Alerts and pop-ups you were not expecting
Some of the most alarming-looking messages people see have nothing to do with the software installed on their device. Knowing where a message was drawn is nearly always enough to tell which kind you are looking at.
The short version
A web page cannot examine your device. If a message appears inside a browser tab, scrolls with the page, or asks you to ring a number, it came from a website, not from your security software. Close the tab — or force the browser to quit if it will not close — and carry on. No call is required, no payment is required, and nothing needs to be installed.
Where the message was drawn tells you what it is
Software installed on a device can put a message in the operating system’s notification area or in its own window. It has access to the device because you installed it. A web page has no such access: it is rendered inside a tab, in a sandbox designed to keep it there, and the information it receives about you is limited to what any site receives — browser and operating system strings, screen dimensions, language settings, and an approximate location derived from your IP address.
That last point explains why a fake warning can correctly name your operating system and your city. It is reading ordinary request headers, not your computer. A page that lists specific infections, file names or a count of threats has invented all of them.
| Characteristic | Your own security software | A web page imitating one |
|---|---|---|
| Where it appears | Operating system notification, or the product’s own window | Inside a browser tab, often full screen |
| Behaviour when you scroll | Unaffected | Moves with the page, or the page will not scroll at all |
| Behaviour when the browser is closed | Still there | Gone |
| What it asks of you | A decision inside the product: quarantine, allow, scan | Ring a number, install something, enter card details |
| Tone | Descriptive, with a detection name and file path | Urgent, counting down, warning of imminent loss |
| Contact details | None; support is reached through the vendor’s own site | A prominent telephone number, sometimes read aloud |
The techniques these pages use
None of them are sophisticated, and all of them are easier to ignore once named.
- Imitation system windows. The page draws something that resembles a dialog box, using an image or plain web elements. It cannot leave the tab.
- Forced full screen. The page requests full screen so that browser controls disappear and the imitation looks more convincing. Pressing Escape, or F11 on Windows, usually exits.
- Dialog loops. A script opens a confirmation box repeatedly so the tab appears stuck. Most browsers offer a checkbox to stop further dialogs from that page; otherwise close the browser entirely.
- Audio. A recorded voice reading a warning aloud, which is unsettling and carries no information.
- Notification permission abuse. A site asks to send notifications, and once allowed, delivers warning-shaped messages to the desktop even when the browser is closed. These are removable in the browser’s notification settings.
- Countdown timers. A clock ticking down to nothing in particular. Nothing happens when it reaches zero.
What to do, in order
- Do not ring the number and do not install anything the page offers. That is the whole objective of the page, and declining it ends the matter.
- Close the tab. If the page resists, close the browser: Ctrl+Shift+Esc then End task on Windows, or Command+Option+Escape then Force Quit on macOS.
- Reopen the browser without restoring tabs. Decline the offer to reopen what was there before, or you will land straight back on the page.
- Review notification permissions. In your browser’s settings, find site notifications and remove any site you do not recognise.
- Run a scan with the software you already have. Not because the page did anything, but because it is a reasonable way to settle the question for yourself.
- Check browser extensions if pop-ups keep appearing on many sites. Persistent pop-ups across unrelated sites point at an extension rather than at any one page.
If you went further than that
People do follow these pages, often because the timing was unlucky or the caller was convincing. The response is practical rather than dramatic.
- If you allowed remote access, disconnect the device from the network and remove any remote-access software that was installed during the call.
- Change the passwords for your email account first and your banking second, using a different device you are confident about.
- Turn on multi-factor authentication for email and banking if it is not already on.
- If any payment was made or card details were given, contact your bank immediately and ask about a chargeback.
- Run a full scan with your own security software and let it finish.
- Report it to Scamwatch and, where cybercrime is involved, through ReportCyber, which is run by the Australian Cyber Security Centre.
- If personal identity information was exposed, IDCARE is a not-for-profit organisation providing identity and cyber support services to people in Australia and New Zealand.
Questions people ask about these pages
Can a website tell whether my device has a virus?
No. A web page runs inside the browser and cannot read the files on your device, inspect its memory or run a scan. A page that displays a list of infections it claims to have found on your computer has found nothing; the list is written into the page in advance. The information a site genuinely receives is limited to things like your browser type, your approximate location from your IP address, and your screen size, which is why a fake alert can name your operating system correctly and still know nothing about you.
How can I tell a real alert from a fake one?
Look at where it is drawn. A genuine alert from security software appears outside the browser, in a notification from the operating system or in the product's own window, and you can still reach the rest of the screen. A fake one lives inside a browser tab, moves when you scroll the page, disappears if you close the tab, and usually asks you to ring a telephone number. Genuine security software does not give you a phone number to call.
What should I do if a full-screen warning will not close?
Close the browser rather than the message. On Windows, press Ctrl+Shift+Esc to open Task Manager, select the browser and choose End task. On macOS, press Command+Option+Escape, select the browser and choose Force Quit. When you reopen the browser, decline any offer to restore the previous tabs, or the same page will load again.
I called the number. What now?
Stop and take stock rather than continuing the conversation. If you installed anything or allowed remote access, disconnect the device from the internet and run a full scan with your own security software, then change the passwords for your email and banking from a different device. If you made a payment or gave card details, contact your bank straight away. Report what happened to Scamwatch, and to ReportCyber if it involved cybercrime.
Are these pop-ups a sign that my antivirus is not working?
Not usually. Blocking every page that displays a misleading message is a web filtering job rather than an antivirus one, and no filter catches everything, because these pages are created and discarded constantly. Seeing one means a page loaded, not that anything reached your device.
Where to take it further
The eSafety Commissioner is Australia’s online safety regulator and publishes guidance aimed at families, schools and older Australians, along with complaint pathways for serious online abuse. For privacy consequences — personal information exposed or mishandled — the Office of the Australian Information Commissioner is the regulator. General guidance on personal cyber security is published by the Australian Cyber Security Centre.