Android Security Updates Explained: How Long Each Phone Stays Protected

Android security updates run 3 to 7 years depending on the brand you own. Learn how to check your exact patch cutoff date before support quietly ends.

I still see readers hanging onto a three-year-old Android phone that runs fine, looks fine, and yet quietly stopped getting security patches months ago. Android security updates are the monthly patches that close known vulnerabilities — separate from the yearly Android version upgrade — and once they stop, your phone stays exposed to every exploit found after that date.

The real deadline that decides whether your phone is still safe isn’t the day it stops getting a new Android version — it’s the day monthly security patches stop, because that’s when known exploits stay open forever.

Quick Answer

Android security updates typically run 3 to 7 years depending on brand: Pixel and Samsung Galaxy flagships lead at 7 years, mid-range phones average 4-5, and budget models often stop at 2-3. Check your exact end date under Settings > Security & Privacy > System & Updates, and treat any device past that date as unsafe for banking.

What Are Android Security Updates, and Why Do They Matter?

A security update patches a specific vulnerability Google or your manufacturer found in Android’s code — different from an Android version upgrade, which adds features. You can be stuck on an old Android version but still safe if patches keep arriving; you can’t be safe once patches stop, no matter how new the version number looks.

Google ships a monthly Android Security Bulletin, and phone makers pull those fixes into their builds on their own schedule. Two phones on the identical Android version can have very different real exposure.

Security updates patch known exploits every month; the Android version number tells you almost nothing about how protected you actually are.

How Long Does Each Android Phone Get Security Updates?

Support windows vary widely by brand and tier. Here’s how the major players compare:

Brand / Tier Typical Update Window Example
Google Pixel (8 and newer) 7 years Pixel 8, Pixel 9 series
Samsung Galaxy S / Z flagships 7 years Galaxy S24, Galaxy Z Fold6
Samsung Galaxy A (mid-range) 4-5 years Galaxy A54, A55
OnePlus flagships 4 years OnePlus 12
Budget/carrier-only models 2-3 years Entry-level prepaid phones

Pro tip: before buying, search “[model name] security update policy” on the manufacturer’s support site. That commitment is usually a specific end date or year count, not a vague promise.

Update windows range from 2 to 7 years, and a flagship can outlast a budget phone by five extra years of protection.

How Can You Check Your Phone’s Update Status?

Find Your Current Security Patch Level

Open Settings, go to About Phone, and look for “Android security update” or “Security patch level.” That date is the last month Google’s fixes were applied — not the day you last tapped “check for updates.”

Look Up Your Model’s End-of-Support Date

On my Pixel 7, Settings > Security & Privacy shows a “Security update” line with an explicit expiration date. My old Moto G7 just displayed “Up to date” with no end date anywhere — itself a warning sign, since transparent manufacturers list a real date.

If your settings don’t show an end date, search your model number plus “end of life” on the maker’s site.

Your patch date lives under About Phone or Security settings, and a missing end date is a sign to plan a replacement sooner.

What Happens When Updates Stop?

Nothing changes visually. Your phone keeps working and no popup warns you. What actually happens is every vulnerability Google discloses afterward stays open permanently, since no manufacturer builds a fix past the support window.

Some banking apps check your patch level and quietly flag or block sessions once you’re far past end-of-support. Play Protect keeps scanning for bad apps, but that’s a different defense layer — it can’t patch an OS-level hole.

Troubleshooting tip: if Settings shows “checking for update” for months on a phone that should still be supported, force a manual check via Settings > System > System update, then contact your carrier — branded phones often delay fixes by weeks for re-testing.

Updates ending doesn’t break your phone visibly, but it leaves every future disclosed exploit permanently unpatched.

How Do You Extend Your Phone’s Safe Lifespan?

You can’t extend the manufacturer’s patch schedule, but you can shrink your exposure and prepare for the switch.

Reduce What’s Exposed

Review which apps reach your camera, contacts, and location by auditing your Android app permissions, and tighten the settings in this guide to lock down Android privacy settings. Less exposed data means less to lose if a flaw is exploited.

Prepare for the Cutoff

Before your window closes, back up your Android phone, and confirm Find My Device is active. For the full technical record, see Google’s Android Security Bulletins.

