Hackers are watching you! e-mail scam: how to spot it and what to do
"Hackers are watching you!" is a fake iOS/macOS scam using fear to manipulate users into downloading unwanted apps. The 2022 guide identified it as a sophisticated social engineering attack with artificial urgency.
Facts checked October 5, 2026. Removal steps checked against Apple's current documentation and the security vendors' reports. We have not run the malware on a Mac. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your Mac is infected.
Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds before you decide anything.
Do it yourself · free Remove Hackers are watching you! e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Hackers are watching you! e-mail scam: summary
| Damage | Fake messages usually aim for users to download potentially unwanted or malicious programs, steal their personal information or trick them into subscribing to useless services |
|---|---|
| Name | Hackers are watching you! |
| Type | Scam, phishing, fraud, fake alert |
| Operation | Claims that the internet connection has been hacked and needs to be secure within two minutes. Otherwise, internet history and other data would be sent off to the contacts |
| Symptoms | A phishing e-mail asking you to sign in |
| Evidence | 4 write-ups by security sites; details still limited |
| Removal | Scan the Mac with security software to find the malware and anything installed with it. Fortect for Mac scans for malware and unwanted programs. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 6 more facts
| Arrives as | |
|---|---|
| Pretends to be | A well-known company |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 2 May 2022 |
| Facts checked | 5 October 2026 |
What the Hackers are watching you! e-mail scam e-mail looks like
Apple security
Hackers are watching you!
Your iPhone connection has been hacked and someone is watching on you! Please do not close this page. If you don't fix this in two minutes, the hacker will reveal your identity and send your browsing history and front-facing camera photos to everyone in your contacts!
Recovery method:
Step 1: Click the "Connection Protection" button below.
Step 2: You will be redirected to the App Store.
Step 3: Install and run the recommended protection app to recover your iPhone.
Protect your connection
How to tell the Hackers are watching you! e-mail scam e-mail is fake
From our report of May 2022 · not reviewed since
"Hackers are watching you!" is a fake message designed to sell software in the worst possible way
It would be unsettling to know that somebody has breached your privacy and can leak personal data to your contact list.
Hackers are watching you! pop-up scam is using precisely this method in order to make people download and install potentially unwanted applications on their devices. In this case, crooks are targeting Apple users, including those who utilize macOS and iOS devices.
The main purpose of this scam is to make people scared, all while saying that their systems have been breached and they need to secure their device within the two minutes, otherwise, all the browsing history would be sent off to the user's contact list. This is ultimately a lie, and you should not believe the "Hackers are watching you!" scam message.

From our report of May 2022 · not reviewed since
More from our earlier report on Hackers are watching you!
- To check the device for infections easily, scan it with security software
- After removal of adware and other PUPs, you should take your time to clean your browser from cookies and other trackers - can help you with that
Is Hackers are watching you! e-mail scam dangerous? What the senders want
From our report of May 2022 · outdated details corrected in October 2026
How do you end up on scam sites?
Evidently, people do not visit malicious websites purposely but venture there accidentally.
For example, websites that distribute illegal software, X-rated content, allow copyrighted video streaming, etc., are very much at fault for bringing users to malicious websites. Since they are usually poorly regulated, they are open to all sorts of malicious individuals and, in some cases, are created by them.
While security and ad-blocking software can greatly aid you in preventing the malicious links and scripts from being executed, it is best to stay away from such places in the first place. Downloading software from peer-to-peer networks and similar websites can also result in ransomware or other malware infections.
From there, users are usually redirected to the site which hosts the scam content, and there could be a variety of websites that do this, for example, securitycheck.network, or blocker.digital were spotted being used for fake alert distribution.
It is also important to note that adware could be one of the main reasons why you encounter phishing content online. Adware is also known to be one of the biggest problems for Mac users, as it was spread using fake application updates or pirated software installers.

From our report of May 2022 · not reviewed since
Fear used to manipulate users in various scam schemes
Social engineering is an art of human mind exploitation, and it's been a proven tactic by cybercriminals as extremely effective over many years.
Recently, we have seen a rise of extortion emails sent by cybercriminals that use a similar tactic to the Hackers are watching you! pop-up scam - they claim that the system has been hacked and a Trojan has been installed on the affected device.
