Staying Safe
The Scams That Actually Target Home Users
Fake support calls, phishing, invoice scams and fake warnings — the ones that reach ordinary people, how each works, and what to do if you engaged.
Workplace portals can be phishing targets too, including systems used for online timesheets; the same rule applies: verify the real domain before signing in.
Security advice tends to describe threats aimed at organisations. The things that reach ordinary people at home are a much shorter list, and they share one feature: they work on urgency rather than on technical sophistication.
The pattern behind nearly all of them
Something urgent has happened and you must act now.
An account will be closed. A payment failed. A parcel is held. Your computer is infected. A relative needs help. A refund is waiting.
Urgency is the tell. It exists to stop you checking, because checking is all it takes to defeat every scam below.
The rule that covers most of it: never act on an urgent message through the contact details it provides. Find the organisation yourself and contact them your way.
Fake technical support
How it works: a phone call, or a pop-up with a number to ring, claiming your computer is infected or your subscription needs renewing. They ask for remote access, "find" problems, and charge for fixing them — or install something, or take your banking details.
The absolute rule: nobody legitimate will telephone you about a virus on your computer. No manufacturer, no operating system provider, no internet provider. Not ever.
Pop-ups claiming infection are the attack, not a warning about one. A real security product does not ask you to telephone anyone.
If a pop-up will not close: close the browser through the task manager, or restart. Do not ring the number and do not click anything in it.
If you gave someone remote access: disconnect from the internet, run a full scan from your built-in protection, change passwords from a different device, and contact your bank if payment details were involved.
Phishing
How it works: a message that appears to come from a service you use, asking you to sign in, confirm details, or approve something. The link goes to a convincing copy of the real site.
The signals:
A link you did not expect. Even a perfect message from a real address is suspicious if you did not initiate it.
A sense of urgency or threat.
A slightly wrong address. Not the display name — the actual domain, which frequently differs by a character or has extra words before the real name.
Requests for information the organisation already has.
And plausibility rather than errors. The old advice about spelling mistakes is out of date; current phishing is well written.
The defence: never sign in through a link in a message. Open the site yourself, from a bookmark or by typing the address. This single habit defeats nearly all of it.
If you entered credentials: change that password immediately, from a different device if possible, and change it anywhere else you used it. Enable two-factor authentication. See two-factor authentication.
Fake invoices and subscription renewals
How it works: an email saying a subscription has renewed for a substantial sum, with a number to ring to cancel. There is no subscription. Ringing connects you to the scam.
Why it works: the response is not fear of a virus but annoyance at being charged, which bypasses the caution people apply to security warnings.
The defence: check your actual account or bank statement. If you did not subscribe, there is no charge to cancel.
Delivery and parcel scams
How it works: a text or email about a parcel needing a small fee, or a redelivery arrangement. The small fee captures card details.
Why it works: most people are expecting something.
The defence: track through the courier's own site or app, using the reference from your original order.
Marketplace and payment scams
How it works, when selling: a buyer overpays and asks for the difference back, or sends a fake payment confirmation, or insists on moving off the platform.
How it works, when buying: an item priced well below market, a seller who cannot meet, and a request for payment by bank transfer or gift card.
The rules: never accept an overpayment refund, never move off the platform's protected payment system, and be suspicious of any price that is too good.
Gift cards are never a legitimate payment method for anything. Any request for them is a scam without exception.
Impersonation of family
How it works: a message from an unknown number claiming to be a family member with a new phone and an urgent problem needing money. Increasingly with voice that sounds convincing.
The defence: ring the person on the number you already have. If they do not answer, ring someone else who knows them. Never send money on the basis of a message alone, however convincing.
Agree a family word — something a caller could be asked that a stranger would not know. Old-fashioned and effective.
Romance and investment scams
Both work slowly, over weeks or months, which is why the usual urgency advice does not apply and why they succeed against careful people.
Romance: an intense relationship that never involves meeting, followed by a financial emergency.
Investment: a returns opportunity, frequently involving cryptocurrency, with a platform showing growing balances that cannot be withdrawn.
Common signals: cannot meet in person, pressure toward a specific platform, small withdrawals allowed early to build confidence, and pressure to keep it private.
That last one matters. Both types isolate the person, which is why telling someone is the most effective single defence.
What to do if you have engaged
Stop communicating. Do not attempt to recover money through the same channel.
Contact your bank immediately if any payment or details were shared. Speed matters — some transactions can be stopped.
Change passwords from a different device, starting with email, because email resets everything else.
Enable two-factor authentication.
Run a full scan if anything was installed.
Report it to your national fraud reporting body and to the platform involved.
And be aware of recovery scams. People who have been defrauded are targeted again by "recovery services" who take a fee and do nothing. Anyone who contacts you offering to recover lost money is a second scam.
Do not be embarrassed into silence. These are professional operations that succeed against careful and intelligent people, and staying quiet is what allows them to continue.
The habits that prevent most of it
Never act on an urgent message through the contact details it provides.
Never sign in through a link.
Nobody legitimate rings about a virus.
Gift cards are never a payment method.
Ring the person you already know on the number you already have.
Take a day. Almost nothing genuine requires acting within minutes, and the delay defeats every scam here.
The short version
Urgency is the common thread, and it exists to stop you checking.
Nobody legitimate telephones about a virus, and a pop-up telling you that you are infected is the attack.
Never sign in through a link in a message — open the site yourself.
Gift cards and bank transfers to strangers are never legitimate.
And if you have been caught, contact your bank first and tell someone. Silence is what the second scam relies on.
For practical baseline security guidance for home users, see CISA Secure Our World.