Scams, malware and your rights in Australia
Security software is sold against a threat, and the threat is sometimes described dishonestly by the people selling it. This page separates the deceptions that circulate in the antivirus category from the genuine risks, sets out what to do if money has already left your account, and names the Australian bodies that handle each type of report.
Deceptions that use antivirus as their cover
The fake infection warning
A web page displays what appears to be a system alert: a scan in progress, a list of threats found, a warning that your device is at risk. It is a picture. A page loaded in a browser cannot examine the files on your computer, cannot see what software you run, and cannot detect malware. Every page of that kind is an advertisement, and many lead to something worse than an advertisement. Closing the tab is the complete response; if the page resists closing, close the browser itself.
The tech-support call
Someone rings claiming to be from a well-known software or telecommunications company and says your computer has been sending error reports, or is infected, or has been compromised. The objective is to have you install remote-access software, at which point the caller controls the machine and can watch you log in to your bank. No legitimate company monitors a consumer's home computer for faults and rings about it unprompted. Hanging up costs nothing and ends the attempt.
The renewal invoice
An email arrives that looks like a receipt for a security subscription, often for a familiar brand and an amount large enough to alarm. It says to call a number if you did not authorise the charge. The number is the actual payload: calling it connects you to the same operation, which then walks you through a "refund" that ends with remote access or a transfer out of your account. Check your own bank or card statement, and contact the vendor through details you look up yourself.
The scareware download
Software advertised as a free scanner or system cleaner reports an alarming number of problems and asks for payment to fix them. Sometimes the findings are fabricated; sometimes the program itself is the problem. Security software downloaded from anywhere other than a vendor's own site or an official store carries this risk.
The common shape
Each of these works by producing urgency and then offering relief from it. A message that insists you act immediately, discourages you from checking with anyone, or asks you to install something so a stranger can help — that combination is the signal, regardless of the brand or story attached to it. Genuine security problems do not require an answer within the next five minutes.
If you have already paid, or installed something
Contact your bank or card issuer immediately
Speed matters more than anything else here. Australian banks have processes for disputed and fraudulent transactions, and a card can be blocked while the matter is examined.
Disconnect the device if remote software was installed
Take it off the network, then remove the remote-access tool. If the machine was used for banking while someone else had control, treat every credential entered on it as exposed.
Change passwords from a different device
Start with email, then banking, then anything reusing the same password. Enable multi-factor authentication where it is offered.
Report it
Scams can be reported to Scamwatch, run by the National Anti-Scam Centre. Cybercrime, including compromise of a device or an account, is reported through the Australian Cyber Security Centre.
Keep the evidence
Screenshots, emails, phone numbers, transaction references and the times things happened. Both your bank and the reporting bodies will ask.
Where Australian law puts the obligation
Two separate bodies of law are relevant, and confusing them wastes time.
- Australian Consumer Law
- Applies to what a business sells and says. Consumer guarantees attach to goods and services supplied to consumers, and they cannot be excluded by a contract term. Misleading or deceptive conduct in trade is prohibited, and the prohibition binds the publisher of a claim as well as the seller of the product. The Australian Competition and Consumer Commission enforces it: accc.gov.au.
- The Privacy Act 1988 (Cth)
- Governs how organisations handle personal information, through the Australian Privacy Principles. If an organisation holding your information suffers a data breach likely to result in serious harm, the Notifiable Data Breaches scheme requires notification. Privacy complaints go to the Office of the Australian Information Commissioner: oaic.gov.au.
A practical consequence for readers of sites like this one: a claim on a web page is conduct in trade. A publisher who invents a statistic, a test result or a testimonial to sell a subscription is exposed under Australian Consumer Law whether or not the vendor knew. That is the reason this site publishes no scores, no prices and no reader reviews, and the reasoning is set out on the methodology page.
When a subscription renews unexpectedly
This is the most common complaint in the security software category and it is not a scam — it is a term the buyer did not see. The sequence that works is ordinary and worth following in order.
- Find the original purchase confirmation and the terms that applied at the time.
- Identify where the subscription was bought, because a purchase made through an app store is usually cancelled and refunded there rather than by the vendor.
- Contact the seller in writing, state what you are asking for, and keep the thread.
- If the response is unsatisfactory, check the ACCC's guidance on consumer guarantees and on the complaint routes available in your state or territory.
- Raise a dispute with your card issuer only after the seller has had a chance to respond, since the issuer will ask what the seller said.
Online harm that is not about money
Not every incident belongs to a consumer or cybercrime agency. Image-based abuse, cyberbullying of a child, and seriously harmful online content are handled in Australia by the eSafety Commissioner, which has statutory powers to seek removal of material. If that is the situation, it is the right place to start rather than a scam report.
What genuinely reduces the risk
Very little of this list involves buying anything, which is itself worth saying on a site that earns money from a link.
- Keep operating systems and applications updated, and retire devices no longer receiving security updates.
- Turn on multi-factor authentication for email first, then banking, then everything else.
- Use a password manager so that a breach of one service does not become a breach of all of them.
- Keep a backup that is not permanently attached to the computer it backs up.
- Verify unexpected requests through a channel you chose yourself, never one supplied in the message.
- Treat urgency as the warning sign rather than the reason to hurry.
Anti-malware software is a reasonable addition to that list. It is not a substitute for any item on it, and a page suggesting otherwise is selling something.
Reporting routes in one place
| Situation | Where it goes |
|---|---|
| A scam, attempted or successful | Scamwatch, National Anti-Scam Centre |
| A compromised device or account, or other cybercrime | Australian Cyber Security Centre |
| Mishandling of your personal information | Office of the Australian Information Commissioner |
| A misleading claim or a refused consumer guarantee | ACCC, and your state or territory consumer affairs body |
| Serious online harm, abuse or harmful content | eSafety Commissioner |
| Money already taken | Your bank or card issuer first, then the relevant body above |
This site is not one of these bodies, has no connection with any of them, and cannot act on a report. It links to them because they are the organisations that can.