using real cryptography and demands payment for the decryption key, a technical attack with real, lasting consequences if it succeeds, not a psychological trick relying on panic alone.
Scareware vs Ransomware
| Criteria | Scareware | Ransomware |
| Is anything actually infected? | No, it’s a bluff | Yes, files are genuinely encrypted |
| What it wants | Payment for fake software, or remote access | Payment for a real decryption key |
| How to resolve it | Close the alert safely, don’t call or pay | Requires genuine incident response and recovery |
The Real Scale of This Problem
Here’s how big this problem genuinely is, in real, current numbers rather than a vague warning.
The FBI’s Internet Crime Complaint Center recorded over $2.1 billion in US tech support fraud losses in 2025 alone, part of a broader $20.9 billion total cybercrime loss figure for the year, a 26% jump from 2024.
Tech Support Scam Scale by Region
| Metric | Figure |
| US tech support fraud losses (2025, FBI IC3) | $2.1 billion |
| UK cumulative scam reports since 2020 (NCSC SERS) | 52 million+ |
In the UK, the NCSC’s Suspicious Email Reporting Service has received more than 52 million cumulative scam reports since its April 2020 launch, contributing directly to hundreds of thousands of malicious sites and URLs being removed from the internet.
Can Your Browser Block This Automatically Now?
Yes, genuinely, and this is worth knowing directly. Microsoft Edge’s Scareware Blocker, enabled by default since late 2025 on devices meeting minimum specifications, uses an on-device AI model to detect the visual and behavioral patterns typical of scareware pages in real time.
When it detects a match, it automatically closes the full-screen page and stops any accompanying audio before you can interact with it at all, and it does this using only local, on-device analysis, without sending screenshots to the cloud. If it makes a mistake and blocks a legitimate page, you can report the false positive, which helps refine detection for everyone else.
Cyber Security Solutions Ltd routinely finds that businesses assume browser-level scam protection like this is switched on everywhere by default, only to discover it’s disabled on older devices or lower-spec machines that fall below the feature’s minimum requirements, a gap worth checking directly across your fleet rather than assuming.
What Should IT Managers Do If This Happens on a Work Device?
Instruct the employee to close the alert safely, using Escape if needed, without calling any listed number or downloading anything the page suggests.
Run a full endpoint scan on the affected device regardless of whether anyone interacted with the alert, since a compromised or malicious ad network occasionally does deliver genuine payloads alongside the scareware display itself.
Review browser history to identify the specific site or ad network that triggered the alert, useful both for internal awareness and for reporting.
If the employee already called the number and granted remote access, treat this as a genuine security incident requiring full response, not a resolved inconvenience. Assume credentials may be compromised, review for any newly installed software or remote-access tools, and reset relevant passwords immediately.
Where Do You Report It?
In the United States, report tech support scams to the Federal Trade Commission and the FBI’s Internet Crime Complaint Center, IC3, both of which track patterns across reports to identify and disrupt broader scam operations.
In the UK, report to Action Fraud, the national fraud and cybercrime reporting service, and forward suspicious emails or scam websites directly to the NCSC’s Suspicious Email Reporting Service, which has a direct, documented track record of using public reports to get malicious sites taken down.
Conclusion
Scareware works because it’s designed to make you panic before you think, which is exactly why the fix is almost always simpler than the alert wants you to believe. Close it safely, never call the number, and treat any device where remote access was already granted as a genuine incident worth investigating properly. If you want help checking whether your team’s devices are actually protected against this, Cyber Security Solutions Ltd can walk through it with you.
