Fake Webroot pop-ups, renewal emails and support scams
A Webroot logo doesn't prove Webroot sent the message. First identify the source, then verify the charge outside the alert. If anyone had remote access or saw online banking, disconnect and treat it as a financial incident.

Do this now: don't call, click or reply. Check the Webroot account and card statement through routes you already trust. If no money, credentials, download or remote session was involved, close the source, remove its browser permission and scan. If a stranger controlled the device or online banking was opened, disconnect it and contact the bank from a different trusted device.
Immediate triage: what you did matters more than what the alert said
A fake Webroot message is designed to make every second feel expensive. The invoice says a charge will be final. The pop-up says data is being stolen. The caller says the bank must be opened now. That pressure is the mechanism, not evidence that the claim is true. Don't call, click or reply while the message controls the route.
If you only saw or opened a message and didn't click, download, reply, call, share data or grant access, the immediate device risk is usually low. Verify the account and statement independently, remove the notification source if necessary and run an updated scan. Receiving a fraudulent invoice doesn't create the charge printed on it.
If you installed a remote tool, watched the pointer move, opened a command window, signed into email or banking, or sent money, stop treating this as a nuisance pop-up. Disconnect the affected computer. Use another trusted device to contact the bank and secure the primary email account. A malware scan can't reverse a transfer or revoke a stolen session. A scan can't reverse a transfer or revoke a stolen session even when its result is clean.
| What happened | First action | Main risk |
|---|---|---|
| Only saw or closed the message | Verify account and statement independently | Future social engineering |
| Allowed site notifications | Remove that exact website permission | Repeated scare alerts |
| Clicked, but entered/downloaded nothing | Close, record URL, update and scan | Phishing redirect or exploit attempt |
| Opened an attachment or download | Stop opening it; preserve name; scan | Malware or credential theft |
| Called, but shared no data/access | Hang up, block and expect follow-ups | Second contact using known details |
| Shared passwords or card data | Secure accounts and contact issuer from clean device | Account takeover and payment fraud |
| Granted remote access or opened banking | Disconnect device and call bank from another device | Device control, persistence and bank fraud |
| Sent money, gift cards, crypto or cash | Contact provider immediately and report | Hard-to-reverse loss and recovery scams |
This page is incident guidance, not a verdict on the product. Our Webroot review covers the antivirus; the scam-protection hub compares tools that can reduce phishing exposure without promising that software can stop every phone script.
Five common routes that borrow the Webroot name
The first route is a browser tab that imitates a system warning. It may flash, play audio, cover the close button or say the device is locked. The page knows ordinary browser details such as operating system family, language or IP region; that doesn't prove it scanned the computer.
The second is a website push notification. At some point, a site was allowed to send alerts. The notification can arrive over the desktop when that site isn't visibly open and can borrow antivirus colors or logos. Current Webroot help says the responsible website appears on the notification, often under “via Chrome,” “Microsoft Edge” or “Firefox.”
The third is a fake renewal invoice in email, text or a calendar event. Its attachment may be a plain PDF or image whose real payload is the phone number. A June 2026 Malwarebytes investigation found invoice campaigns impersonating multiple household brands specifically to push recipients into a support call.
The fourth route is a search result or paid ad for “Webroot support,” refund, cancellation or renewal. Webroot and the FTC both warn that scammers place support pages and ads in search results. High placement is advertising or ranking, not identity verification.
The fifth is an unsolicited call or follow-up from someone who already knows the victim clicked, called or paid. Caller ID can be spoofed. The script may escalate from antivirus support to a bank, government or fraud-department impersonator and demand secrecy, remote access or movement of money to a supposedly safe account.
| Source clue | What it usually means | Safe verification |
|---|---|---|
| Inside installed Webroot Home/status view | Potential genuine product alert | Open Webroot independently from Start/system tray |
| Web Threat Shield block page | Site reputation warning | Leave page; review inside verified extension/app |
| “Via Chrome/Edge/Firefox” plus unfamiliar site | Website notification permission | Remove exact site in browser settings |
| Invoice with urgent phone number | Likely callback/refund scam | Check statement and account without message links |
| Search ad or caller offering unsolicited repair | Unverified support identity | Type official site/account route yourself |
Real Webroot alert, browser push or impersonation?
A genuine installed-product alert has a local context. Webroot’s current Total Protection status guide says green means secure, orange means pending scan actions and red means a shield is disabled. The user reviews the problem inside the installed Webroot interface or its system-tray Home view.
