Fake Microsoft‑Branded Security Scans Prompt Victims to Uninstall Antivirus, Enabling Refund Scams
What Happened — A set of fraudulent websites, styled as “SysScan” and using Microsoft branding, present a fake security scan that tells users their third‑party antivirus is “causing serious problems.” The pages then collect personal and banking details and steer victims toward a “refund” phone call where the scammer removes the antivirus and harvests credentials.
Why It Matters for Compliance & Audit Readiness
- The scenario directly tests the effectiveness of SOC 2 Access Controls and Security Awareness Training – controls that must demonstrate that users cannot be tricked into disabling security tools.
- Continuous‑compliance programs need auditable evidence that phishing‑resistance policies are enforced, that training is up‑to‑date, and that incident‑response playbooks cover social‑engineering attempts.
- Verisq’s Security Awareness Training capability provides the evidence‑collection framework to prove that your organization’s training program meets the SOC 2 CC6.1 (Security Awareness) requirement.
Who Is Affected — Consumers and employees across all sectors that use Windows PCs with third‑party antivirus solutions; the attack surface includes any organization that allows personal devices on its network.
Recommended Actions
- Review and reinforce SOC 2 CC6.1 controls: ensure all users receive regular, phishing‑focused security awareness training and that completion is logged.
- Update incident‑response playbooks to include steps for handling fake‑scan encounters, including immediate verification of any request to uninstall security software.
- Deploy web‑filtering or DNS‑blocking rules to block known “SysScan” domains and monitor for similar brand‑spoofing sites. Source: Malwarebytes Labs
Technical Notes
- Attack vector: Phishing‑style website spoofing (brand impersonation).
- Data types at risk: Personal identifiers, banking credentials, remote‑access information.
- Mechanics: The page reads browser‑exposed data (user‑agent, screen size, device memory) and fabricates security findings; no real scan is performed. Source: Malwarebytes Labs