AdeptBaseReference for Australia

Consumer reference

Security-themed scams, consumer rights and who to contact in Australia

A large share of the fraud that borrows the language of computer security never touches a computer. It works by conversation. This page describes the recurring patterns in neutral terms, sets out what Australian consumer law provides when a subscription goes wrong, and lists which body handles which complaint.

Nothing on this page is a statement about your device. AdeptBase cannot see any visitor's computer, runs no scan, and makes no claim about whether anything is wrong with yours. The patterns described below are described because they are documented publicly by Australian agencies, and because recognising a pattern calmly in advance is more useful than reacting to it under pressure.

The unsolicited technical support call

The longest-running pattern in this category is a call, or a pop-up giving a number to call, from someone presenting themselves as technical support for a well-known software or telecommunications company. The caller reports a problem they cannot actually know about, asks for remote access to demonstrate it, shows something on screen that is presented as evidence, and moves to payment, a refund process that requires banking access, or the installation of software.

Three details are worth holding onto. Software vendors and internet providers do not telephone individuals about malware found on their machines; they have no way of detecting it from outside. Ordinary system logs and diagnostic tools always contain warnings and errors on a healthy computer, so anything shown from them is not evidence of a problem. And remote access, once granted, is total: the person on the other end can see and do anything the account can, including opening banking sessions and installing software.

The response that works is procedural rather than clever: end the call, do not call back a number the caller supplied, and if you need to check whether the company was really trying to reach you, contact them through a number you looked up yourself. Reports go to Scamwatch, which is operated by the National Anti-Scam Centre and publishes descriptions of the scam types currently circulating.

Pages that imitate a security warning

The web equivalent is a page that mimics an antivirus interface or a system dialog: a progress bar, a list of problems apparently found, a countdown, a number to call or a button to install a fix. This is scareware, and its whole method is producing enough urgency that the viewer acts before thinking.

The structural giveaway is simple and always available: a web page cannot scan a computer. Browsers deliberately prevent page code from reading the file system, listing running processes or examining installed software. Any page reporting infections is reporting a result it has no mechanism to obtain, whatever the layout suggests. The same reasoning applies to a page claiming your subscription has expired, your licence is invalid, or your device is unprotected.

Closing the tab ends it. Where a page resists closing, closing the browser entirely, or restarting the machine, does. Nothing needs to be installed and no number needs to be called, and a genuine product on your computer reports through its own interface rather than through a web page.

Renewal notices and invoices that arrive by email

A common variant arrives as an invoice or renewal confirmation for security software, often for a plausible amount in AUD, with a telephone number or link for cancelling a charge the recipient never authorised. The objective is the call or the click, not the invoice: the money never existed, and the conversation moves to a refund that requires remote access or card details.

The check is the same each time and does not involve the message at all. Open your bank or card statement independently and look for the charge. If there is no charge, there is nothing to cancel. If there is one, go to the vendor's own site or your card issuer directly, using contact details you already have. Messages of this kind can be reported to Scamwatch, and where email or account credentials have been entered into a linked page, the guidance and reporting route at cyber.gov.au applies.

Where a real subscription has gone wrong

Not every complaint is a scam. Automatic renewals charged after a reader believed they had cancelled, software that does not do what the sales page described, and refunds that are refused are ordinary consumer matters, and Australian Consumer Law applies to software sold to consumers in Australia alongside whatever the vendor's own refund policy says.

Two principles are worth knowing in outline. Consumer guarantees are set by law and cannot be excluded by a contract term, so a clause purporting to remove them does not achieve that. And conduct that is misleading or deceptive in trade is prohibited, which covers how a price, a renewal or a product's capabilities are represented. The Australian Competition and Consumer Commission publishes the detail, and complaints about a trader can be lodged with it or with the consumer affairs or fair trading office in your state or territory.

Practically, the sequence that resolves most of these is: raise it with the vendor in writing and keep the correspondence; if that fails, lodge a complaint with your state or territory consumer affairs office; and where a card was charged, ask your card issuer about a chargeback within their time limits. Keeping the receipt and the original sales page — a saved copy or a screenshot at the time of purchase — makes every one of those steps easier.

Which Australian body handles what

Complaints reach the right place faster when the right body is chosen first. Each of the following links goes to the organisation's own site, and the descriptions are of their published roles.

Australian bodies relevant to security, scams and consumer complaints
BodyDeals with
ScamwatchReporting scams and reading descriptions of current scam types; operated by the National Anti-Scam Centre.
Australian Cyber Security CentreGuidance on protecting devices and accounts, and reporting cyber incidents such as ransomware or account compromise.
ACCCConsumer protection and competition, including material on consumer guarantees and misleading conduct.
OAICPrivacy complaints under the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Notifiable Data Breaches scheme.
eSafety CommissionerOnline safety, including cyberbullying of children, adult cyber abuse and image-based abuse.

When a company loses your data

Where an organisation covered by the Privacy Act suffers a data breach that is likely to result in serious harm, the Notifiable Data Breaches scheme requires it to notify affected individuals and the Information Commissioner. The practical consequence for a reader is that notification should come to you, and that the OAIC is where a privacy complaint goes if the organisation's own response is unsatisfactory.

The useful response on your side does not depend on which company was breached. Change the password for the affected service, change it anywhere else it was reused, enable two-factor authentication on the email account that can reset the others, and treat messages referring to the breach with particular care, since breach notifications are themselves imitated. There is rarely anything to install and never a reason to grant remote access to someone who contacted you first.

Monitoring installed by someone with access to the device

A category that antivirus products do detect, but that is not usually discussed as malware, is software installed on a device by another person to monitor its user. It is often marketed for family or employee monitoring, and products differ on whether they classify it as spyware or as a potentially unwanted program.

Where this arises in the context of family or domestic violence, removing the software is not always the safest first step, because removal can be noticed. The eSafety Commissioner publishes guidance for people in that situation and provides reporting routes. This is stated here because a page about security software that ignored it would be incomplete, and because the safe sequence is not the technical one.

The one habit underneath all of it

Every pattern on this page works by arriving from outside and creating a reason to act immediately. The single habit that defeats all of them is to stop and re-establish contact through a channel you chose: a number from your own card, an address you typed yourself, an application you opened rather than a link you were sent. Nothing legitimate is damaged by the delay, and every one of these patterns is.