Posted on

Cloned package-tracking pages that request unnecessary payments

“Your package could not be delivered” is an unusually efficient scam message.

The sender does not need to know whether you ordered something.

Enough people are waiting for enough packages that the message will eventually land on somebody at exactly the right moment.

The United States Postal Service warns about smishing messages that impersonate delivery services and use lures such as a problem with the shipping address or a package waiting at the Post Office. The goal is to pull the recipient toward a site that requests personal or financial information.

USPS also states something worth remembering when a page suddenly asks for a small “redelivery” charge: USPS does not charge a fee for redelivery.

See the USPS Scams & Scheme Alerts.

The copied tracking page supplies the missing credibility

A delivery scam becomes more convincing after the click.

Instead of a crude form, the victim may see familiar carrier colors, logos, progress bars, tracking language, and fields that resemble the real company’s site. The page can claim that delivery failed because an address must be corrected or a minor fee must be paid.

The amount may be deliberately small.

A $1 or $3 charge feels more like postage than theft, which makes entering a payment card seem reasonable. But the valuable part may be the card information itself, along with the victim’s name, address, phone number or other data entered into the fake page.

The cloned appearance does not make the seller, carrier or tracking record real.

Check the shipment without using the message

If a delivery notice seems plausible, verify it independently.

Open the carrier’s official website or app yourself. If you have a genuine tracking number from the retailer or order confirmation, enter it there. Do not rely on the link in the unexpected text or email to tell you which site is the carrier.

If the message claims a payment is required, check the carrier’s published policies before entering financial information.

This is particularly useful because the scam’s strongest evidence is often coincidence: you really are expecting a package.

That coincidence proves only that packages are common.

It does not prove that the message came from the company carrying yours.

The cloned tracking page is designed to make an ordinary delivery delay feel like a transaction that must be completed immediately.

The safer approach is to leave the transaction behind and ask the real carrier what is actually happening.

Posted on

Malicious advertisements delivered through apparently ordinary websites

You can be on the right website and still be looking at the wrong advertisement.

That is the uncomfortable part of malvertising.

Microsoft defines malicious advertising as a situation in which an attacker submits malicious content to an advertising network and that content is then hosted by a benign website. Its SmartScreen documentation even includes a demonstration scenario described as a benign page hosting a malicious advertisement.

See Microsoft’s SmartScreen explanation of malvertising.

The publisher does not have to be the attacker.

The ad can come from somewhere else

Modern websites often sell advertising space through networks and exchanges rather than selecting every advertisement manually.

The page belongs to the publisher. The ad may be supplied through an external advertising chain.

That separation is useful for legitimate advertising because it lets publishers fill inventory automatically. It also creates a place where malicious creatives, redirects, fake warnings, or dangerous destinations can enter the page without the site’s ordinary editorial content being compromised.

Google’s own Ad Manager documentation warns publishers about ads that trigger automatic redirects or pop-ups and classifies them as malvertising. Google says it scans creatives and blocks malicious content, while also noting that third-party exchanges and other demand sources may have different protections.

See Google’s Ad Manager guidance on malware in ad content.

Trust in the host leaks into the advertisement

Users rarely think about the supply chain behind a rectangle on a webpage.

If the surrounding site is familiar, the advertisement benefits from the site’s reputation. A fake update, fake security warning, investment offer, or download button can feel less suspicious because it appeared inside a place the user already trusts.

But ad placement is not an endorsement of the destination.

Microsoft notes that malicious ads can redirect users to phishing sites, initiate unwanted downloads, or push people toward further social-engineering steps.

Treat the click as a new destination

A reputable publisher is evidence about the publisher.

It is not proof about every advertiser delivered through that page.

Before entering credentials, downloading software, or paying for something reached through an ad, inspect the destination as a separate site. Check the domain. Reach the company independently if the offer involves an account or service you already use. Prefer the vendor’s known website for downloads and sensitive transactions.

Malvertising exploits a mental shortcut that normally works well: I trust this place, therefore the things inside this place are probably safe.

Advertising networks make that conclusion less reliable.

The webpage can be legitimate while one rectangle inside it is somebody else’s trap.

Posted on

Fake CAPTCHA prompts that ask users to perform unsafe actions

A CAPTCHA is supposed to ask the website a question about you.

