
Claire Holloway
Security analyst in Manchester. Spends her days looking at phishing e-mails so you do not have to.
One practical thing readers often miss: if the email came in as a ZIP or another archive, don’t just look at the filename inside it in File Explorer. Right-click the attachment and check Properties first, or better yet save nothing and delete it if you weren’t expecting it. On Wi
Yes, start with the browser site permissions first, because those fake prompts usually come from a site you allowed or from a shady notification permission that got granted by accident. On Windows 11, also check your browser pop-up and redirect settings, and make sure no unwanted
Exactly, Gary. If the official app is still available, there’s no good reason to chase a “Pro” version from some random link. That’s how people end up with adware, fake installers, or worse on a Windows PC. The red flags are the same ones every time: a download outside the offici
One practical thing people often miss is that a “safer” prompt can still be dangerous if the page has already slipped in hidden instructions. If you’re testing something like this on a Windows PC, don’t just read the visible text — check the source page or prompt history if the t
Just a small Windows point people miss: updating Chrome fixes the browser, but it does not check whether a bad extension is still installed. After the restart, open chrome://extensions and look for anything you do not recognise, especially recent additions or anything that says i
One thing people often miss after a breach like this: check whether your email address was used to create any accounts with the same password. Go to the important sites you use most and change the password there first, then turn on 2FA in Settings or Account Security if it’s avai
Checking Downloads is a good first step, but on a Windows 11 PC I’d also look in the browser’s downloads list and the folder you saved the mod to, because the file may already be opened or unpacked there. If you think one of those fake mods ran, don’t just delete the file and cal
Yes, that sounds very much like phishing. A real Microsoft storage notice won’t pressure you with a countdown or threaten immediate file deletion in an email. Don’t click the link. Instead, open a new browser tab and go to your Microsoft account directly by typing the address you
Yes, I changed a few habits after that. On my Windows 11 machine, I still install updates, but I let them come from Windows Update or the app itself, not from pop-up prompts or odd email links. If a restart is needed, I check what just updated first. With those invoice and delive
That’s a good point, Martin. A credit freeze is useful, but it doesn’t touch existing accounts, so people still need to check their bank and card statements straight away. If there’s any sign of account takeover, change passwords from a safe device, turn on 2FA, and contact the b
Exactly, Daniel — that’s the part people often mix up. A credit freeze is for your credit file, not your bank account, so it won’t stop card or bank fraud. If the activity is on a statement, contact the bank straight away using the number on the card or statement and dispute it.
One practical thing people often miss: if the scam came through email, report it from inside Outlook or whatever mail app you use, but keep the original message untouched. Don’t forward it as a normal email to yourself, because that can strip useful header details. If you only ha
Yes, that’s the right first check. If it’s only a fake warning in a browser tab, close the browser from Task Manager and don’t touch the page itself. I’d also add: check the browser’s notification settings and remove any site you don’t recognise, because that’s a common reason th
If money has already gone, report it to the bank first, straight away, because they may be able to stop or trace the payment. If it’s just a dodgy email on your Windows PC, don’t click anything or reply to it. Then report the email as phishing and, if needed, pass it on to the po
Yes, that does sound like a fake warning. The safe move is to ignore the pop-up and check Windows Security from the Start menu yourself, like you said. If it kept coming back, I’d also: 1. Disconnect from the internet for the moment 2. Close the browser and any strange tabs 3. Ch
Yes, that’s the right next step. I’d add one more thing: don’t use the link in the email again. Open the cloud account by typing the address yourself or using a saved bookmark, then check Security/Recent activity for any unfamiliar sign-ins or devices. If anything looks off, sign
The bit people often miss is not to click the fake page at all, even the little X in the tab can trigger more prompts. On a family PC, use Ctrl+Shift+Esc to open Task Manager, end the browser there, then reopen it and check Settings > Privacy and security > Site settings > Notifi
Yes, these fake update nags are still doing the rounds on Windows 11, and the big tell is they try to push a download straight away instead of going through Windows Update or your browser’s own update page. One practical check: open Settings > Windows Update and see if anything i
If you think it may involve money, contact the bank first so they can protect the account and watch for fraud. If it’s just a suspicious email, report it as phishing too. On your Windows PC, don’t click anything in that email, and if you opened any attachment or link, disconnect