They then demand users send Bitcoin to a special crypto-wallet if they don't want the allegedly filmed material of them watching XXX content to be leaked to their Facebook friend list.
Without a doubt, this new scam was inspired by these previous examples, as it makes people panic and, since they believe that the threat is real, they do what they are told by cybercrooks silently. Here is an example of the message you might expect after accessing a website that hosts the scam:
When dealing with messages that claim that something is missing or needs to be updated, always check the URL of the page showing it. The words within the URL can be "Security," "Scan," "Defender," and similar ones that are related to security. Users are almost always asked to download and install software which could be malicious.
Another thing to keep in mind is that logos, fonts, and other attributes of well-known companies can be easily forged online, so you shouldn't trust a logo just because it's there.
In fact, any message online that claims virus infections or data breach is fake and you should never adhere to it. The best thing is to close down the browser tab and check your device for infections using legitimate methods as described below.
From our report of May 2022 · outdated details corrected in October 2026
Make the necessary malware checks
While all the information shown within the Hackers are watching you! scam message is fake, you should still make computer checks to be safe.
Get rid of malicious apps
Adware can also be installed on the system level, so you should ensure that all of its components are eradicated.
Next, remove unwanted Profiles and Login items:
Finally, remove the PLIST files:
- Click Safari > Settings...
- In the new window, pick Extensions.
- Select the unwanted extension and select Uninstall.
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
- Open the Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- Here, select the unwanted plugin and click Remove.
- Open Applications folder
- Select Utilities
- Double-click Activity Monitor
- Here, look for suspicious processes related to adware and use the Force Quit command to shut them down
- Go back to the Applications folder
- Find ExtendedService in the list and move it to Trash.
- Go to Preferences and select Accounts
- Click Login items and delete everything suspicious
- Next, pick System Preferences > Users & Groups
- Find Profiles and remove unwanted profiles from the list.
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any suspicious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and delete all the related .plist files.
From our report of May 2022 · not reviewed since
Solution for iOS users
If you are encountering suspicious pop-ups on your iPhone, you can block them via the browser settings.
Here's what you should do:
Your next task is to make sure that your browser data is cleared so that you wouldn't be rerouted to the same malicious pages or that phishing content wouldn't be shown again.
- Open Settings and go to Safari
- Here, look for the following options: Block Pop-ups Fraudulent Website Warning
- Enable them by toggling the switch to the right.
- Go to Safari Settings once again and click Advanced
- Tap the Website Data section
- Select Remove All Website Data.
What to do after the Hackers are watching you! E-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you entered a password after clicking the link in the Hackers are watching you! Message, treat that account as known to the sender.
Open the provider's real site by typing its address yourself, not through any link in the e-mail, and change the password there. Choose a new one you have never used before, and change it on every other account that shared the old one.
Then use the option to sign out of all other sessions or devices, if the provider has one. This works the same in any browser on Windows 11 and Windows 10.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
Two-step verification asks for a code from your phone or an authenticator app whenever someone signs in from a new device. A stolen password alone is then not enough to open the mailbox.
Turn it on in the security settings of the e-mail account first, then for the bank, shop and social accounts that send their reset links to that address.
While you are there, check the recovery e-mail and phone number and the forwarding rules, which attackers sometimes change to keep access. The settings pages look the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Report the message instead of only deleting it. In Outlook choose Report > Report phishing, in Gmail the three-dot menu > Report phishing; the provider then blocks the same message for other people.
Do not reply and do not click anything else in it. On a work account, forward it to your IT team as an attachment first. Web mail and the mail apps on Windows 11 and Windows 10 offer the same options.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A page that only asked for a password installs nothing, so most readers can skip this step. If the Hackers are watching you!
E-mail or the page it opened made you download or open a file, delete it and run a full scan, then a Microsoft Defender Offline scan.
In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Choose a proper web browser and improve your safety with a VPN tool
Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.
One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.
However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.
Lost your files? Use data recovery software
While some files located on any computer are replaceable or useless, others can be extremely valuable.
Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:
- power cuts
- Blue Screen of Death errors
- hardware failures
- crypto-malware attack
- even accidental deletion
To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.
Questions about Hackers are watching you! e-mail scam
Is the 'Hackers are watching you!' pop-up real?