You can’t restart the update clock, but tightening permissions and backing up now limits what a future exploit could reach.

Common Mistakes to Avoid

Trusting “Up to date” at face value. That label means no pending download exists, not that your model still gets patches. Check the actual patch date instead.

Buying a budget phone without checking its update policy. Many entry-level models get 2 years or less. Look up the schedule before you pay.

Ignoring carrier-caused delays. A carrier-locked phone can lag weeks behind the unlocked version of the same model.

Still banking on an end-of-support phone. Migrate authenticator apps and payments to a supported device before the cutoff, not after.

Leaving automatic updates off. Enable Settings > System > System update > automatic downloads so you never miss a patch.

Frequently Asked Questions

How do I know when my phone’s security updates end?
Check Settings > Security & Privacy > System & Updates for an end date, or search your model plus “security update schedule” online. On my Pixel the date sits right in settings; on older budget phones I’ve tested, it’s often missing entirely.

Do budget Android phones really get fewer updates?
Yes — most budget and carrier-only models cap out around 2-3 years versus 4-7 for flagships. Check this the same way you’d check battery capacity before buying.

Is it unsafe to keep using a phone after updates stop?
It’s riskier, not instantly dangerous — the phone still works, but future exploits stay unpatched. I’d stop banking on it and treat it as a secondary device rather than replace it that same day.

Does Google Play Protect cover me once patches end?
Only partially. Play Protect scans for malicious apps but can’t fix a vulnerability baked into Android itself. Losing one layer still weakens the other.

Can a custom ROM extend support?
Some community ROMs like LineageOS keep patching older hardware after the manufacturer stops, but that means unlocking your bootloader and accepting the risk yourself.

Why does my carrier’s update arrive later than the unlocked model’s?
Carriers re-test updates against their network first, adding days or weeks of delay. An unlocked or Google-direct model usually gets patches faster.

Conclusion

Your Android phone’s real safety deadline is its security patch cutoff, not its version number or how new it feels. Check your patch date today under Settings > Security & Privacy, and if you’re within a year of end-of-support, start backing up and shopping for a replacement now.

Windows Sandbox: How to Test Untrusted Apps Without Touching Your Real PC

Windows Sandbox lets you test untrusted apps safely on Windows 11. Enable it in minutes and try any installer without risking your real PC.

I’ve downloaded plenty of installers from small developer sites and forum links where I genuinely couldn’t tell if the .exe was safe. Running it straight on my main Windows 11 machine felt like a gamble every time. Windows Sandbox solves that problem by giving you a disposable, isolated desktop that throws itself away the moment you close it.

The crux is this: Windows Sandbox is a full, temporary copy of Windows that runs inside your real Windows 11 install, so anything an untrusted app does — installs, registry changes, malware — never touches your actual files, drivers, or settings.

Quick Answer

Windows Sandbox is a free, built-in Windows 11 Pro/Enterprise feature that launches an isolated, temporary desktop for testing unknown apps. Enable it once in Windows Features, then open it from the Start menu, drag in an installer, and run it. Close the window and every trace disappears — no cleanup, no snapshots, no risk to your real system.

What Is Windows Sandbox and How Does It Work?

Windows Sandbox is a lightweight virtual machine that Microsoft builds directly into Windows 11. Unlike a full VM in something like VirtualBox, it uses your existing Windows installation files instead of a separate disk image, so it starts in seconds rather than minutes.

Every time you open it, you get a completely clean desktop. Every time you close it, that desktop — along with anything you installed or downloaded inside it — is permanently discarded. Nothing persists between sessions, which is exactly what you want when you’re testing something you don’t fully trust yet.

In short: Windows Sandbox is a throwaway Windows desktop that resets itself every time you close it.

How Do I Turn On Windows Sandbox on Windows 11?

Check Your Windows 11 Edition First

Windows Sandbox only ships with Windows 11 Pro, Enterprise, and Education. If you’re on Home edition, the feature won’t appear in the list at all — you’d need to upgrade to Pro to get it. You also need virtualization enabled in your BIOS/UEFI, which is on by default on most modern PCs.

Enable the Windows Sandbox Feature

  1. Press Win, type “Turn Windows features on or off,” and open it.
  2. Scroll down and check the box next to “Windows Sandbox.”
  3. Click OK and let Windows install the feature.
  4. Restart your PC when prompted.

