What’s going around
Our security healthcheck covers settings, one by one. This page is about tricks, which have no switch to flip. Almost every successful attack now is a message that persuades you to do something, rather than a virus that sneaks in, so knowing the shape of the trick protects you better than any software.
Reviewed July 2026. We keep this current rather than leaving it to rot.
Tricks doing the rounds
Being asked to paste something into Terminal
A web page, often a fake 'verify you are human' box or a fake error message, tells you to copy a line of text and paste it into Terminal. Doing so installs the malware yourself. This is why it works: because you ran it, none of the Mac's built-in protections ever get a say. It is currently the most common way Macs are infected, and it usually arrives through a sponsored search result or a link on a social post.
If a website ever tells you to copy something and paste it into Terminal, it is an attack. There is no legitimate website anywhere that needs you to do this. No exceptions, however official the page looks.
A very large breach just happened: 23 million accounts exposed
Paidwork, a gig-work app, had a serious breach in 2026: names, dates of birth, email addresses, phone numbers, home addresses, device details and passwords (as bcrypt hashes) for over 23 million accounts, alongside bank account numbers and payout history for anyone who used it to get paid out. It surfaced on a hacking forum in April and was published in full in July.
Check haveibeenpwned.com with your email address to see if you were caught up in this, or any other breach. If you were, change that password everywhere you reused it. A breach this size happens every few weeks somewhere; the habit of checking regularly is what protects you, not knowing about this one company.
Downloading software from a search result
You search for an app, and the first result is an advert leading to a convincing copy of the real site. The download works, but it comes with a passenger. Real examples in the past year include fake versions of common Mac utilities and, increasingly, fake AI tools.
Never download software from a search result. Type the maker's address yourself, or use the App Store. The top result is the one somebody paid for, which makes it the least trustworthy thing on the page, not the most.
"Your Mac is infected" pop-ups
A page appears looking like a genuine macOS alert, complete with Apple logo, warning of viruses and offering a phone number or a download. Sometimes it fills the screen and resists being closed.
It is just a web page. A web page cannot see inside your Mac, so it cannot possibly know whether you have a virus. Real macOS updates never appear in a browser and never give you a phone number.
Mac password stealers
Software that runs once, takes everything valuable, and sends it off: saved browser passwords, login sessions, the keychain, crypto wallets, and files from your Desktop and Documents. It arrives through the two tricks above, or through cracked software.
The malware is a five-minute problem. The stolen passwords are a five-year problem. That is why unique passwords and two-factor matter so much: they stop one bad afternoon becoming everything you own.
"Our bank details have changed"
An email arrives from a supplier you really do use, attaching a real-looking invoice with new bank details. Their email account has been compromised, or convincingly imitated. Nothing on your side has been hacked, which is why no security software catches it.
Any change to bank details is verified by ringing the supplier on a number you already had. Never a number in the email, never by replying to it. Agree that rule now, and make it one that nobody can be annoyed at you for following.
Being asked to "approve" or "allow" something you did not start
A prompt asks you to grant an app access to your email or files, or a login approval appears on your phone. Approving it hands over access without the attacker ever needing your password, and two-factor is never challenged, because you approved it.
If a login or permission prompt appears that you did not personally just trigger, it is not yours. Say no. An unexpected approval request means somebody else already has your password.
Fake delivery texts, and refunds you never asked for
A text about a missed parcel needing a small redelivery fee. The few pounds are not the point: your card details are. A costlier variant is an emailed invoice for a subscription you do not have, with a phone number instead of a link. Ringing it leads to someone installing remote access software and walking you into your own bank.
Check any charge you do not recognise in your own banking app, or on the company's real website. Never on a number or a link in the message that told you about it. No real bank or police force will ever ask you to move money to a safe account. That request alone proves the call is fake.
Fake QR code stickers
A criminal's sticker is pasted over the genuine QR code on a parking meter or charging point, leading to a convincing copy of the payment site. You pay them, you still get a ticket, and you are sometimes signed up to a subscription as well.
