Get-shields.com e-mail scam: how to spot it and what to do
Get-shields.com is a malicious website designed by crooks. Most commonly, people do not enter it intentionally but are rerouted to it after clicking a link on some shady website or taking it by automatic scripts.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove Get-shields.com e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Get-shields.com e-mail scam: summary
| Damage | Fake messages usually aim for users to download potentially unwanted or malicious programs, steal their personal information or trick them into subscribing to useless services |
|---|---|
| Name | Get-shields.com |
| Type | Scam, phishing, fraud, fake alert |
| Operation | Claims that Chrome browser has been damaged by malware. It then asks users to download a fake security tool to remove it |
| Symptoms | A phishing e-mail asking you to sign in |
| Evidence | 4 write-ups by security sites; details still limited |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 6 more facts
| Arrives as | |
|---|---|
| Pretends to be | |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 22 June 2022 |
| Facts checked | 7 October 2026 |
What the Get-shields.com e-mail scam e-mail looks like
WARNING! Your Chrome is severely damaged by 13 Malware!
We have detected that your Chrome is (62%) DAMAGED by Tor.Jack Malware. Malicious and Aggressive Ads have injected this on your device.
Immediate Action is required to Remove and Prevent it from spreading that will leak sensitive data from your device. It includes your Social Media Accounts, Messages, Images, Passwords, and Important Data.
Here is how you can solve this easily in just a few seconds.
Step 1: Click the button below, "Allow error alerts," then subscribe to recommended spam protection app on the next page.
Step 2: Run the powerful Google Play-approved application to clear your phone from SPAM ads and block potential Malware with a few taps.
How to tell the Get-shields.com e-mail scam e-mail is fake
From our report of Jun 2022 · not reviewed since
- You should not interact with the content shown by a scam website.
- Instead, check your system for adware or malware infections with security software
- You should remove caches and other web data to prevent data tracking - use the repair and maintenance tool.
- You can also repair damaged system components with it
Is Get-shields.com e-mail scam dangerous? What the senders want
From our report of Jun 2022 · not reviewed since
Get-shields.com shows fake messages that encourage users to download potentially unwanted applications
Get-shields.com is a malicious website designed by crooks.
Most commonly, people do not enter it intentionally but are rerouted to it after clicking a link on some shady website or taking it by automatic scripts. The important part here is that users do not expect the redirect to happen, hence why the hosted scam sees moderate success over time.
Once there, users are presented with the "WARNING! Your Chrome is severely damaged by 13 Malware!" scam message, which is meant to frighten them and try to convince them that their systems are infected - this is typical social engineering technique operated by tech support scammers. Get-shields.com also pretends to represent "Google Security," which is not at all true, as Google has nothing to do with this.
The main goal of scammers is to make users download questionable software - an activity that they financially profit from.

From our report of Jun 2022 · not reviewed since
The scam message and what it means
Tech support scams are extremely effective because they attempt to abuse users who are not familiar with them and computing in general.
When users are frightened, they become extremely worried about their computer security and personal safety, which can prompt them to make rash decisions. Get-shields.com tries to abuse this situation.
As soon as users enter the page, they are presented with one of the fake messages that the scammers host. Most commonly, people might be shown the following widespread scam:
In this example, crooks are claiming that the system was infected with so-called Tor.Jack malware, which actually does not exist, and the name is completely fabricated. Crooks prey on users who are not familiar with these technicalities, and their goal is to throw as much scary, confusing information as possible.
What to do after the Get-shields.com e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you typed a password on the page the Get-shields.com message opened, assume the sender has it. Go to the real site by typing its address yourself and change the password there, choosing one you have never used.
Change it anywhere else the same password was used, and sign out all other sessions if the service offers it. Any browser on Windows 11 or Windows 10 will do, as long as you do not follow the e-mail's link.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
With two-step verification on, a stolen password alone no longer opens the account, because a sign-in from a new device also needs a code from your phone.
Switch it on for the e-mail account first, then for banking, shopping and social accounts that use that address.
Check the recovery phone, the recovery e-mail and any forwarding rules while you are in the settings, since attackers change them to come back. The pages are the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Do not reply and do not click anything else in the message. In Outlook select the e-mail and choose Report > Report phishing; in Gmail open the three-dot menu next to Reply and pick Report phishing.
That trains the filter for everyone on the service, and the message goes to the junk folder. If the e-mail came to a work address, forward it to your IT team as an attachment first.
The steps are the same in the web mail and the mail apps on Windows 11 and Windows 10.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A fake sign-in page only steals what you type, so most readers can skip this step. If the Get-shields.com e-mail made you download or open a file, delete it and scan the PC.
In Windows Security > Virus & threat protection > Scan options, run a Full scan and then Microsoft Defender Antivirus (offline scan) > Scan now. The offline scan restarts Windows 11 or Windows 10 and takes about 15 minutes.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
From our report of Jun 2022 · not reviewed since
Remediation steps and how to remove adware
Many users immediately assume they have been infected with a virus once they are redirected to Get-shields.com.
While all the statements and messages on the page are fully fabricated, dismissing the possibility of infection completely is not advisable. Adware, for example, is one of the most common infections that users don't expect to find on their systems, as it is spread using deceptive distribution methods such as bundling or fake updates.