No. The "Hackers are watching you!" pop-up is a fake message and scam designed to sell potentially unwanted applications. The 2022 guide identified it as targeting Apple users on macOS and iOS devices.
The message falsely claims your iPhone or Mac connection has been hacked and someone is watching you, threatening to reveal identity and send browsing history and camera photos to your contacts.
All of this is false. No actual hacking has occurred. The scammers use fear and social engineering to manipulate you into downloading software, not because you are actually in danger.
What does the scam claim will happen if I don't respond?
The 2022 guide documented that the scam message claims that if you don't fix the alleged problem within two minutes, the hacker will reveal your identity and send your browsing history and front-facing camera photos to everyone in your contacts. The artificially urgent two-minute deadline is a psychological manipulation tactic used by tech support scams.
This creates artificial emergency pressure preventing rational thinking. In reality, no such threat exists and your contacts will not receive anything. The scammers rely on panic and fear to drive immediate action without verification.
What does the scam want me to download?
The 2022 guide noted that the scam directs you to click a "Connection Protection" button that redirects to the app store where you are encouraged to install a recommended "protection app." This protection app is the actual malware or unwanted program the scammers want you to install.
The app claims to recover your iPhone from the alleged hack, but instead collects your personal information or installs adware. Some fraudulent apps may request permissions to access your camera, contacts, and other sensitive device features without legitimate justification.
How do scammers trick me into visiting these fake alert pages?
The 2022 guide identified that users do not visit malicious websites purposely but land on them accidentally. Websites distributing illegal software, X-rated content, and copyrighted video streaming are major sources of malicious redirects. These poorly regulated sites are open to malicious actors or created by them.
Software downloaded from peer-to-peer networks can bundle malware redirecting to scam sites. Additionally, adware already installed on your device can redirect you to scam pages when you browse legitimately. Once redirected, the fake alert captures your attention through fear messaging.
Why do scammers use fear tactics to manipulate me?
The 2022 guide explained that social engineering is an art of human mind exploitation proven extremely effective by cybercriminals over many years. The "Hackers are watching you!" scam uses fear to bypass rational thinking and force immediate action. Similar extortion emails claim your system is hacked with trojan malware and threaten to leak filmed XXX content to Facebook friends.
These new scams were inspired by previous examples because fear works. Panic causes people to comply silently without questioning the threat's legitimacy. Understanding this manipulation tactic helps you resist the panic response.
How can I tell if a browser alert is fake?
The 2022 guide recommended checking the URL of any page showing security or system alerts. Fake alert pages often contain words like "Security," "Scan," or "Defender" in the URL. Always be suspicious of logos, fonts, and company attributes since these are easily forged online.
Never trust a logo just because it is present. Any message online claiming virus infections or data breach is fake and should be closed immediately. Legitimate Apple, Google, and Windows security alerts do not appear as demanding pop-ups with download buttons or app store redirects.
Should I disable ad-blockers or make browser exceptions for these pages?
No. The 2022 guide explicitly stated you should close down the browser tab showing the scam alert immediately. Do not make any browser exceptions, disable ad-blockers, or grant permissions requested by the fake alert. Instead, verify the alert's legitimacy through your device's official settings and legitimate security apps.
After closing the pop-up, perform a legitimate malware check through official means. Ad-blockers and browser protections exist to prevent exactly this kind of scam; they should remain enabled and configured to block these fraudulent pages.
What legitimate steps should I take after seeing a "Hackers are watching you!" alert?
The 2022 guide recommended closing the browser tab immediately and checking your device for infections using legitimate methods. Do not download or install anything from the scam page.
Open your browser settings and review Extensions to remove any suspicious plugins. Check your system's Applications folder for unwanted programs and delete them. Remove login items and suspicious profiles from your system preferences.
Finally, perform a full scan with legitimate anti-malware software to detect and remove any actual threats that may have been installed. Only use official security tools from reputable vendors.
Will Fortect remove Hackers are watching you!?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Hackers are watching you!, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Imperva: Social Engineering (read October 5, 2026)
- FTC: How to recognize and avoid phishing scams (read October 5, 2026)
- CISA: Recognize and report phishing (read October 5, 2026)
- Microsoft Support: Protect yourself from phishing (read October 5, 2026)
- NCSC: Phishing attacks, dealing with suspicious e-mails and messages (read October 5, 2026)