It is not supposed to ask you to operate the computer on the website’s behalf.

Microsoft has documented a social-engineering technique known as ClickFix in which attackers imitate familiar human-verification pages such as CAPTCHA, reCAPTCHA, or Cloudflare-style checks. Instead of merely asking the visitor to click a box or solve a challenge, the fake page gives instructions that lead the user into running a command on the computer.

See Microsoft’s analysis of ClickFix.

The request stops matching the job

A legitimate human-verification challenge exists to distinguish a person from automated traffic.

It may ask you to click a checkbox, identify images, wait briefly, or complete some other interaction inside the browser.

The fake version changes the assignment.

It might tell you to open a system dialog, paste something from the clipboard, launch a terminal, or perform some unrelated sequence of operating-system actions. Microsoft says ClickFix campaigns use exactly this mismatch to get users to initiate the infection themselves.

That is the useful warning sign: the “verification” begins asking for capabilities that a normal CAPTCHA does not need.

Familiarity lowers suspicion

CAPTCHAs are annoying but ordinary. People have been trained to comply with them quickly because they appear during sign-ins, downloads, ticket purchases and other routine web tasks.

Attackers borrow that muscle memory.

Microsoft has observed fake CAPTCHA pages used in campaigns that ultimately install information-stealing malware or remote-access software. Its security intelligence also classifies fake CAPTCHA behavior as a social-engineering technique rather than a real verification system.

See Microsoft’s FakeCaptcha threat description.

A CAPTCHA should stay in its lane

If a human-verification page suddenly asks you to open Windows Run, PowerShell, Terminal, or another system tool and paste or execute something, stop.

Do not finish the instructions merely because the page says they are required.

Close the page and return to the service through its known address. If the site genuinely requires verification, it can present a normal challenge again.

The fake CAPTCHA depends on one assumption: that a familiar box labeled I am not a robot will make every instruction beneath it feel equally legitimate.

It should not.

The moment the test asks you to become the installer, the test has changed.

Posted on

Tech-support scams that turn an alarming pop-up into remote access

The pop-up is not the main event.

The remote-control session is.

The Federal Trade Commission describes a common tech-support scam in which a bogus warning claims the computer has a virus or other serious problem and tells the user to call for help. The supposed technician then asks for remote access to the computer, pretends to diagnose an infection, and sells an unnecessary repair or uses the access for something worse.

See the FTC’s guide to tech-support scams.

Remote access changes the problem completely

Before remote access is granted, the scammer has a story.

After remote access is granted, the scammer may be able to see what is on the screen, manipulate files, install software, observe passwords, or guide the victim through banking and payment steps while appearing to “fix” the machine.

The FTC has brought cases involving operators who used frightening pop-up advertisements, claimed affiliation with Microsoft or Apple, and persuaded people to allow remote access. Once connected, the operators pointed to harmless system information as supposed evidence of infection and sold unnecessary services.

See the FTC’s 2019 refund announcement involving a tech-support operation.

The crucial move is therefore not the fake scan. It is the transfer of control.

Break the chain before the technician becomes “trusted”

If an unexpected warning tells you to call technical support, do not use the number in the warning.

If someone contacts you unexpectedly and says your computer has a problem, do not give that person remote access.

Instead, close the message and contact the software vendor, device manufacturer, employer help desk, or another trusted technician through contact information you obtained independently.

Microsoft states that it does not make unsolicited calls offering technical support and that genuine Microsoft error messages do not include phone numbers telling users to call.

See Microsoft’s tech-support scam guidance.

A convincing scammer may know real technical terms. The remote-access program itself may also be legitimate software commonly used by actual support departments.

Neither fact proves the person on the other end should control the machine.

The authority has to be verified before access is granted, not after the stranger is already moving the mouse.

Posted on

Browser warnings impersonating an antivirus product

A web page that says FIVE VIRUSES DETECTED has already accomplished one thing.

It made the browser look like a security product.

Microsoft documents tech-support scam pages that display fake error messages, switch the browser into full-screen mode, trap users in repeated pop-ups, and present a phone number for supposed technical help.

The important clue is that the warning is coming from the page, not from the security product it claims to represent.

See Microsoft’s guidance on tech-support scams.

A claim of a scan is not evidence of a scan

A deceptive page can put almost anything on the screen: a progress bar, a list of infected files, a familiar antivirus logo, flashing red borders, siren sounds, or a percentage counter labeled Scanning....