Launch Windows Sandbox for the First Time

After the restart, press Win, type “Windows Sandbox,” and open it. On my first launch it took about 15 seconds to boot into a bare Windows 11 desktop — no icons, no installed apps, just the taskbar and a browser shortcut.

Enabling Windows Sandbox takes one checkbox and one restart, and it only works on Pro, Enterprise, or Education editions.

How Do I Test an App Inside Windows Sandbox?

Copy the Installer Into the Sandbox

Drag and drop the installer file from your real desktop straight into the Sandbox window. You can also copy a file on your host machine and paste it inside the Sandbox — clipboard sharing works both ways by default.

Run and Watch the App’s Behavior

Double-click the installer inside the Sandbox exactly as you would on your main PC. Watch for anything odd: unexpected extra installers bundling in, browser homepage changes, or new startup entries. Since this is an isolated copy of Windows, none of that follows you back out.

Close the Sandbox When You’re Done

Close the Windows Sandbox window like any other app. You’ll get a warning that all Sandbox data will be discarded — click Yes. There’s no save state and no export; that’s the entire point.

Testing inside Sandbox means dragging the file in, running it, and closing the window to erase every trace.

Windows Sandbox vs Virtual Machine vs Antivirus Scan: Which Should You Use?

Windows Sandbox isn’t your only option for vetting an unknown file. Here’s how it stacks up against the two alternatives I reach for most often.

Method Setup Time Best For
Windows Sandbox Under 2 minutes (one-time) Running an installer to see what it actually does
Full Virtual Machine (VirtualBox/Hyper-V) 20-30 minutes per VM Long-term testing, snapshots, or non-Windows OS testing
Antivirus / online scan Under 1 minute A fast static check before you even open the file

Windows Sandbox wins on speed and zero maintenance; a full VM wins when you need to keep and compare results across sessions.

How Do I Fix Windows Sandbox When It Won’t Start?

If Windows Sandbox greys out in the features list or fails to launch, the fix is almost always virtualization-related.

Confirm Virtualization Is On

Open Task Manager, go to the Performance tab, and check that “Virtualization” reads Enabled under CPU. If it says Disabled, you need to turn on Intel VT-x or AMD-V in your BIOS/UEFI settings.

Check for Conflicting Software

Sandbox can fail to start if another hypervisor, like VirtualBox running in a non-Hyper-V-compatible mode, is holding the CPU’s virtualization extensions. Close other VM software before opening Sandbox.

Pro tip: If Sandbox hangs on a black screen for more than a minute, don’t force-close it immediately — the first boot after enabling the feature sometimes takes longer while Windows finishes provisioning the base image.

Troubleshooting tip: Run DISM /Online /Cleanup-Image /RestoreHealth in an elevated terminal if Sandbox installs but crashes on every launch — a corrupted system image was the culprit the one time this happened to me.

Most Sandbox failures trace back to disabled virtualization or a conflicting hypervisor, both fixable without reinstalling Windows.

Common Mistakes to Avoid

  • Assuming Sandbox works on Windows 11 Home. It doesn’t — upgrade to Pro or use a full VM instead.
  • Treating Sandbox as a permanent test environment. Everything resets on close, so don’t install tools you plan to reuse; set up a real VM for that.
  • Skipping the virtualization check in BIOS. If the feature won’t even install, verify VT-x/AMD-V is on before troubleshooting anything else.
  • Downloading the file into Sandbox instead of dragging it in. Browsing inside Sandbox works, but dragging a file you already vetted a little is faster and avoids re-downloading through a slower virtualized network stack.
  • Ignoring red flags because “it’s just a test.” Note what the installer does inside Sandbox — bundled toolbars, odd network requests — before deciding whether to trust it on your real PC at all; a quick look at how to spot a fake app before you install it helps you catch trouble before you even reach for Sandbox.

Frequently Asked Questions

Does Windows Sandbox slow down my PC while it’s running?
It uses a modest slice of CPU and RAM while open, similar to running a lightweight VM. On my 16GB laptop I didn’t notice a slowdown in other apps, but on an 8GB machine, close a few browser tabs first.