A genuine Web Threat Shield block page is also documented. It offers a safe exit, more classification detail, a review request and—only for a site the user knows—an unblock choice. The documented workflow doesn't tell the reader to call a number, buy gift cards or let a stranger operate the PC.
A website notification identifies the browser and sending site. It may use the Webroot name, but it's still browser-delivered content. Don't disable Webroot to stop it. Remove the unfamiliar site’s permission and check browser extensions instead.
The FTC’s strongest discriminator is blunt: real security warnings don't ask the user to call a phone number. Webroot likewise says to ignore a support pop-up’s number and links. A logo, HTTPS padlock, caller-ID name or accurate device detail can't rescue that red flag.
Not every strange local Webroot dialog is a scam. Current community reports include users seeing repeated or blank product event dialogs. Treat an odd dialog as a product fault when it originates in the installed app and doesn't demand off-app payment or remote contact; capture it and use the Webroot troubleshooting guide or verified support.
Verify a Webroot renewal or invoice without touching the message
Real renewal notices exist. Webroot’s auto-renewal documentation says direct customers receive notices 30 and 14 days before expiration at the email used for the original purchase. It says renewal uses the standard renewal price plus applicable tax.
That means “renewal” and “Webroot” in the same email prove nothing by themselves. A fake message can copy those details, and a legitimate purchase can be billed by a reseller rather than Webroot. Verification needs three independent records: the seller on the original receipt, the subscription shown in the account and an actual pending or posted transaction. The Webroot account and keycode guide separates current and legacy account routes without exposing the keycode to a caller.
Don't press the email’s sign-in or cancel button. Type account.webroot.com yourself or use the original reseller account. Open the bank/card app from its known icon or bookmark. If no matching transaction exists, the FTC says that supports treating the claimed charge as fake. If a transaction exists, contact the issuer through the card, app or known statement details—not the invoice.
A sender display name is weak evidence. Email From fields and lookalike domains can deceive, and a compromised legitimate mailbox can send real-looking fraud. Grammar is also weak now. Account, order history and statement evidence matter more than a polished logo or a familiar signature.
Use our Webroot pricing and renewal guide to identify the expected seller and amount. If cancellation or a real charge is the issue, follow the verified Webroot cancellation and refund route rather than calling the message.
How to close a locked browser pop-up without pressing its buttons
Try the ordinary browser tab or window close control first. Don't press a page button labelled Scan, Remove, Continue, Call, Cancel renewal or X when the X is drawn inside the webpage. A website can style any graphic as a close button and route it elsewhere.
If the page traps focus or repeatedly reopens on Windows, press Ctrl+Shift+Esc, select the browser in Task Manager and end the task. Webroot’s browser-pop-up guidance recommends restarting and declining to restore the previous session. That avoids loading the same tab again.
After the browser opens cleanly, review notification, pop-up/redirect and extension permissions. Clear site data for the suspicious origin if known. Resetting the entire browser can be useful when homepage, search and extensions keep changing, but it's broader than necessary for one revoked notification and may affect custom settings.
Update Windows and the browser, then run Webroot from its verified local icon. If the tab was merely a webpage and nothing was downloaded or executed, a clean scan plus stable settings is reassuring. If unknown software installed, redirects persist outside one browser or security controls turn off, continue to the deeper scan/rebuild section.
Remove the website permission behind repeated antivirus-looking notifications
Webroot’s current browser-notification guide says the sending website is listed on the alert itself. The notification gear can open settings where that site is blocked or removed. Dismissing one alert stops only that instance.
In Chrome, open Settings → Privacy and security → Site Settings → Notifications. Google’s current notification instructions let users remove or block individual sites and enable quieter prompts. Edge and Firefox have equivalent permission lists; Webroot’s guide links their current paths.
Review the list rather than blocking every notification blindly. Calendar, mail and work apps may have legitimate permissions. Remove unfamiliar domains, especially those granted moments before the alerts began. Then inspect installed extensions and pop-up/redirect permissions.
Google’s unwanted-software checklist escalates concern when tabs won't go away, homepage or search changes, extensions return, browsing redirects or virus alerts persist. One site permission is a browser cleanup; persistent unauthorized changes deserve a scan and possibly a browser reset.
Fake invoice email, PDF or calendar event: the phone call may be the payload
An invoice attachment isn't harmless merely because it's a PDF, but it isn't automatically malware either. Many callback scams put the number inside an image or PDF because the decisive manipulation happens on the phone. Don't open it again, enable content, scan a QR code or call to “cancel.”
