← All terms

Scareware

Scareware is malicious software or fake alerts that frighten victims into installing malware or paying for useless 'security' products by faking an infection.

Scareware is a social engineering technique that manufactures fear — typically a fake virus alert, a flashing "your computer is infected" pop-up, or a full-screen browser lock — to pressure the victim into a harmful action: downloading fake antivirus software, paying for a useless cleanup tool, or calling a fraudulent "support" number. The threat it warns about does not exist; the scareware itself is the attack.

How it works

Scareware usually arrives through malicious ads, compromised websites, or poisoned search results. The victim lands on a page that suddenly displays an alarming system-style alert, often mimicking Windows Defender, macOS, or a well-known antivirus brand. Common pressure tactics include:

  • Fake scan animations that "discover" dozens of infections in seconds, complete with progress bars and file names.
  • Browser lockers — full-screen pages with JavaScript that hides the cursor or re-opens dialogs, making the browser appear frozen until the victim complies.
  • Countdown timers and alarm sounds claiming files will be deleted or the machine reported unless the user acts immediately.
  • Tech support numbers connecting the victim to a call center that requests remote access or payment — the same infrastructure behind callback phishing.

The payoff varies: payment card details harvested through a fake purchase, remote-access tools installed under the guise of "cleaning," or actual malware delivered as the promised antivirus. In corporate environments, the remote-access variant is the most dangerous, because it hands an attacker an interactive session on a managed endpoint.

How to defend against it

  • Teach the tell: real security software does not demand payment through browser pop-ups, and browsers themselves do not scan for viruses. Any alert that asks the user to call a number or install something immediately is hostile.
  • Make closing safe and easy. Train employees to close the browser via the task manager if a page will not release them, and to report the incident rather than "fix" it themselves — reporting behavior is a core signal in a human risk program.
  • Block the delivery channels with ad-blocking or DNS filtering on managed endpoints, and restrict who can install software or run remote-access tools.
  • Simulate the scenario. Fear-based lures behave differently from curiosity-based ones; security awareness training that includes scareware examples builds recognition before the real pop-up appears.

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.Callback PhishingCallback phishing (TOAD) is an attack where an email lures the victim into phoning a fake support line, moving the scam to a live phone call.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo