There is another scam going around as pop-ups that appear in your browser while surfing the web with Safari, Firefox or Chrome. What happens is a pop-up appears and explains that you have a security breach on your Macintosh (or Windows computer). Then, it directs you to call 800-656-8547, for instructions on how to take care of this “breach.” The instructions are to let a “technician” into your computer virtually, which is a bad idea in general, and then have to pay them upwards of $300 to “clean your Macintosh.” This is just another variation of the typical pop-up scareware banners that trick you into thinking something is wrong with your computer–which there is not. Whatever you do, don’t call that number!
If you happen to be reading this post after you have called the number for this pop-up scam, here’s a few things to do immediately on your Macintosh.
- First, if you gave them a credit card number, you will probably want to call the bank and have them deny the charge and cancel that card. Once they have that number, they may use it further, or, sell it off on the black market.
- If they actually took control of your Mac, they may have done nothing, or, they may have inserted any variety of malware, keylogging software, etc. It’s hard to say for sure, but, different scams of this variety do different things. At minimum, you would want to change your administrator password (System Preferences –> Users and Groups –> Change Password) for all accounts on the Mac. Depending on your comfort level, you would also want to consider rolling back to an earlier date in time with Time Machine backup, or, consider a scorched Earth path to completely wipe the computer clean and start over. If you were to do this drastic step, I would wipe the computer clean, and then install an operating system first, and then go back and restore just your user folder from backup. Select only important users in the Setup Assistant dialog box—not the Applications, Other files and folders, or Computer & Network Settings. Don’t transfer the Guest account, if you had this enabled.
- Don’t install 3rd party software from your backups–try to go back to the original media for this step.
- We advise you change any internet passwords that you may have typed in after this breach, such as banking or online retail store accounts–this is a good step to do anyway, every few months.
- It’s not a bad idea to install some form of anti-virus software at this point, such as Sophos for the Mac, which is more of a piece-of-mind-just-in-case step. It will come up with some errors during scanning, which usually means that it cannot scan system files that are in use. If it finds anything strange, it will quarantine these files.
Hopefully after all of these steps, your Mac will be somewhat back to normal. Remember, this scam is a popular one and many more malicious folks are putting this scam into action. 800-656-8547 is just one of many following the same routine and we ask that you don’t ever call anyone for Macintosh help except for AppleCare and local computer companies (such as Capital Mac Service) in your area that specialize in the Macintosh. If you get bitten by this, or any other scam, don’t panic and don’t ever give out personal information such as credit card numbers, social security numbers and birthdates. Above all else, don’t let remote people take over your computer–this is just asking for trouble!