Those graphics prove that the webpage can draw graphics.

They do not prove that the named antivirus company inspected the computer and found the threats listed on the page.

Microsoft makes one particularly useful distinction: genuine Microsoft error and warning messages do not include phone numbers telling users to call support.

That simple rule breaks a large family of scare pages.

Leave the page before diagnosing the machine

If a browser page suddenly announces a severe infection, do not use the page itself as the route to diagnosis.

Close the tab or browser. If the page has trapped the browser in full screen or repeated dialogs, use the operating system to close the browser rather than clicking buttons inside the warning. Then open the security software already installed on the machine and run its normal scan or update process.

Microsoft also recommends downloading software only from official vendor sites or trusted application stores rather than from links supplied by the warning.

See Microsoft’s Defender guidance on support-scam pages.

A real security alert can certainly be urgent.

The difference is authority.

Your installed antivirus, operating system and browser have defined ways to report danger. A random page that suddenly claims to represent one of them is merely a page until independently verified.

The scareware trick is to collapse those two things into one.

It wants the message about your security software to be mistaken for a message from your security software.

Posted on

Fake customer-support accounts that intercept requests for help

Posting a public complaint can accidentally create a customer-service wanted ad for scammers.

You identify the company. You describe the problem. You reveal that you want help now.

The impostor only has to answer first.

In 2024, the Federal Trade Commission warned that scammers were monitoring social media for travelers complaining about airline delays and cancellations. Fake customer-service accounts then contacted those travelers pretending to represent the airline.

The scammers asked for booking information, phone numbers, bank details, or directed victims to spoofed websites.

See the FTC’s warning about airline customer-service impersonators.

The scammer already knows the problem

This attack has an advantage over a random phishing message: context.

If you just posted that your flight was canceled, an account replying with “We can help with your rebooking” does not have to guess what will get your attention.

The public conversation supplied the script.

A copied company logo, a support-sounding username and a polite reply can be enough to move the conversation into direct messages, WhatsApp, text messages, or a fake form where the requests become more sensitive.

That is why apparently relevant information is not proof that the responder is legitimate. The scammer may know the details simply because you posted them publicly.

Verify the channel, not the tone

The safest way to confirm support is to approach the company independently.

Open the airline, bank, retailer or service’s official website or app and find its support channel there. If the company lists official social-media accounts, follow those links from the company’s own site rather than trusting a username that looks close enough.

The FTC specifically recommends contacting airlines through their official app, website, chat, phone number, or an in-person representative. It also warns against sharing personal information over social media.

This matters because good manners are easy to imitate.

A fake support account can apologize, use your name and promise to escalate the case. None of that gives it authority over your reservation, account, refund or money.

Public customer service creates a strange asymmetry: everybody can see who needs help, but the customer may have difficulty seeing who actually has the right to provide it.

That uncertainty is exactly where the impostor works.

Posted on

Imitation storefronts built around stolen retail identities

A fake store does not have to invent a convincing retailer.

It can steal one that already exists.

In 2025, after JOANN announced store closures and liquidation sales, the Federal Trade Commission warned about bogus websites advertising supposed online JOANN bankruptcy sales with discounts of 80% to 90%.

The useful detail was simple: the real liquidation sales were happening in physical stores. JOANN was no longer selling online. The websites using the brand online were not an unusually generous version of JOANN. They were impostors.

See the FTC’s warning about fake JOANN sales.

Familiar branding supplies borrowed credibility

A copied storefront can reuse almost everything a shopper recognizes: company name, logo, product photography, category structure, sale banners and even fragments of policy text.

None of those elements prove who is actually taking the payment.

That is the important gap.

The page may say JOANN, Nike, a local dealership or some other established retailer. The merchant processing the payment can still be an unrelated party operating a different domain.

The FTC says scammers commonly impersonate real companies in social-media ads and lead shoppers to fake sites offering famous brands at unusually low prices. Victims may receive a counterfeit item, something unrelated, or nothing at all.

See the FTC’s guidance on brand-name shopping scams.

Check evidence outside the store

A fake storefront controls everything inside its own page. That means its reviews, countdown timers, stock warnings and claims about a liquidation sale are weak evidence.

Useful checks happen somewhere the seller does not control.