Can I install real software permanently using Windows Sandbox?
No, nothing installed inside Sandbox survives after you close it. If you want a persistent isolated environment, set up a dedicated virtual machine instead.

Is Windows Sandbox available on Windows 10?
Yes, on Windows 10 Pro and Enterprise (version 1903 and later) through the same “Turn Windows features on or off” menu I used above.

Does Windows Sandbox protect me from every kind of malware?
It isolates most file-based threats effectively, but it’s not a substitute for antivirus on your main PC. I still run a normal AV scan on anything I later decide is safe enough to install for real.

Why does my Sandbox window look completely empty with no apps?
That’s expected — Sandbox boots a bare Windows image with no third-party software preinstalled. If you need a browser or specific tool for testing, grab one of the many built-in Windows 11 settings and tools already available, or install it fresh inside the session.

Can I copy files out of Sandbox before closing it?
Yes, clipboard and drag-and-drop work in both directions, so you can pull a log file or screenshot out before you close the window and lose everything else.

Conclusion

Windows Sandbox turned “I hope this installer is safe” into a two-minute test I actually run before opening anything questionable. Enable it once, and it’s there every time you need a disposable desktop. For more built-in Windows 11 features worth setting up, check my guide to automatic file backups on Windows 11, and see Microsoft’s own Windows Sandbox documentation for the full technical rundown.

5 Checks That Reveal a Fake App Before You Install It

Learn to spot a fake app before installing with 5 quick checks — verify the developer, read review patterns, and audit permissions in under two minutes.

Learning to spot a fake app before installing is one of the most useful habits you can build for your phone. Every year, millions of people download malicious clones that look legitimate but secretly steal personal data, serve aggressive ads, or quietly charge hidden subscriptions. I nearly fell for one myself — a flashlight app in the Play Store with polished screenshots, five-star reviews, and tens of thousands of downloads. The single most effective defence is knowing what to check in the two minutes before you tap Install.

Fake apps — also called copycat apps or malicious clones — mimic trusted software closely enough to fool careful users. The good news: once you know which signals to check, the whole routine takes under two minutes and applies to any app store on any platform.

Quick Answer

Before installing any app, verify the developer name exactly matches the official company, confirm that reviews span months rather than days, check that permissions match the app’s stated purpose, and search the developer name in your browser. If any check fails, don’t install.

How Do Fake Apps End Up in App Stores?

App store review processes catch most threats, but bad actors find workarounds. A common method: submit a harmless app that passes review, then push a malicious update weeks later. Others clone a popular app’s name and icon precisely, counting on users rushing through search results without reading carefully.

Google Play has removed fake security and utility apps after tens of thousands of installs. The Apple App Store is harder to penetrate but not immune — phishing links on social media bypass the store entirely and point users straight to malicious downloads.

Understanding how fakes slip through tells you exactly which listing signals deserve the most scrutiny.

What Red Flags Should You Check Before Installing?

1. Verify the Developer Name Exactly

The most common trick is a one-letter swap or extra word — “Whatsup Inc.” instead of WhatsApp LLC, or “Adobe System” without the “s.” Tap the developer name in the store and look at their full catalog. A legitimate publisher has dozens of well-known titles, not three apps with vague names published in the last month.

Pro tip: On Android, tap “About this app” in the Play Store listing. On iPhone, tap the developer name to see every app they’ve ever published.

2. Read the Review Dates and Patterns

A real app collects reviews over months or years. If an app shows thousands of reviews but every one was posted within the last two weeks, that’s a paid-review farm. Look for a range of star ratings — genuine apps have unhappy users who name specific bugs. Rows of five-word five-star praise (“Great app!! Works perfectly!!”) repeated by dozens of accounts is a reliable signal to walk away.

3. Audit the App Permissions Before Downloading

On Android, tap “About this app” then “App permissions” in the Play Store listing before you download. On iPhone, permission prompts appear on first launch. A flashlight app that requests access to your contacts and microphone has no legitimate reason for either. I once installed a battery optimizer that wanted SMS read access — a permission no battery tool ever needs — and removed it within minutes.

Troubleshooting tip: After installing any app, open Settings > Apps (Android) or Settings > Privacy & Security (iPhone) and revoke any permission that doesn’t match the app’s stated purpose. My guide to Android app permissions explains exactly what each one accesses and which are safe to deny.

