We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Fake Sophos alert and support-scam recovery · current Sophos Home, browser-vendor, Microsoft and FTC guidance checked August 5, 2026

Remove Fake Sophos Pop-Ups and Support Scams Safely

Do not call the number, click “scan” or install the offered tool. Close the alarming page, check whether Sophos Home recorded a real event, then match the cleanup to what actually happened: seeing a notification is not the same incident as granting remote access or paying.

No pop-up phone numbersVerify through HistoryPermission before resetRecovery by exposure

Two-minute response: do not click inside the warning or call its number. Close the browser with its normal window control; on Windows, Microsoft suggests `Alt+F4` when a scareware page blocks mouse controls, followed by a restart if the browser still will not close. Open browser notification settings independently and block the sending site, then open Sophos Home from the operating system and check the Home dashboard History. If you installed a tool, shared data, granted remote access or paid, skip to the matching recovery branch because browser-permission cleanup alone is no longer enough.

Your first response should reduce risk, not prove the warning wrong

Do not interact with the page to “see what it detects,” and do not call the number it displays. Fake support sites can make every button—including a close-looking button inside the page—open another tab, start a download or hand you to a phone scam. Use the real browser window control or the keyboard route described below. Do not revisit the URL to capture a better screenshot and do not search the displayed phone number, because scam domains and numbers change quickly and search results can contain more impersonation.

After the page is closed, record what you remember: browser, visible sending domain, wording, time, whether audio/full-screen mode appeared and whether you clicked, downloaded, installed, shared information, allowed remote control or paid. That exposure list decides the recovery. Merely seeing a web page does not establish infection, but a fake page also cannot certify that the device is clean. The safe test is an independent browser-permission review plus the real Sophos application and dashboard.

If the local Sophos shield is red, the device is overheating, a new program continues to open the page outside the browser, or remote control is still active, disconnect the device from networks used for sensitive work. Use another trusted device for banking and account recovery. Our Sophos Home troubleshooting guide owns genuine product faults, while the main Sophos Home review explains the actual product and support model; this page owns impersonation and the changes it may leave behind.

A logo is not evidence that the alert came from Sophos

A web page can display a copied shield, product name, animated “scan” and fake threat count without reading the device. Treat location and evidence as more reliable than design. The FTC's current tech-support scam guidance states that real security pop-up warnings do not ask the user to call a phone number. Urgency, gift cards, cryptocurrency, a remote-control download or a promise to refund a subscription are decisive scam signals.

Sophos Home's current detection-review article says a malware detection produces a notification in the installed antivirus and a dashboard notification. Open the local app through Start, Applications or the known Sophos shield—not the warning—and reach the Home dashboard through your own bookmark or by navigating directly to Sophos Home. A matching device, time, detection name and path are evidence. A page telling you what it “found” before you ran anything is not.

A missing Home event does not prove that no browser hijacker or unwanted app exists. Sophos says it can block categorized PUAs and malicious sites but cannot necessarily reverse settings already changed with the user's permission. That is why the identification route checks both the alert channel and the browser/device state rather than choosing between “nothing happened” and “everything is infected.”

Identify where the message appeared before cleaning it

Expand the message only through the operating system's notification center when that can be done without opening its link. Look for the sending website or browser name, then compare it with the independent Sophos record. The five channels below can look similar while requiring different actions.

ChannelUseful evidenceFirst action
Real Sophos detectionLocal Sophos notification plus matching Home History entryOpen Sophos independently and manage the recorded detection
Website notificationBrowser/site source in Notification Center; can arrive in backgroundBlock that site's notification permission
Web-page scarewareAlert lives inside a tab, may use full screen, audio or looping dialogsClose the browser without clicking the page
Legitimate Mac Welcome promptInstalled Sophos, Full Disk Access/setup context, no support phoneVerify through System Settings and current Sophos instructions
Installed PUA or hijackerRedirects, changed search/homepage, extension/app/startup persistenceRemove permission, then review browser, apps, startup and scan

If a notification impersonates another antivirus that is not installed, its branding is another clue. Sophos explicitly routes that situation to its Browser Hijackers guide. Do not install the named antivirus merely to make the warning “match,” and do not allow a PUA because the fake page claims it is a required Sophos component.

