Emails and texts about an antivirus subscription
Messages announcing that a security subscription has renewed, or is about to, arrive constantly in Australian inboxes. Most are addressed to people who never had the subscription in the first place, and the whole approach rests on getting a reply.
The short version
Never use the contact details inside the message. If you want to know whether a subscription exists, sign in to the vendor’s site yourself, in a browser, using an address you typed or bookmarked, and look at your account. If you want to know whether a payment was taken, look at your bank statement or ring the number on the back of your card. Both checks take a minute and neither involves the message at all.
How the approach works
The message is usually formatted as an invoice or a renewal confirmation. It names a well-known security product, shows an amount, and states that the sum has been charged or will be charged shortly. There is often no link at all — just a telephone number or a reply address for cancellations and refunds. The absence of a link is deliberate, because a link can be inspected and a phone number cannot.
The intended reaction is a phone call made while annoyed. On that call, the person answering is helpful, apologises for the charge, and offers to process a refund. The refund requires remote access to your computer so that the amount can be entered into your banking; during the session an amount appears too large, and you are asked to return the difference by transfer, gift card or cryptocurrency. What has actually been transferred is control of the machine and, in due course, money in one direction only.
Variants use the same structure. A text message about a lapsed subscription with a link to an imitation sign-in page. A confirmation of a purchase you did not make, with a cancellation link. A message claiming a payment failed and asking you to update card details. Scamwatch, run by the National Anti-Scam Centre, publishes current examples and figures at scamwatch.gov.au, and it is worth reading before rather than after.
What gives them away
- You do not have the product. The messages are sent in bulk, so most recipients never bought anything from the company named.
- The only way to respond is a phone number or a reply address. Genuine vendors put account management in your account, not on a call centre queue.
- The amount is uncomfortable but plausible. Large enough to prompt action, small enough to be believable as an annual renewal.
- The sender address does not belong to the company. Look at the full address rather than the display name, which can say anything.
- Your name is missing. A real invoice from a real vendor has your account details on it, not just an invoice number.
- It is an image rather than text. Sending the whole message as one picture is a way around filters that read words.
- The timing is pressing. A short window before the charge is final, or before the refund offer lapses, is there to prevent the checks described above.
What to do with one
- Do not ring the number, reply, or follow any link. Non-engagement is the complete answer for a message you did not expect.
- Check your own accounts independently. Sign in to the vendor’s site by typing the address yourself. Look at your bank or card statement for a matching charge. If there is no subscription and no charge, the message is fiction.
- If there is a real charge, deal with it through the real channels. The vendor’s account area and your bank — contacted through numbers you look up yourself — are the two places anything can genuinely be resolved. The renewals and refunds page covers the sequence.
- Report it. Reports to Scamwatch feed the National Anti-Scam Centre’s picture of what is circulating. Where cybercrime is involved, ReportCyber is the Australian Cyber Security Centre’s reporting service.
- Then delete it and move on. There is nothing further to be gained from keeping it, unless you have reported it and been asked to retain a copy.
If you already made a payment or gave remote access
Contact your bank straight away and ask about reversing the payment — the sooner, the more can usually be done. Remove any remote-access software installed during the contact, run a full scan with your own security software, and change the passwords for your email account first and your banking second, from a device that was not involved. IDCARE, a not-for-profit organisation providing identity and cyber support services across Australia and New Zealand, can help work through the consequences if identity information was exposed.
Reducing how often these arrive
You cannot stop them entirely; bulk messaging costs the sender almost nothing. A few habits reduce both the volume and the risk each one carries.
- Keep one email address for financial accounts and a different one for shopping, newsletters and sign-ups. When a message about money arrives at the wrong address, you know immediately.
- Turn on multi-factor authentication for your email account before anything else. It is the account that can reset all the others.
- Note the renewal dates of the subscriptions you actually hold in a calendar. A message about a renewal is easy to judge when you know when yours falls due.
- Report and block rather than unsubscribe. Using an unsubscribe link in a message sent in bulk by a stranger confirms the address is read.
- Keep bank and card contact numbers stored from the card itself, not from a search result, so that a real emergency does not begin with a search.
- Agree a household rule: nobody installs anything or allows remote access because of a phone call, however plausible.
Where your address came from
Usually a data breach at some unrelated service, or a list traded between senders. Australia’s Notifiable Data Breaches scheme requires organisations covered by the Privacy Act 1988 to notify affected individuals and the regulator when a breach is likely to result in serious harm; the scheme is administered by the Office of the Australian Information Commissioner, which also publishes statistical reports on breaches. If you believe an organisation has mishandled your personal information, the OAIC is where a privacy complaint goes.
None of that makes an individual message more or less genuine. It simply explains why a stranger has your address and, often, your name — and why neither of those details should persuade you that a message is real.
The same approach by telephone
The message version has a spoken equivalent, and it is worth recognising because the pressure is greater in real time. The caller says they are from a well-known software company, a telecommunications provider or a bank, mentions a subscription, a refund owed or a problem detected on your connection, and asks you to go to your computer.
Two rules cover every version of this call. No legitimate company telephones a customer to say it has detected a problem with their device, because no company can see your device from outside. And nobody who genuinely needs to help you requires remote access to your computer within minutes of an unexpected call.
Hanging up is a complete and sufficient response — you owe an unsolicited caller no explanation. If you want to check whether anything was genuine, ring the organisation back on a number you look up yourself, from your card, your bill or the organisation’s website, and never on a number the caller gives you.