4. Read the Description and Screenshots

Legitimate apps list specific features, maintain a changelog in the “What’s New” section, and link to a real privacy policy and support page. Fake apps rely on vague copy: “Best utility performance optimizer 2024!” with no feature detail. Screenshots that show a UI unrelated to the app’s stated purpose — or generic stock photos — are a warning worth heeding.

5. Search the Developer Name Outside the Store

Spend 60 seconds searching “[developer name] reviews” or “[app name] scam” in your browser. Real apps have Reddit threads, tech-publication coverage, or an official website. If the only results are the app store listing itself, that absence is worth acting on before you download.

These five checks form a pre-install routine that takes under two minutes and catches the most common copycat patterns.

How Do Real and Fake Apps Compare?

Signal Legitimate App Fake / Copycat App
Developer name Exact official company name Subtle misspelling or added word
Review history Spread over months or years Clustered within days or weeks
Permissions Match the app’s stated purpose Overbroad; requests unrelated access
Description Specific features, changelog, support link Vague, generic, poor grammar
Publisher catalog Multiple well-known titles Few apps with unrelated names

Running this comparison against any unfamiliar listing takes under two minutes and highlights where a fake app can’t maintain the appearance of legitimacy.

Common Mistakes to Avoid

  • Trusting the icon alone. Copycats replicate official icons pixel-for-pixel. Always verify the developer name separately — a matching icon proves nothing on its own.
  • Skipping the permissions screen. Tapping “Allow” on every prompt without reading is how fake apps gain lasting access to your data. Revoke anything the app doesn’t need right after install.
  • Installing from links in messages or ads. Phishing links bypass app stores entirely. Navigate to the store yourself and search for the app directly rather than tapping a link someone sent you.
  • Treating high download counts as proof of safety. Fake review services inflate install numbers. Use download count as one signal among several, not the deciding factor.
  • Never rechecking permissions after an update. A clean app can gain new permissions through a later update. Revisit Settings > Apps (Android) or Settings > Privacy & Security (iPhone) every few months.

Each mistake follows the same root cause — moving too fast through the installation process without pausing to verify the basics.

Frequently Asked Questions

Can fake apps appear on the Apple App Store?
Yes, though it’s rarer than on Google Play. Apple’s review process is stricter, but copycat apps with slightly altered names do get through. The same pre-install checks apply on iOS. For broader app privacy on iPhone, see 8 iPhone privacy settings to change right now.

What should I do if I already installed a suspicious app?
Uninstall it immediately, then open Settings and revoke every permission it was granted. Change passwords for any accounts you logged into while the app was active. If personal data may have been exposed, the recovery steps in how to protect your identity after a data breach apply directly here.

Does Google Play Protect scan apps automatically?
Yes. Open the Play Store, tap your profile picture, and select Play Protect to confirm it’s enabled and run a manual scan. Google’s Play Protect support page explains exactly what it checks. On iPhone, iOS sandboxing limits what a malicious app can access even after install.

Are free apps with no obvious revenue model more suspicious?
Worth extra scrutiny, yes. An app with no ads and no paid tier may be monetising your data instead. That said, many legitimate open-source apps are genuinely free — run all five checks regardless of price, not just for apps that cost money.

These answers cover the most common questions that come up once you start applying the pre-install checklist to unfamiliar apps.

Conclusion

Two minutes of checking before you tap Install can save hours of cleanup afterward. Verify the developer name, study the review patterns, audit permissions, and search outside the store — that four-step habit filters out the vast majority of fake apps. For more on how bad actors use the same manipulation tactics in a different context, my guide to spotting tech support scams is a natural next step.

Spot a Tech Support Scam Before It Hooks You: 6 Red Flags and What to Do

Learn to spot a tech support scam fast: 6 red flags that expose fake alerts, cold calls, and phony support pages before handing over access or money.

I was halfway through a video call when a blaring alarm flooded my screen and a banner declared that Windows had detected critical infections — complete with a toll-free number to call immediately. My stomach dropped before my brain took over. Tech support scams are engineered to produce exactly that reaction, because panic is what makes them work.

According to the FTC’s consumer guidance on tech support scams, these schemes cost Americans hundreds of millions of dollars each year. The reassuring part: once you know how to spot a tech support scam, the tactics become obvious — and you can shut them down in seconds.