If you only previewed the email and took no other action, verify the alleged charge, report the message as phishing and delete it. Opening a normal message isn't evidence that the PC is infected. The important branches are whether a link or attachment executed, credentials were entered, a number was called or a remote tool was installed.
A calendar invite can show an alarming “Webroot renewal” event even when the user never created it. Current 2026 community reports show this delivery route. Delete or report the unsolicited event without using its details, then review calendar-sharing and automatic-event settings so unknown invitations don't become trusted reminders.
Preserve the original message when money, credentials or remote access are involved. Keep headers, attachment name, timestamp and screenshots. Forwarding screenshots to friends is safer than forwarding a live attachment, and public posts should redact names, account fragments, barcodes, addresses and report numbers.
Search ads and “official support” numbers aren't identity proof
Webroot’s tech-support scam warning says fraudulent Webroot support sites and phone numbers exist and may appear through search advertising. The FTC describes the same path: scammers optimize pages or buy ads so a worried user calls them.
Don't solve one suspicious number by searching for a different number and calling the first result. Type the known official domain, use the account’s support link or start from the product’s local Help area. The current Webroot support hub routes account, product and reseller cases without requiring trust in an ad.
Lookalike sites may use HTTPS. The padlock says the browser connection to that domain is encrypted; it doesn't say the domain belongs to Webroot. Slight misspellings, extra support words, unrelated domains, aggressive chat and immediate remote-access requests are strong warning signs.
Legitimate technology companies don't make surprise calls to report a computer problem. Webroot and the FBI tech-support guidance say to hang up. Caller ID can be forged, and a caller who knows the victim owns Webroot may have learned it from an earlier leak, purchase list or the victim’s own response.
Eight-step response to a fake Webroot alert or support contact
The sequence changes from browser cleanup to incident containment as soon as remote control, credentials, banking or payment enters the story. Complete the relevant steps in order and use a different trusted device for financial and password work when the computer may have been controlled.
Stop contact and use none of the supplied details
Don't call the number, reply, click a link, scan a QR code or open the attachment. End an existing call and ignore instructions to keep the incident secret, move money or leave a remote-support window open.
Identify where the alert actually came from
Check whether it's inside the installed Webroot app, a Web Threat Shield block page, a browser tab, a website notification marked via Chrome, Edge or Firefox, an email, a text or a calendar event. Record the visible source without interacting with it.
Verify the subscription and charge independently
Type the known Webroot account address yourself or open the original reseller account. Check the card or bank statement through its normal app or bookmarked route. Don't use a message link, reply address or search-ad phone number.
Close the alert and remove the exact site permission
Close the tab normally or end the browser task if it's trapped, then restart without restoring the session. In browser Site Settings, remove the unfamiliar website listed as the notification sender and review unknown extensions.
Disconnect a device that was remotely controlled
If software was installed, a stranger moved the pointer, commands ran or online banking opened, disconnect Wi-Fi or Ethernet and stop using that device for passwords or payments. Don't let the caller reconnect for a supposed refund.
Secure financial and identity accounts from a clean device
Contact the bank or payment provider through a known number or app, disclose remote access and follow its fraud process. Change exposed and reused passwords, revoke sessions, enable MFA and protect the primary email account first.
Preserve evidence, update and scan safely
Keep the original email, attachment name, transaction record, call time, remote-tool name and screenshots. Update Windows, the browser and verified security software, then run supported scans; use a professional clean rebuild when device trust can't be restored.
Report the scam and monitor for a second approach
Report relevant details to the FTC and IC3, and send the impersonation evidence to verified Webroot support if useful. Watch statements, email rules, recovery methods and credit reports; reject anyone promising guaranteed recovery for an upfront fee.

Don't let the scammer remain on the call while you “verify” with the bank. A sophisticated script may coach the victim to distrust real bank staff, move funds, buy gold or cash, or lie about the purpose. End the communication and start each trusted contact independently.
After remote access: assume the session saw more than the screen
Disconnect Wi-Fi and Ethernet if a stranger controlled the computer, installed a tool, ran commands or changed settings. Don't reconnect because the caller promises to uninstall the software or finish a refund. Don't use the same computer to change passwords or contact the bank.
From another trusted device, contact financial institutions and explain that an unknown party had remote computer access. Preserve the remote tool name, installer, session code, call time, caller details and visible commands. Don't publish the session code or let a second “helper” reuse it.