Use the 90-day Home History as the Sophos source of truth

The current Sophos Home History documentation says each device retains Home activity for 90 days. Filters separate Threats, Websites, Other scan activity and Quarantine. Entries age out automatically and cannot be manually deleted, which makes History more useful than the appearance of a single pop-up.

Select the correct computer and compare the alert time. A real website block should appear under the relevant website activity; a file/PUA detection should have a name, path or action under threat/quarantine views. If the device is missing or recent History is absent, confirm it was installed under the same Home account. Our dashboard, account and device guide covers wrong-account and disconnected-device cases.

Do not click Allow or Ignore merely to clear a frightening entry. A real Sophos detection has its own decision path, and a false positive should be submitted through the official sample route. Save the detection name and path, then use our scan, quarantine and PUA guide. The goal is to manage the recorded item, not to make every badge disappear.

The Mac “Welcome to Sophos Home” prompt can be legitimate

Sophos's current Welcome popup article documents a real macOS screen that asks the user to complete Full Disk Access after installation or an OS upgrade. If required components are missing, it can return on reboot or when a scan starts, and the menu-bar shield may say the computer is at risk. Current Known Issues also says outdated Sonoma can make the Welcome screen repeat.

Verify the context without following a web-page link: Sophos Home is installed, the prompt leads to macOS System Settings → Privacy & Security → Full Disk Access, and the components come from `/Library/Sophos Anti-Virus`. Sophos currently lists Sophos Diagnostic Utility, SophosScanAgent, SophosCleanD, SophosServiceManager and SophosUpdater among components that may need access. Update macOS, use the current official sequence and restart.

A browser page that borrows “Welcome to Sophos,” offers a phone number, asks for payment, installs a profile or tells you to download a remote-control tool is not that workflow. Close it and use the browser branch. The Sophos Home for Mac review explains the legitimate permission burden, while our install guide gives the complete supported setup sequence.

The real “Third Party Antivirus” warning names an installed product or leftovers

Sophos's July 2026 third-party antivirus article documents a legitimate Home message: running two resident security programs can reduce security and the user should uninstall the named product or its leftovers. The article excludes Windows Defender because it adapts to another registered provider. Manage that message through the local Home app and the operating system's installed-program list.

The same Sophos article makes the impersonation distinction explicit: if pop-ups claim to come from an antivirus that is not installed, use the Browser Hijackers removal process. Do not follow the fake alert's uninstall or purchase button. First confirm installed products and Windows Security provider state, then remove an actual old suite with its vendor's supported uninstaller. A browser notification needs a site-permission fix instead.

A website notification is not the same as a pop-up tab

A website notification is delivered through a permission you granted to a site, often after a deceptive “click Allow to continue” prompt. It can appear in the corner or Notification Center while the original tab is gone. Microsoft says Edge site notifications can appear even when Edge is closed, and Apple says Safari website notifications can arrive even when Safari is not open. That background behavior is why the message feels like an operating-system or antivirus alert.

A web-page pop-up lives in the current tab, a new tab or window. It may expand to full screen, play audio, show a fake scan or loop dialogs. Blocking pop-up windows and revoking notification permission are separate settings. Clearing cookies/history is also separate. The useful evidence is the source: website listed in the notification, current tab address, or a persistent extension/application that creates new redirects.

BrowserCurrent official settings routeWhat to change
ChromePrivacy and security → Site Settings → NotificationsRemove or block the suspicious sender
EdgePrivacy, search, and services → Site permissions → All sitesSet that site's Notifications permission to Block
FirefoxPrivacy & Security → Permissions → Notifications → SettingsRemove the website or set its status to Block, then save
SafariSafari Settings → Websites → NotificationsDeny the sender; optionally stop new permission requests

Sophos's current Browser Hijackers guide puts notification revocation first and browser reset later when symptoms persist. Follow that order. Resetting every browser before saving the sender, extension and download evidence can make the cause harder to identify and may not stop synced settings from returning.

