Messages, calls and payment requests
Six questions about the texts, emails and phone calls that arrive uninvited, how to judge them calmly, and what the Australian reporting routes are.
The short version for this whole page
Receiving these messages is not a sign that anything is wrong with your device. They are sent in bulk to numbers and addresses obtained elsewhere. The reliable test is not whether a message looks convincing — many do — but whether you can confirm it through a channel you chose yourself.
How can I tell whether a message is genuine?
Stop using the message as evidence about itself, and confirm through a route you already trust. Appearance is no longer a useful signal.
Why the old advice has aged badly. Spelling mistakes and clumsy layout used to be giveaways. Current messages are frequently well written, correctly branded and sent from addresses that pass a casual inspection. Caller identification can be set to display a name. So the question "does this look real?" has stopped being informative, and the question "can I confirm this independently?" has replaced it.
What to do instead, at no cost.
- Do not use any contact detail in the message. Not the link, not the phone number, not the reply address.
- Open the organisation's app, or type its address into your browser yourself, and look for the same notice there. A genuine account problem will be visible when you sign in normally.
- If there is no app, telephone the number on your card, your statement, or the organisation's published contact page.
- Notice what is being asked for. Requests for a code sent to your phone, for remote access to your computer, for payment in gift cards or cryptocurrency, or for secrecy, are the strongest signals available.
- Allow yourself the delay. Urgency is the mechanism, and nothing legitimate collapses because you checked for ten minutes.
When to ask for official help. Scamwatch at scamwatch.gov.au publishes descriptions of the scam types currently circulating in Australia, which is useful when you want to know whether something matches a known pattern. Many banks and government agencies also publish pages stating what they will never ask for.
Where a paid product may or may not help. Some products filter known scam addresses and block known numbers, which reduces volume without being a substitute for checking. No product can tell you whether a particular message about your account is true, because that is a question about your account rather than about the message.
Why do I get so many parcel and toll messages?
Because sending them is nearly free and the scenario is plausible for almost anyone. Nothing about your phone invited them.
Likely causes of the volume. Numbers are sent in bulk, often sequentially, so a message arrives whether or not you ordered anything. Delivery, toll and small-refund scenarios work because the amounts named are small enough not to trigger much thought and because many people are genuinely expecting a parcel. Delivery and toll themes are among the categories Scamwatch reports on regularly.
What to do first, at no cost. Do not reply, even to object; a reply confirms the number is live. Use the report-junk or block-sender option in your messaging app. In Australia, scam text messages can be forwarded to the number 7226 (which spells SCAM), a free service operated for reporting them. Then delete the message. If you are genuinely expecting a delivery, check the tracking number in the carrier's own app or site.
When to ask for official help. Report through scamwatch.gov.au if you want the message recorded, and contact your telecommunications provider, which may offer additional blocking for your service.
Where a paid product may or may not help. Message-filtering features in some security apps reduce how many of these you see. Both iOS and Android already include filtering for messages from unknown senders at no cost, which is worth switching on before paying for anything.
Someone phoned saying my computer has a problem. Is that ever real?
No. Software companies and telecommunications providers do not telephone individuals because a computer reported a fault. There is no mechanism by which an unsolicited caller would know.
How the call works. The caller names a well-known company, says errors have been detected, and asks you to open a particular screen on your computer. They then interpret ordinary entries — routine log messages that exist on every machine — as evidence of infection. The objective is to get remote-access software installed, after which they ask for payment for a fix, or move to the banking screen. The same script also appears as a pop-up giving a support number to call, which produces the identical conversation with you making the call.
What to do, at no cost. Hang up. You do not need a reason and you are not being rude. If a browser page is displaying a warning and a number, close the tab; if it will not close, close the browser entirely, or restart the computer. Never install remote-access software at the request of someone who telephoned you.
When to ask for official help. Report the call to scamwatch.gov.au. The Australian Cyber Security Centre at cyber.gov.au publishes guidance on this category of approach. If the caller claimed to be from a specific company, that company's own site will usually state plainly that it does not make such calls.
Where a paid product may or may not help. A product cannot intervene in a telephone conversation, and it will not stop you from granting access if you are persuaded to. If the pop-up version is appearing repeatedly in your browser, the browser-side steps on the slow computer page are the relevant remedy.
I let someone connect to my computer remotely. What now?