Remote-control software can be legitimate, so an antivirus may not classify it as malware. The absence of a detection doesn't prove the session was safe. Check installed applications, startup items, browser extensions, new user accounts and remote-access services with a trusted technician; remove unauthorized tools only after preserving evidence.
If the scammer had administrator rights, security software was disabled, commands ran or the scope is unclear, a clean operating-system reinstall from known-good media is the stronger trust decision. Back up documents cautiously, not unknown executables or scripts. The Webroot installation guide belongs after the operating system is trustworthy again.
The FBI says victims should run current security software and consider professional cleaning. It also warns that scammers often share victim information. Expect another call claiming to be Webroot, a bank, law enforcement or a recovery service.
If online banking was opened during the remote session
Call the bank’s fraud team from the number on a physical card, known statement or official app on a clean device. State clearly that a scammer had remote access while banking was open. Ask about active sessions, pending transfers, new payees, contact-detail changes and the bank’s device-compromise process.
Don't trust the visible balance that appeared during the session. Refund scammers can alter webpage display, move money between the victim’s own accounts or hide transactions to create a fake overpayment. The FTC documents this script: the scammer claims to refund too much and demands repayment using hard-to-reverse methods.
Follow the bank’s instructions about freezing cards or accounts, replacing credentials and filing an affidavit. Check every account reachable through the same email, phone number or password. A bank login saved in the browser may expose more than the account shown on screen.
Don't move money to a “safe” account supplied by a caller, and don't withdraw cash, buy gold or ship currency. A genuine bank or government investigator doesn't require secrecy or payment to protect funds. If a transfer is pending, speed matters; call before spending time on a full antivirus scan.
Passwords, card details and identity documents need their own recovery
Secure the primary email account first from a clean device. Change the password to a unique one, sign out other sessions, review recovery email/phone, remove unknown forwarding rules and enable phishing-resistant MFA or the strongest available method. Email controls most password resets.
Change any password typed or stored during the session and every reused copy. Revoke sessions and app passwords rather than assuming a password change alone invalidates them. Review account activity for new devices, OAuth grants, recovery methods and mailbox rules.
Contact the card issuer when card number, expiry or security code was shared, even if no charge appears yet. A replacement number may be appropriate. For Social Security or identity-document exposure, follow the relevant national identity-theft process and consider credit freezes or fraud alerts.
Webroot identity monitoring can alert on some downstream signals, but it can't retrieve a disclosed password or prevent every new-account attempt. Our Webroot identity-protection guide explains the monitoring boundary. Account hardening and financial action come first.
Payment recovery depends on the method—and speed
For a credit or debit card, contact the issuer immediately, identify the transaction as fraud or a scam-induced payment and follow its dispute process. Don't call a number from the invoice. A chargeback isn't guaranteed, but delay weakens options.
For a bank or wire transfer, call the bank’s fraud department and ask whether the transfer can be recalled or frozen. For a payment app, use its official fraud route. For a gift card, contact the card issuer with the card and receipt; never send another code to someone promising to unlock the first.
Cryptocurrency and cash are difficult to recover, but report the wallet, transaction hash, exchange account or shipping details promptly. Contact the legitimate exchange involved and law enforcement. Never pay a tracing or recovery service that guarantees return of funds for an upfront fee.
The 2025 FBI IC3 annual report recorded 47,794 tech-support complaints and about $2.135 billion in reported losses. Those figures cover reported tech-support fraud, not all incidents and not Webroot specifically. They show why payment containment outranks cosmetic browser cleanup after money moves.
When a scan is enough—and when a clean reinstall is safer
If the event was only a browser notification or closed webpage, remove the permission, update Windows/browser/Webroot and run a scan. Confirm the browser homepage, search, extensions and downloads are normal. A second-opinion on-demand scan can be reasonable when no competing real-time engine is forced on.
If an attachment or installer ran, use Webroot’s current scan and quarantine workflow, record detections and avoid restoring unknown files. The Webroot scans and quarantine guide explains scan boundaries. A clean result is evidence, not proof that credentials or sessions remained private.
Escalate toward professional cleaning or a known-good reinstall when a scammer had administrator access, security services were disabled, new accounts appeared, remote tools return, browsers remain hijacked or commands/scripts ran. Preserve personal documents cautiously and reinstall applications from verified publishers.
Don't clone the entire compromised installation back onto a clean PC. Don't restore unknown executables, cracked software, startup scripts or browser profiles without review. After rebuild, update the OS fully, install Webroot from the verified account and change exposed passwords from a trusted device.
