Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Microsoft‑Branded Security Scans Prompt Victims to Uninstall Antivirus, Enabling Refund Scams

Fraudulent sites posing as Microsoft‑branded security scanners tell users to uninstall their antivirus, then harvest personal and banking data. The episode highlights gaps in SOC 2 access‑control and security‑awareness controls, underscoring the need for verifiable training evidence.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

Fake Microsoft‑Branded Security Scans Prompt Victims to Uninstall Antivirus, Enabling Refund Scams

What Happened — A set of fraudulent websites, styled as “SysScan” and using Microsoft branding, present a fake security scan that tells users their third‑party antivirus is “causing serious problems.” The pages then collect personal and banking details and steer victims toward a “refund” phone call where the scammer removes the antivirus and harvests credentials.

Why It Matters for Compliance & Audit Readiness

  • The scenario directly tests the effectiveness of SOC 2 Access Controls and Security Awareness Training – controls that must demonstrate that users cannot be tricked into disabling security tools.
  • Continuous‑compliance programs need auditable evidence that phishing‑resistance policies are enforced, that training is up‑to‑date, and that incident‑response playbooks cover social‑engineering attempts.
  • Verisq’s Security Awareness Training capability provides the evidence‑collection framework to prove that your organization’s training program meets the SOC 2 CC6.1 (Security Awareness) requirement.

Who Is Affected — Consumers and employees across all sectors that use Windows PCs with third‑party antivirus solutions; the attack surface includes any organization that allows personal devices on its network.

Recommended Actions

  • Review and reinforce SOC 2 CC6.1 controls: ensure all users receive regular, phishing‑focused security awareness training and that completion is logged.
  • Update incident‑response playbooks to include steps for handling fake‑scan encounters, including immediate verification of any request to uninstall security software.
  • Deploy web‑filtering or DNS‑blocking rules to block known “SysScan” domains and monitor for similar brand‑spoofing sites. Source: Malwarebytes Labs

Technical Notes

  • Attack vector: Phishing‑style website spoofing (brand impersonation).
  • Data types at risk: Personal identifiers, banking credentials, remote‑access information.
  • Mechanics: The page reads browser‑exposed data (user‑agent, screen size, device memory) and fabricates security findings; no real scan is performed. Source: Malwarebytes Labs
📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →