People still fall for scareware?

GuyClapperton 0 Tallied Votes 293 Views Share

Symantec has published one of those rare things - a report that contains an actual surprise. It seems some 4 million people have fallen for Scareware in the last 12 months.

I'm stunned.

Not because people are installing fake antivirus systems. That's a shame but in some ways it's inevitable; people on their own will fall for scams. No, what alarms me is that the IT community (and if we include journalists and bloggers that's all of us) are doing so little to dissuade them.

It wouldn't take much. An email sent to all remote workers reminding them that not only should they not install pirated software onto their systems, not only is clicking a link in an email from someone they don't know and filling bank details in after that a really, really bad idea, but if someone approaches you with AV software it's probably fake. Coming from someone they trust, like an employer, it could transform the way scams succeed on the Internet.

Now if you'll excuse me I have a mail telling me my ISP is going to close my account if I don't log on and confirm all of my passwords...

Dani AI

Generated

As notes, scareware works because it pairs urgent language with familiar-looking UI cues. Two practical gaps stand out in the thread: an employer playbook that can be deployed in days, and a short, reliable verification checklist for end-users that reduces panic-driven mistakes.

Employer playbook (low-cost, immediate steps): remove local administrator rights for daily accounts; enforce automatic OS and app patching and centrally deploy vetted endpoint protection; apply application-control or software-restriction policies on critical machines; configure browsers/endpoints to reduce drive-by downloads and block aggressive popups; publish one official channel for security alerts and require staff to report suspicious messages there; run short recurring reminders plus occasional simulated scareware/phishing tests and follow up with targeted training.

End-user checklist: do not run installers or accept “scans” offered by popups; if a system looks compromised, disconnect network access and report to the official IT/security channel; confirm any urgent claim by contacting the organisation using independently obtained phone numbers or paperwork; use a non-administrator account for everyday work, keep regular backups and restore points, and maintain current OS/antimalware signatures; if an unwanted program was installed, boot known rescue media or run an offline scanner and escalate to IT instead of paying or calling numbers supplied in the alert.

The reply from is off-topic spam and should be removed or flagged. Keeping this thread clean helps future readers. Ultimately, technical controls reduce exposure, but consistent procedures, fast support and short, repeated reminders are the decisive defenses against scareware.

saranyafa 0 Newbie Poster

What have u done to live it 2day..?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.