Pay for parking in the operator's own app, or on a number printed into the machine. If a QR code is a sticker sitting on top of the surface, do not use it.
AI voice cloning, and why it worries people more than it should
A few seconds of someone's voice is enough to clone it convincingly, and there have been genuine, expensive cases of people being fooled by a familiar voice or face on a call.
This gets considerably more press than the evidence supports. UK losses from impersonating a boss or a supplier actually fell in 2025, while old-fashioned fake-goods and investment scams grew. It deserves five minutes of preparation, not five hours of worry.
Ransomware, and what it actually means for a Mac business
Ransomware is the threat making the news, and rightly so. But ransomware that attacks Macs barely exists in the wild.
For a Mac business the risk is almost never the Mac. It is your cloud accounts, your shared drives, and any Windows machine in the corner. The defence is a backup you have actually restored from, kept somewhere the infected machine cannot reach.
Not malware, just annoying
Half of what frightens people is not an attack at all. Every one of these is reversible in under five minutes, and not one of them means you were careless. The common thread is that each was agreed to once, usually by clicking the button that looked like the only way to carry on.
Notifications that look like virus warnings
Alerts keep appearing saying your Mac is infected or a subscription has expired. They arrive in Notification Centre alongside Mail and Calendar, which makes them look official. What actually happened is that months ago a website asked to send you notifications and somebody clicked Allow. That permission was then sold on to advertisers.
A web page cannot scan your Mac, so it cannot know whether you have a virus. This is an advert wearing a costume, and it takes about thirty seconds to remove for good.
Events you never agreed to, appearing in your calendar
Invitations arrive, usually to an iCloud address, and land in the diary before you have accepted anything, often repeating and usually containing a link.
Your account has not been broken into. Somebody has your email address and nothing else. This is spam that arrived through the diary door instead of the inbox door.
Browser extensions that changed hands
A useful extension installed years ago, a coupon finder or a PDF tool, was sold to somebody else or had its developer account compromised. An automatic update turned it into an advert injector. The permission to read every page you visit was granted on day one and carried over to the new owner.
Nothing broke in. A tool you approved changed hands, and removing it removes the problem completely.
Your homepage or search engine changed by itself
The browser opens on a site nobody has heard of, searches go somewhere unfamiliar, and new tabs appear on their own. This almost always arrives inside a bundled installer: a free file converter, a fake update prompt, or a 'Mac cleaner', where a pre-ticked box installed an extra passenger.
Something you downloaded came with a passenger. It has not spread, it is not encrypting anything, and it reverses.
"Cleaner" and "speed up your Mac" apps
An app you half remember installing reports hundreds or thousands of problems, shows red warnings constantly, and wants a subscription to fix them. The problems are largely invented, and the alarm is the product.
The thing warning you about problems is the problem. Uninstall it and the warnings stop.
"I know your password, and I have been watching you"
An email quotes a real password of yours and threatens to release embarrassing footage unless you pay. The password being genuine is what makes it frightening.
That password came from a website that was breached years ago, not from your computer. They have never been anywhere near your Mac, and there is no footage.
"Background items added", and a Mac that starts up slowly
macOS tells you when an app registers something to run in the background. Over years these accumulate, and the machine takes longer to become usable after logging in.
That notification is your Mac being honest with you about something an app just did. It is a receipt, not an alarm. Older versions of macOS simply never told you.
Fans blowing and everything slow, right after a big update
For a day or two after a major macOS upgrade the Mac reindexes everything it can search and re-analyses your photo library.
This is temporary and normal, and it settles by itself. It causes more worried phone calls than every genuine piece of Mac malware put together.
If something has happened and you are not sure how bad it is, ask sooner rather than later. Nobody here will make you feel foolish for clicking something: these tricks are designed by professionals to be convincing, and the people who fall for them are not the careless ones.
