AgileBase

Scams, consumer rights and where to report them

The vocabulary of security software is used in scams as often as in product pages. This page separates the patterns, the checks, and the Australian bodies that take reports.

Which Australian body handles what

Several organisations publish guidance and take reports in this area, and they do not overlap as much as their names suggest. Sending a report to the right one saves time and makes the report more useful.

Australian bodies relevant to security software, scams and personal information
BodyWhat it isWhat to take there
Australian Cyber Security Centre Part of the Australian Signals Directorate; publishes cyber security guidance for the public Cybercrime reports through ReportCyber, and step-by-step recovery advice
Scamwatch Run by the National Anti-Scam Centre at the ACCC Scam reports and descriptions of current scam types
ACCC The national competition and consumer regulator; administers the Australian Consumer Law Problems with a purchase, misleading claims, and consumer guarantees
OAIC Regulates the Privacy Act 1988 (Cth) and the Australian Privacy Principles Privacy complaints about how an organisation handled your personal information
eSafety Commissioner Australia's independent regulator for online safety Reports about cyberbullying, image-based abuse and seriously harmful online content

If money has moved, the first call is to your bank or card issuer rather than to any of these, because the fastest actions available — stopping a payment, freezing a card — are theirs. The reports above come next and can be made afterwards.

Scam patterns that borrow the language of security software

Scamwatch and the ACSC both publish current descriptions; the summaries here are general and the linked pages are the authority. What these patterns share is that they use the vocabulary of antivirus software to manufacture a reason to act quickly.

The unsolicited technical-support call

A caller claims to be from a well-known technology company and says a problem has been detected with your computer. The request that follows is to install remote-access software so the caller can "fix" it. Legitimate software companies do not telephone individuals about problems detected on their machines, and no company can detect a fault on a home computer without something installed that reports to them. Hanging up costs nothing and forecloses the whole sequence.

The browser pop-up that claims to have scanned your device

A web page displays what looks like a system warning, sometimes with a fabricated list of infections and a countdown. This is scareware, and it works by imitating an operating system dialog inside a web page.

Why a web page cannot have scanned your computer

Browsers deliberately isolate web pages from the rest of the machine. A page can see what you give it and a little about the browser itself; it cannot enumerate your files, inspect your processes or run a scan. Any page that reports a specific infection count has drawn a picture of a dialog box. Closing the tab ends it. If the tab resists closing, closing the browser from the operating system's task manager or app switcher does.

The subscription renewal email

An email states that a security subscription has renewed for a large amount and offers a phone number or link to cancel or obtain a refund. The document attached is an invoice for something never purchased. The purpose is either to get you onto a phone call or to collect account details during a supposed refund. The check is the same for any such message: ignore the contact details in the email and reach the vendor through its own site or through the account you already have.

The "refund" that arrives as an overpayment

A follow-up to the pattern above. During a supposed refund, the caller appears to transfer too much money and asks for the difference back. Scamwatch describes variants of this on its types of scams pages. A genuine refund reverses to the payment method it came from and never requires you to send money anywhere.

Checking a message without trusting it

Every pattern above depends on you using contact details the message supplied. Breaking that habit handles most of them.

  • Reach the organisation through a channel you already have: a bookmark, the app on your phone, the number on the back of your card, or a search for the official site.
  • Check the account itself rather than the message about the account. A renewal charge is visible in your account history and on your card statement.
  • Treat urgency as a signal in itself. The pressure to act immediately is the mechanism, not an incidental feature of it.
  • Verify with someone before acting on any request involving a payment, a code from an SMS, or remote access. A short conversation interrupts the sequence.
  • If a caller is claiming to be from your bank, hang up and call the bank back on the published number. Wait a few minutes, or use a different phone, so the previous call has certainly ended.

When the problem is the purchase, not a scam

A separate situation: the vendor is genuine, the charge is real, and the product or the transaction was not what you expected. That is consumer law rather than cybercrime.

The ACCC's guidance on consumer rights and guarantees sets out the guarantees that apply to products and services supplied to consumers in Australia, and its guidance on problems with a product or service describes the steps to take. In outline, the sequence is to raise it with the seller first, in writing, keeping a record; then to escalate to the relevant consumer protection agency if it is not resolved. A card issuer's chargeback process runs separately and has its own deadlines, which is why it is worth asking about early rather than late.

Misleading claims by a business in trade are also a matter for the ACCC. That obligation applies to publishers as well as to vendors, which is one reason this site declines to restate product claims it cannot verify.

If your personal information was involved

Where an organisation has mishandled your personal information, the complaint route runs through the organisation first and then to the Office of the Australian Information Commissioner. Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act must notify affected individuals and the OAIC about eligible data breaches likely to result in serious harm.

Practical steps after a breach notice do not depend on security software: change the password on the affected account and anywhere it was reused, turn on multi-factor authentication where it is available, and watch for messages that reference real details from the breach, since those details are what makes the next approach convincing. The ACSC's report and recover guidance covers the sequence in more detail.

Helping someone else

Most of these patterns are aimed at people who are alone with the decision. Two things help more than any technical control.

The first is agreeing in advance that a phone call about a computer problem is always worth pausing on, and that pausing to ask someone is never rude. The second is knowing that reporting after the fact is still worth doing: reports to Scamwatch and ReportCyber feed the descriptions that warn the next person, and they are accepted whether or not money was lost.

For the terminology used in these messages — scareware, phishing, remote access trojans — the glossary gives the plain meanings.