Close a full-screen or looping scareware page without using its buttons

Microsoft describes fake support pages that enter full-screen mode, play audio, loop pop-ups and imitate Windows errors. Do not use an “X” drawn inside the page or call the number to ask how to unlock it. Try the real browser window control. On Windows, Microsoft's current scam guidance recommends `Alt+F4` when the mouse cannot close the browser; restart the computer if it still cannot be closed.

After restarting, do not restore all prior tabs automatically. If the browser offers a session-restore button, leave it alone until the notification permission, startup pages and extensions have been reviewed. Disconnecting the internet can stop a page from loading more content, but it does not remove a granted notification permission or installed tool. Complete the appropriate cleanup while the device is under your control.

On a Mac, use the normal browser/application quit route; if the application is genuinely unresponsive, use Apple's standard Force Quit interface rather than clicking the page. Preserve only safe evidence such as the time and remembered source. Do not reopen the malicious URL for a screenshot, and do not paste it as a live link into a family chat.

Remove the sending site from Chrome notifications

Google's current Chrome notification instructions route through More → Settings → Privacy and security → Site Settings → Notifications. Review sites allowed to send notifications and remove or block the suspicious sender. Chrome can automatically block abusive notifications, but an existing permission still deserves review when the source matches the fake alert.

Do not click the notification to visit the sender and change permission from that page. Use Settings independently. Blocking all new notification requests is optional; calendars, messaging and other trusted sites may rely on them. If the fake alert returns after the sender is removed, review extensions, startup pages, homepage/search and synced browser data rather than repeatedly clearing the cache.

Block the site in Edge and distinguish notifications from pop-ups

Microsoft's current Edge notification guide uses Settings and more → Settings → Privacy, search, and services → Site permissions → All sites, then the website's Notifications control. Choose Block for the suspicious sender. The exact placement can change with Edge releases, so use the linked official page if the labels differ.

Microsoft explicitly distinguishes site notifications from pop-up windows. A notification appears through the notification system and can persist in the background; a pop-up opens in a tab/window. Revoke the site permission for the first and use Edge's pop-up/redirect controls for the second. If Edge shows a work-managed policy, do not remove organizational settings; contact the real administrator through a known channel.

Revoke Firefox Web Push permission and save the change

Mozilla's current Firefox Web Push guide uses Settings → Privacy & Security → Permissions → Notifications → Settings. Select the suspicious website, remove it or set it to Block, then save changes. Firefox says Web Push is opt-in: the site needed permission at some point, even if the prompt was disguised as a CAPTCHA or continue button.

Removing all websites is available but not required for one known sender. The separate option to block new notification requests can reduce future permission traps. If Firefox continues redirecting after permission cleanup, use Mozilla's official Refresh/reset guidance and review extensions. Do not paste old `about:config` tweaks from a forum into a general cleanup; they can disable legitimate features without removing the responsible extension or PUA.

Deny Safari website notifications and inspect Mac notification settings

Apple's current Safari website-notification guide uses Safari → Settings → Websites → Notifications to deny a site and optionally stop websites asking for notification permission. System Settings → Notifications can also disable an individual website's notifications. Removing the sender in Safari is what revokes the website permission rather than merely hiding its banners.

Safari can deliver website notifications even when it is not open, so do not assume the sender is a native Sophos process. After permission cleanup, review Safari extensions, homepage and search settings. If a suspicious configuration profile or unknown login item exists, do not delete everything with a technical-looking name. Match it to the installed application or use Apple's and Sophos's current guidance before removal.