Quick Answer

A tech support scam uses a pop-up alarm, unsolicited phone call, or fake error page to convince you your device is infected. Microsoft, Apple, and Google never contact you unprompted about viruses. Hang up or close the tab, then run a free scan with Windows Defender or Malwarebytes.

What Are the Three Types of Tech Support Scams?

Most attacks arrive one of three ways. Knowing the delivery method makes the red flags much easier to spot.

Scam type How it arrives Immediate giveaway
Fake pop-up alert A website triggers a full-screen alarm with a toll-free number Real OS errors never include a phone number
Unsolicited phone call Caller claims to be Microsoft, Apple, or “Windows Support” Legitimate companies never call you about viruses unprompted
Fake search ad Paid ad mimics the official support page for a brand URL doesn’t end in the brand’s real domain

All three methods share the same end goal: get you on a call, convince you to hand over remote access, or pay for fake “cleanup” software.

How Do I Spot a Tech Support Scam in the Moment?

Run through these six checks whenever something feels off. Most scams fail on the very first one.

1. The Alert Includes a Phone Number

Real error messages from Windows, macOS, or any browser never display a phone number. The moment you see a toll-free number urging you to “call immediately,” you’re looking at a scam. Close the tab without dialing.

2. Someone Contacted You First

Legitimate tech companies do not make unsolicited calls to warn you about viruses or account compromises. If you receive an unexpected call from “Microsoft Support” or “Apple Security,” hang up without engaging. Scammers routinely spoof real Microsoft and Apple caller-ID numbers to appear more convincing.

3. The Page or Alarm Won’t Close

A frozen browser with a looping alarm is a scare tactic, not a real system event. Press Alt+F4 on Windows or Command+Q on Mac to force-quit the browser. If it won’t respond, open Task Manager (Ctrl+Shift+Esc) and end the browser process — the “emergency” disappears instantly.

4. They Ask You to Install Remote Access Software

Once on a call, scammers direct you to download AnyDesk or TeamViewer so they can “diagnose” your machine. They then open Windows Event Viewer — which shows harmless warnings on any healthy PC — and present those entries as proof of infection. On my freshly installed Windows 11 machine, Event Viewer listed 47 warnings straight out of the box. Every one of them was normal.

5. Payment Is Requested by Gift Card or Wire Transfer

Legitimate companies bill through secure online portals, not over the phone. Any request for gift cards, wire transfer, Zelle, or cryptocurrency is a definitive sign of a scam — without exception.

6. The URL Doesn’t Match the Real Brand

Before clicking a search result or support link, check the browser address bar. Domains like microsoftsupportcenter.net or apple-security-alert.com are not owned by Microsoft or Apple. Real Microsoft pages end in microsoft.com and real Apple pages end in apple.com.

If even one of these six signs appears, stop — the combination of urgency, unsolicited contact, and unusual payment demands has no legitimate use case.

What Should I Do When a Scam Targets Me?

If You See a Pop-Up or Fake Alert

  1. Do not call the number on screen.
  2. Force-quit the browser with Alt+F4 or Task Manager.
  3. Run a free scan with Windows Defender or follow this malware removal walkthrough to confirm nothing installed itself.
  4. Clear your browser cache (Ctrl+Shift+Delete) in case a rogue extension triggered the alert.

If You’re on the Phone With a Scammer

  1. Hang up without explaining yourself — engagement gives them more time to manipulate you.
  2. Block the number immediately.
  3. Report it at ReportFraud.ftc.gov.

If You Already Gave Them Remote Access

  1. Disconnect from the internet immediately — pull the cable or toggle Wi-Fi off.
  2. From a separate device, change passwords for email, banking, and any accounts saved in your browser.
  3. Enable two-factor authentication on all important accounts right away.
  4. Run Windows Defender Offline Scan: Settings → Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan.
  5. If you shared financial details, contact your bank and follow this identity recovery guide for the full response plan.

Pro tip: Turn on Tamper Protection before anything goes wrong: Settings → Privacy & Security → Windows Security → Virus & threat protection settings → Tamper Protection (toggle On). This blocks unauthorized software — including tools scammers try to install — from disabling Windows Defender.