Preserve evidence, report once, then expect recovery scammers
Keep the original email and headers, attachment filename, screenshots, caller number as displayed, call times, remote-tool name, payment receipts, wallet or transaction IDs and the address or account that received funds. Don't edit the originals. Redact sensitive details from any public post.
Report U.S. consumer fraud at ReportFraud.ftc.gov and internet-enabled crime at IC3.gov. Contact the financial institution separately; an FTC or IC3 report doesn't freeze a transaction. Use verified Webroot support for an impersonating site or account question.
Current community reports are useful for recognizing patterns—calendar invitations, callback invoices and expensive supposed long-term support—but they don't identify every sender or prove a specific product dialog is fake. Don't post live malicious links or ask strangers in private messages to recover money.
The next approach may claim to be the bank, police, Webroot, the FTC or a recovery specialist who found the stolen funds. The FBI says victim details may be shared. A request for an upfront fee, remote access, gift card, cryptocurrency, secrecy or movement to a “safe” account is another scam.
Tell a trusted person what happened. Scammers isolate victims and exploit embarrassment. A second person can help review transactions, document contacts and resist a caller’s urgency without judging the initial mistake.
Fake Webroot pop-up, email and support scam FAQ
Is a Webroot pop-up with a phone number real?
Treat it as fraudulent. The FTC says real security warnings don't ask users to call a phone number, and Webroot says not to call or click numbers inside urgent support pop-ups. Verify through the installed app or typed official support route.
Does seeing a fake Webroot alert mean my computer is infected?
No. It may be a browser tab or a website notification permission. Infection becomes more plausible when settings change, extensions return, downloads run, security tools stop or a stranger had remote control. Close the source, remove permission and scan.
Can a legitimate Webroot renewal email arrive before expiration?
Yes. Webroot says direct auto-renew customers receive notices 30 and 14 days before expiration. Verify the plan, seller and charge in the account and statement you open independently; a renewal theme alone neither proves nor disproves fraud.
I opened the email but clicked nothing. Am I infected?
Usually the meaningful risk begins with a link, attachment, QR code, credential entry, download or call. Preserve and delete the message after verification, update the mail app and browser, and investigate further only if another action or suspicious device behavior occurred.
How do I stop Webroot-looking notifications from Chrome?
Open Chrome Settings, then Privacy and security, Site Settings and Notifications. Find the unfamiliar site shown on the notification and block or remove it. Also review extensions and pop-up/redirect permissions; don't disable genuine Webroot protection to silence a website.
What if the pop-up won't close?
Don't click its buttons. On Windows, use Ctrl+Shift+Esc to open Task Manager and end the browser, then restart it without restoring the previous session. Remove the site permission, inspect extensions and run an updated scan.
What should I do after giving a scammer remote access?
Disconnect that device, contact financial institutions from another trusted device, secure email and financial accounts, preserve the remote-tool and session evidence, and arrange a professional clean or reinstall if administrative control or banking access was exposed.
Can Webroot remove remote-access scam damage?
A scan can find some malware or unwanted tools, but it can't revoke stolen passwords, reverse payments or prove that an administrator-level session made no persistent changes. Account recovery, bank action and sometimes a clean operating-system rebuild are separate jobs.
Can I get money back after a fake Webroot support payment?
Contact the payment provider immediately. Card issuers, banks, wire services and gift-card issuers have different fraud processes and timing matters. Cryptocurrency and cash are harder to recover. Ignore anyone demanding another fee to guarantee recovery.
Where should a Webroot impersonation scam be reported?
Use ReportFraud.ftc.gov for the FTC and IC3.gov for internet-enabled crime, and preserve the report numbers. Contact verified Webroot support through its official site for brand impersonation or account questions, and notify the bank or payment provider separately.
Bottom line: verify outside the message, then respond to the action taken
A real Webroot alert can be checked inside the installed app. A browser notification names its sending website. A claimed renewal can be checked in the independently opened account and bank statement. None of those checks requires the phone number, link or reply address supplied by the suspicious message.
If the incident stopped at a notification, remove its permission and scan. If it reached credentials, banking, remote control or payment, disconnect the device and secure the financial and identity layers from somewhere clean. Scanning matters, but it can't undo social engineering.
Keep evidence, report through official routes and be ready for a second scammer who claims to recover the loss. The safest support channel is the one you reach independently—not the one that created the panic.