Review extensions, downloads, homepage and search only after permission cleanup

When revoking the sender stops the alerts and no other symptom exists, a full browser reset may be unnecessary. If redirects continue, review extensions installed around the first incident, the Downloads list and folder, startup pages, homepage and default search engine. Disable one unknown extension, record its name and source, restart the browser and retest. Remove it through the browser's supported interface when it is confirmed unwanted.

Do not open a downloaded file to identify it. Save its name, path, time and publisher/signature when available, then scan it through the installed Sophos workflow or submit it using the official sample path. A legitimate extension can also be abused or sold, so “from the browser store” is not a permanent clean verdict. Recent permission changes and unexplained “managed by your organization” policies deserve attention.

Use the browser vendor's current reset function only if settings remain altered. Read what the reset preserves, protect needed bookmarks and do not assume it removes a separately installed Windows/macOS application. Sophos's Browser Hijackers guide links the supported reset pages for Chrome, Firefox, Edge and Safari. It also warns that Mac cases may need advanced steps; keep those tied to the live official article instead of copying Terminal commands into a one-size-fits-all checklist.

Browser sync can bring the unwanted change back

Sophos specifically tells users to review accounts linked to the browser because sync can reinstall an offending app or setting. If the sender or extension returns after removal, check other signed-in devices and the account's extension/settings sync. Pause the relevant sync category, remove the unwanted item on affected devices and verify the clean state before resuming. Do not delete the entire cloud account in panic.

A browser reinstall does not necessarily clear synced data. The clean browser can sign in and immediately restore the same extension, startup page or permission. Document which account was active and whether another device shows the same change. If the browser account password was entered into the fake page, handle it under the shared-data branch from a trusted device before resuming sync.

Remove unknown applications and startup persistence by exact identity

If the incident installed a program or redirects continue outside one browser, review installed applications by date and publisher. Use Windows Settings → Apps or the application's supported uninstaller; on Mac, verify the exact application and its official removal route. Do not delete random files from Program Files, Library or LaunchAgents based only on a suspicious name. That can damage legitimate software while leaving the actual startup entry intact.

Sophos's Browser Hijackers article routes Windows users to Task Manager's Startup area and Mac users to login/startup locations. Record each unknown item before disabling it and test one change. A name that matches a printer, accessibility tool, VPN or backup agent should be verified rather than guessed. Our Sophos Home install guide helps distinguish legitimate Sophos components and correct removal/reinstall paths.

If a remote-control app was deliberately installed for the scam, removing its startup entry is not enough. Uninstall it, revoke unattended-access credentials/tokens inside the remote service when possible and continue with the remote-access recovery section. Preserve the app name and session time for bank/account or law-enforcement reports.

Run Sophos Home and handle a PUA through the real dashboard

After notification permission, browser and application cleanup, update Sophos Home and run the appropriate full scan. Sophos's Browser Hijackers guide recommends a full system scan after related files/apps and browser changes are removed. Do not stack several resident antivirus products for reassurance; they can conflict, and a second opinion should be an intentional separate step.

The current PUA dashboard guide defines Allow, Clean and Ignore. Clean removes the PUA. Ignore clears the alert without excluding or deleting it, so it can return when relaunched. Allow adds the application to PUA exclusions and should be used only when the program is trusted. A recurring file may be restored by an update, backup or cloud sync.

Save the detection name and full path before action. If the program is legitimate but the detection may be wrong, use Sophos's sample/false-positive route rather than a broad exclusion. If the scan is stuck or quarantine is unclear, use our dedicated scan guide. A fake page's threat count has no value in this decision; the real Home event does.

Clicking is not the same as installing, but check what changed

If you clicked a fake button but no file downloaded, no form was submitted and no browser permission was added, close the page, inspect Downloads and recent permissions, then update and scan. A click may only have opened another page. Do not assume identity theft occurred, but do not click again to test the path. Save the new URL as plain text only if needed for an official report.