Remove unwanted or malicious apps
Adware might be responsible for phishing, and other dangerous websites users encounter regularly. Alternatively, you can look for unwanted programs yourself as follows:
While moving apps into Trash is usually how you delete most normal applications, adware tends to create additional files for persistence. Thus, you should look for .plist and other files that could be related to the virus. If you are not sure, skip this step entirely.
To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
Don't forget to check for unwanted extensions - you can find them by accessing browser settings or clicking the "Extensions" button on the browser.
Clean your browsers to secure your privacy
To stop the unwanted tracking activities, you should remove cookies and other trackers from your computer. To do that, you should access browser settings or employ a powerful PC maintenance tool , which can also be used to fix any virus damage if such has occurred.
MS Edge (Chromium)
- Enter Control Panel into the Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till uninstallation process is complete and click OK.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Click Menu and pick Options.
- Go to Privacy & Security section.
- Click on Clear Data...
- Select Cookies and Site Data, as well as Cached Web Content and press Clear.
- Click on Menu and go to Settings.
- Select Privacy and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.
- Click Safari > Clear History...
- From the drop-down menu under Clear, pick all history.
- Confirm with Clear History.
Questions about Get-shields.com e-mail scam
Can reading "WARNING!" infect my computer?
Reading it cannot. An e-mail is text and pictures, and current versions of Outlook, Gmail and other web mail services do not run code from a message just because you opened it. What can cause harm is an action:
- signing in on the page the link opens
- opening an attachment
- enabling macros in a document
The message "WARNING!" was built to lead you to one of those steps. If you stopped at reading, delete it and use the report button so the provider can block the same wave for others. Nothing needs to be removed from Windows.
How fast do I need to react after signing in on the "WARNING!" page?
As fast as you can. Stolen passwords are often tried within minutes, and the first thing an attacker usually changes is the recovery e-mail or phone, which locks you out. Change the password from a clean device first, then sign out everywhere and review the recovery settings.
If you are already locked out, use the provider's account recovery form straight away and mention that the page behind "WARNING!" took your password. Warn your contacts, since a taken-over mailbox is often used to send the same phishing to them.
Could Get-shields.com be a genuine message?
We checked it, and it is not. Google is only the costume. The message exists to get your password, and real companies handle that inside your account, after you sign in normally, not through links, attachments or phone numbers in a message you did not expect.
Scammers copy logos and footers perfectly, so the design proves nothing. The sender address, the link target and the request are the reliable signs, and all three point to a scam here. Delete it, and if you are worried, check your account directly.
Why does Get-shields.com say that your account needs urgent attention?
Because that story works. A problem that needs fixing, a deadline and a simple solution make people act before they check.
The claim that your account needs urgent attention is the same for everyone who received Get-shields.com; it was written once and sent in bulk. Nothing about your own situation triggered it.
If you are unsure, look at the real account or service the normal way, without using the message. The claim will not be there, which settles the question. Then report the message.
What does Get-shields.com want from me?
In the end, your password. Everything else in Get-shields.com, from the logo to the deadline, is there to get you to that point without stopping to think. Knowing the goal helps you judge your risk.
If you did not give it, you lost nothing and can delete the message. If you did, the steps in this guide are ordered by what you handed over:
- passwords first
- then card and bank details
- then documents and anything you installed
- ran
Act on the highest item on that list first.
How do I contact the real Google?
Not through anything in Get-shields.com. Type the official website address into the browser yourself, use the app you already have, or use the phone number printed on your card, contract or a previous genuine invoice.
Search results can be risky too, because scammers buy ads for support numbers. Once you reach the real Google, you can ask whether there is any problem with your account and report the scam message; many companies have a dedicated address for phishing reports on their security page.
Could malware on my computer cause Get-shields.com?
It can, but it is not the most common cause. Information stealers copy saved passwords and session cookies from browsers, which can lead to an e-mail with the subject "WARNING!". More often, the password came from a breach or a phishing page.
To be sure, run a full scan in Windows Security and check Installed apps and browser extensions. If anything is found, clean the PC first and change passwords afterwards from a clean device, because changing them on an infected PC lets the malware take the new ones too.
Why did I receive Get-shields.com?
Scam messages go to millions of addresses and numbers collected from data breaches, public websites and simple guessing. Receiving Get-shields.com does not mean your PC is infected or that an account of yours was hacked.
If the message includes an old password of yours, it comes from a breach of some website; change that password wherever you still use it. Mark the message as spam or phishing so your provider blocks similar ones. Never reply to ask to be removed from the list: the sender treats a reply as proof that the address works.
What should I do first after Get-shields.com?
Secure the account involved. From a device you trust, open the official app or website directly, change the password and sign out of all sessions. Turn on two-step verification with an app or a passkey rather than text messages if the service allows it.
Then check recent activity, linked e-mail addresses and recovery phone numbers for changes you did not make. If an e-mail with the subject "WARNING!" involved money, call your bank using the number on the back of your card. Only after that look into how it happened.
Will Fortect remove Get-shields.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Get-shields.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- WeLiveSecurity: Malicious scripts in compromised websites and how to protect yourself (read October 7, 2026)
- Imperva: Social Engineering (read October 7, 2026)
- FTC: How to recognize and avoid phishing scams (read October 7, 2026)
- CISA: Recognize and report phishing (read October 7, 2026)
- Microsoft Support: Protect yourself from phishing (read October 7, 2026)