Disconnect, then treat passwords and bank access as the priority. Act in order rather than quickly.
What to do, at no cost.
- Disconnect from the internet: turn off wi-fi or unplug the cable. This ends the session immediately.
- Telephone your bank on the number on your card. Tell them someone had remote access. Do this before anything else if banking was open during the call.
- From a different device, change the password on your email account first, then on banking, then on anything else used on that computer.
- Uninstall the remote-access program they asked you to install. Note its name first, in case you need to describe it.
- Reconnect, install all pending updates, and run a scan.
- Consider reinstalling the operating system. Where someone had hands-on control, this is the option that removes the uncertainty — the steps are on the clicked-a-link page.
- Report it through ReportCyber at cyber.gov.au and to scamwatch.gov.au.
When to ask for official help. If money left an account, the bank is the first call and the time between the transfer and the report matters. If the computer is used for a business holding other people's personal information, obligations under the Privacy Act may apply; the OAIC explains the Notifiable Data Breaches scheme at oaic.gov.au.
Where a paid product may or may not help. A scan is a sensible part of step five and the protection already on your system can run one. Where someone had interactive control of the machine, a scan is not a guarantee, which is why step six exists.
Where do I report it, and is reporting worth the time?
Scamwatch for scams, ReportCyber for cybercrime, eSafety for harmful content, the OAIC for mishandled personal information. It takes a few minutes and it is worth doing.
| Organisation | What it is | Typical reason to go there |
|---|---|---|
| Scamwatch | Run by the National Anti-Scam Centre at the ACCC | Any scam message, call or website, with or without a loss |
| ACSC / ReportCyber | Part of the Australian Signals Directorate | Cybercrime reports, and published security guidance |
| eSafety Commissioner | Australia's online safety regulator | Seriously harmful content, cyberbullying, image-based abuse |
| OAIC | The national privacy regulator | An organisation has mishandled or lost your personal information |
| ACCC | Competition and consumer regulator | Misleading conduct by a business selling to Australians |
| Your bank | Your own financial institution | Any situation involving money, cards or account access |
On whether it is worth it. You will usually not receive an individual response, and that is a fair reason to feel the effort is wasted. The purpose is different: reports let these bodies see which campaigns are running now, which is how public warnings get published while they are still relevant. A few minutes contributes to that.
Can I stop the messages arriving at all?
You can reduce them substantially; you cannot stop them entirely. Blocking works per sender, and senders change.
What helps, at no cost. Switch on the filtering for unknown senders built into your phone's messaging app. Use the report-junk option rather than only deleting, because reporting feeds the carrier's filters. Register your number on the Do Not Call Register, which stops legitimate telemarketing and makes the remaining calls easier to recognise, while noting that it has no effect on callers who are already breaking the law. Use the mail provider's own report-phishing button on scam emails rather than simply deleting them. Avoid giving your mobile number where an email address will do.
What to expect. Volume usually falls over weeks rather than immediately, and it fluctuates. A quiet month followed by a busy one is normal and does not mean something has changed on your device.
When to ask for official help. Your telecommunications provider can advise on blocking available for your service. Persistent targeted contact from a known individual is a different matter and may be a police issue; the eSafety Commissioner at esafety.gov.au publishes guidance on online abuse.
Where a paid product may or may not help. Call and message filtering is the mobile feature in this category most likely to earn its cost, because it is the one addressing the thing that actually bothers people. Try the free filters built into your phone first and see what is left over.
What to watch out for
- Anyone asking for a verification code sent to your phone. Those codes exist precisely so that nobody else has them, and no legitimate staff member needs one.
- Payment by gift card, cryptocurrency or bank transfer to a personal account. These are chosen because they are difficult to reverse.
- An offer to recover money you already lost, for a fee. Scamwatch describes follow-up contact of this kind.
- Any instruction to keep the conversation to yourself. Checking with someone is exactly what the request is designed to prevent.
Where a paid product sits in all of this
Most of this page is about judgement and reporting, and software is a small part of it. The genuinely useful software features here are web-address filtering and call and message screening. Norton AntiVirus Plus is a paid antivirus product; what any particular licence includes is stated on the vendor's own site, which is the accurate source for it.
The following is a paid affiliate link. The publisher of this site is paid a commission on sign-ups through it, at no extra cost to you.
Visit the Norton AntiVirus Plus website to read what the vendor says is included.