If a file downloaded but never ran, do not open it. Record and remove it after Sophos scans or classifies it. If you launched an installer, granted administrator rights or added a browser/profile extension, move to application cleanup and the stronger recovery level. Review the exact install time, publisher, new services/login items and browser changes rather than deleting everything created that day.

What happenedMinimum responseEscalate when
Saw onlyClose, revoke sender, review browser, scanRedirects or settings persist
Clicked onlyCheck permissions, downloads and forms; scanA download, login or permission occurred
Downloaded/installedRemove app, update, full scan, inspect persistenceAdmin rights, profiles or remote control were granted
Remote accessDisconnect, remove tool, trusted-device account recoveryUnknown changes or sensitive sessions were visible
Shared dataPasswords, session revocation, MFA/provider recoveryFinancial or identity information was exposed
PaidContact payment provider, dispute, monitor and reportAdditional coercion or account takeover continues
Six-level fake support scam recovery map from seeing an alert to making a payment
Match the recovery to the exposure: merely seeing a page is not the same incident as installing remote access, sharing credentials or paying.

Remote access turns a browser nuisance into a device-trust incident

End the remote session and disconnect the affected computer from the network, especially from work, banking and password-manager use. Do not negotiate with the caller or let them “uninstall themselves.” Record the remote tool, displayed session/account, time and any commands or windows you remember. Uninstall the tool through the operating system and revoke unattended-access credentials inside the remote service when available.

From another trusted device, change exposed account passwords, revoke active sessions and enable MFA. Begin with primary email, password manager, banking and the browser-sync account because they can unlock other services. Review forwarding rules, recovery email/phone, new MFA methods and trusted devices. Do not type new passwords on the potentially controlled machine until its trust is restored.

Microsoft's current tech-support scam recovery says scammers with remote access may install malware or unwanted software and that resetting the device can be appropriate. A clean Sophos scan is useful but cannot reconstruct every action taken with legitimate administrator privileges. When sensitive information was visible or unexplained persistence remains, back up personal data carefully and use the operating system's trusted recovery/reset route or qualified in-person help.

Recover credentials and personal data from a trusted device

If you entered a password into the fake site or told it to a caller, change that password immediately from a trusted device. Change it anywhere it was reused, revoke existing sessions and add phishing-resistant MFA or the strongest method the service supports. A password change without session revocation can leave an attacker signed in, and MFA added before removing an attacker's recovery method can preserve their access.

If you shared card, bank, government ID or tax/identity information, contact the relevant institution through a known official route. In the United States, the FTC points identity exposures to IdentityTheft.gov; other countries have their own identity and fraud services. Monitor statements and account alerts, but do not rely on monitoring instead of immediate provider action.

Do not upload identity documents or diagnostic logs to a public Sophos forum, Reddit thread or removal website. A screenshot can expose email addresses, device names, domains, phone numbers or financial tabs. Redact only copies used for community discussion and preserve the original privately for the bank, provider or official report.

Use official Sophos support without letting search results choose the contact

Navigate directly to the Sophos Home support page. Premium users have the current web form/chat and documented weekday support route; Free users mainly use the knowledge base and account routes. A search result, PDF or forum page that repeats a phone number beside Sophos cancellation, malware or refund language is not proof of affiliation.

Give support a short evidence packet: Home version, OS, browser, device, local time/timezone, displayed domain as plain text, alert channel, matching or missing History event, changed permissions/extensions/apps and the exact exposure level. Include a screenshot only if it was captured without interacting and contains no secrets. If Sophos requests SDU logs, send them only through the official ticket/SendSafely process because logs can contain sensitive system details.

Sophos can help classify a detection or troubleshoot the Home product; it cannot reverse a bank payment or take over identity recovery. Send each part to the correct owner. If the event was a real website block rather than impersonation, our web protection guide explains website exceptions. If Home itself will not update or stay protected, return to the technical troubleshooting page.

Fake Sophos pop-up and support-scam FAQ

Is a Sophos pop-up with a phone number real?