Go independently to the retailer’s known website. Search for the seller’s domain and company name with words such as scam, complaint or review. Compare the advertised price with established retailers. Check whether the company’s official channels even acknowledge the sale.

When paying, a credit card generally provides stronger dispute protections than gift cards, wire transfers, cryptocurrency or other hard-to-reverse methods. The FTC specifically warns against sellers that insist on those difficult-to-recover payment methods.

A copied logo is cheap.

A real commercial identity is harder to fake once you stop asking the storefront to verify itself.

Posted on

Typosquatted domains that exploit small typing errors

The difference between the right website and the wrong website can be one missing letter.

That is enough.

Typosquatting is the practice of registering a domain that resembles a familiar one closely enough to catch people who mistype the address or fail to notice a small change. Microsoft gives the simple example of a missing letter in a company name; ICANN’s security work describes the same problem with lookalike domains such as faceboook.com or goggle.com.

See Microsoft’s explanation of typosquatting and ICANN’s DNS security study.

The trick is effective because users usually recognize a domain as a shape, not as a forensic specimen.

Familiar enough is often enough

A mistyped address may lead to a harmless parking page full of ads. It can also lead to a copied login page, a fake store, or a malware download.

The attacker benefits from recognition already earned by somebody else. The colors, logo and layout can all imitate the legitimate service. The domain only needs to survive a glance.

The browser’s lock icon does not solve the problem. Encryption can protect the connection to the wrong site just as effectively as it protects the connection to the right one.

That means the useful question is not simply, “Is this connection encrypted?”

It is, “Who owns the address I actually reached?”

The visible address is evidence

Before entering a password, payment card, recovery code or other sensitive information, look at the registered domain itself rather than the page design.

A scammer can copy the page. The scammer cannot place a fake page at the genuine domain unless that domain has also been compromised.

Microsoft recommends using saved favorites for important banking, shopping and social sites instead of retyping the address each time. Modern browsers may also warn about common mistyped domains, but those protections are assistance rather than permission to stop looking.

The FBI makes the same general point in its phishing guidance: carefully examine URLs and spelling because scammers deliberately use small differences to gain trust.

See the FBI’s spoofing and phishing guidance.

Typosquatting is almost insultingly simple.

That is why it remains useful.

The attacker does not need to defeat the real website. The attacker only needs to stand one character away from it.

Posted on

Fake download buttons that divert users from the intended software

A software download page should contain one obvious answer to one obvious question.

Where is the download?

The predatory version contains four answers, three of them lying.

Fake download buttons work because users arrive with their attention already narrowed. They know the program name. They want the installer. A large button saying DOWNLOAD NOW feels like navigation rather than advertising.

That visual assumption is the target.

The advertisement borrows the job of the page

Google’s advertising policies explicitly prohibit misleading designs such as image ads containing download or install buttons and ads that resemble system messages or site controls.

Its AdSense guidance is even more direct: ads should be kept away from download buttons because users may mistake the advertisement for the download link.

See Google’s misleading ad design policy and AdSense policy guidance.

The rule exists because the confusion is predictable.

An unrelated installer does not have to defeat the user’s security software if it can first convince the user to run it voluntarily.

Sometimes the whole page is the fake button

Mozilla has documented fake Firefox update pages and advertisements that tell users an urgent or critical browser update must be downloaded manually. Mozilla identifies these as scam tactics used to distribute malware or malicious extensions.

Firefox normally updates automatically and provides its own built-in update mechanism. A random webpage demanding an executable is not part of that process.

See Mozilla’s fake Firefox update warning.

The Federal Trade Commission gives similar advice for software advertised through search engines and social media. Criminals can buy ads for recognizable software, send the click to a cloned site, and deliver malware instead. The FTC recommends bypassing the advertisement and going directly to the software publisher’s site.

See the FTC’s consumer alert on fake software ads.

The genuine path is usually less exciting

A real download link does not need to scream.

Before running an installer, identify the publisher first. Confirm the domain belongs to the developer. Prefer the developer’s own download page or an official application store. Check that the filename and digital signature correspond to the software you intended to install.

Do not assume the largest button is the correct one merely because it is visually dominant.

That is the entire trick behind the fake-download-button economy.

The user thinks the page is helping locate software.

The page is sometimes auctioning the moment immediately before the click.