Treat it as a support scam. The FTC says real security pop-up warnings do not ask you to call a phone number, and Sophos Home provides support through its official web routes. Close the browser without clicking the alert, then verify the event in the independently opened local Sophos app and Home History.

Does a fake virus pop-up mean my computer is infected?

Not by itself. It may be a web page or a site notification that can be stopped by closing the page and revoking permission, but repeated redirects, new extensions, changed search settings or installed software require deeper cleanup. Use the exposure and symptom evidence instead of trusting the page's fake scan result.

Why do fake alerts appear when the browser is closed?

Website notifications can be delivered through the browser's background notification system, and Edge and Safari document that they can appear when the site or browser is not visibly open. The notification usually identifies the sending site or browser when expanded. Revoke that site's notification permission rather than clicking the alert or only clearing history.

How do I know whether Sophos really detected something?

Open Sophos Home independently from the operating system and sign in to the Home dashboard through your own bookmark or direct route. Real Sophos detections produce a local antivirus notification and a dashboard entry, while History retains Home activity for 90 days. A matching event, path and detection name are evidence; a logo on a web page is not.

Is the Welcome to Sophos Home pop-up on Mac fake?

It can be a legitimate macOS Full Disk Access setup prompt after installation or an operating-system upgrade. Sophos documents the exact Welcome screen and says it may return when required permissions are incomplete or Sonoma is outdated. Verify it through the installed app and System Settings, and never use a web-page phone number or downloaded profile to complete it.

Will clearing cookies stop fake antivirus notifications?

Not reliably. Cookies and history are different from a site's notification permission, and synced browser settings or extensions can restore unwanted behavior. Remove or block the sending site under Notifications first, then review extensions, homepage, search engine and sync if symptoms persist.

Should I reset the browser immediately?

Start with the narrowest action: close the page and revoke the suspicious site's notification permission. Reset the affected browser only when redirects, homepage/search changes or unwanted extensions remain after permission cleanup. Save needed bookmarks and understand what the browser's official reset preserves before using it.

What if I downloaded a tool from the fake Sophos alert?

Do not open it again. Preserve the filename and path, disconnect from sensitive work, remove the installed program through the operating system when applicable, update the device and run Sophos Home's full scan. If the tool received remote-control permission or ran with administrator rights, follow the remote-access recovery branch and consider a trusted reset.

What should I do after giving a scammer remote access?

End the session and disconnect the affected device from networks used for sensitive work. From a different trusted device, change exposed and reused passwords, revoke sessions and enable MFA; remove the remote-access tool and review accounts, updates and scans. Microsoft says resetting the device may be appropriate because the scammer could have installed additional software.

Can Sophos support remove the fake alert for me?

Sophos's current Browser Hijackers guide explains notification permissions, browser reset, unknown applications, sync, startup items and a full scan. Use the official Home support site reached directly, not a number or chat opened by the alert. Premium users can submit a case, but payment, identity and account recovery still need the bank or relevant provider.

Verify the browser, device and accounts before declaring cleanup complete

Restart the browser without restoring the suspicious session. Confirm the sender is absent from allowed notifications, the homepage/search engine and extensions are expected, no unknown application or startup item returns and ordinary browsing no longer redirects. Update the OS, browser and Sophos Home, then complete the real full scan and review the Home dashboard History. One clean restart and wake cycle are more informative than repeatedly refreshing the same page.

If remote access, administrator installation, credentials or payment were involved, browser quietness is not the finish line. Verify remote tools and unattended access are gone, sessions/recovery methods are clean, MFA is under your control and the bank/provider has the incident. Consider a trusted OS reset when device trust cannot be re-established. Keep a private timeline and report identifiers until financial and account monitoring is complete.

The final rule is simple: never let an alarming page define both the problem and the remedy. Close it, verify through independently opened trusted surfaces and match recovery to exposure. If the recovered setup is no longer a good fit, compare our current Windows 11 antivirus guide or Mac antivirus guide only after the existing device and accounts are stable.