Troubleshooting tip: If your browser is completely frozen on a scam page, open Task Manager (Ctrl+Shift+Esc), find your browser under Apps, right-click it, and choose End Task. When you reopen the browser, close the previous-session tab before anything reloads.

Fast action after remote access matters: the sooner you disconnect and rotate passwords, the smaller the window scammers have to use what they captured.

Common Mistakes to Avoid

  • Calling the number “just to check.” Engaging makes you an active target. The number is always fake — there is nothing to verify by calling.
  • Trusting caller ID alone. Scammers spoof real Microsoft and Apple phone numbers routinely. A matching caller ID proves nothing about who is actually on the line.
  • Paying to “cancel” the service. After one payment, scammers often call back claiming a refund is owed, then walk you into sending even more money.
  • Not changing passwords after remote access. Even if the scammer “found nothing,” they may have silently copied saved credentials from your browser while on screen.
  • Letting embarrassment delay action. These scams catch intelligent people every day. Report immediately to the FTC and your bank — every hour of delay helps only the scammer.

The most common thread across scam reports is the same: the victim felt rushed. Slow down, run the six-flag checklist, and the scam has nowhere to go.

Frequently Asked Questions

Can a pop-up actually lock my computer?

No — a webpage can go full-screen and loop audio, but it cannot lock your operating system. Alt+F4 or Task Manager always breaks the illusion. The first time I hit one of these pages, I was convinced my PC had crashed; Alt+F4 cleared it in under two seconds.

Is it safe to use my computer after seeing a fake alert?

In most cases, yes. The pop-up itself rarely installs anything — its only job is to scare you into calling. Run Windows Defender after closing the browser; if the scan is clean, you’re fine and can continue working normally.

What if a family member already paid the scammer?

Call the bank or card issuer immediately to dispute the charge or freeze the card. If they paid by gift card, contact the issuer’s fraud line — some amounts are recoverable if you act within hours. Then change all passwords on any account the scammer may have viewed during remote access.

How do I tell a scam email from a real Microsoft security alert?

Real Microsoft security emails come from @microsoft.com addresses and link only to microsoft.com pages — never to a phone number. When in doubt, go directly to account.microsoft.com to check your security alerts. You can apply the same pattern recognition used to spot phishing emails across any brand.

These four questions cover the moments people freeze up most — bookmark this page so you can run through them the next time something suspicious lands on your screen.

Conclusion

Tech support scams run entirely on urgency and manufactured fear — remove either and the con collapses. Keep three rules front of mind: error messages never include phone numbers, real companies never call you unprompted about viruses, and no legitimate payment request ever involves gift cards or wire transfers. Share this guide with anyone who might be a target — awareness is the one defense these scams have no answer for.

Signs Your Phone Has Been Hacked and How to Take Back Control

Worried your phone has been hacked? I walk through the warning signs and an exact Android and iPhone cleanup plan so you can lock things down today.

Last winter a friend handed me her iPhone because it was “acting possessed” — dead by lunch, random Portuguese-language ads on the home screen, and a password-reset email from her bank she never asked for. Twenty minutes later we found a configuration profile she had been tricked into installing, and the picture snapped into focus. The earlier you catch a compromised phone, the difference between a fifteen-minute cleanup and months of identity-theft cleanup.

I have walked dozens of people through this exact panic, and the pattern is always the same: a few small symptoms that each look innocent until you line them up. Below I cover what a hacked phone actually looks like and the precise steps I use to clean one up on both Android and iPhone.

Quick Answer

The clearest signs your phone has been hacked are sudden battery drain, apps you never installed, unexpected mobile-data spikes, messages sent from your accounts that you didn’t write, pop-up ads, sluggish performance, and password-reset emails you didn’t request. If two or more apply, run a malware scan and change your passwords today.

What Are the Warning Signs Your Phone Has Been Hacked?

Spyware and adware leave fingerprints. Each sign below can have an innocent explanation on its own, but when several appear together I treat the phone as compromised until proven otherwise. Here are the seven I check first.

Is your battery draining far faster than normal?

Malicious apps run silently in the background — tracking location, uploading contacts, streaming the microphone — and all of that burns battery fast. If a phone that once lasted all day now dies by mid-afternoon for no obvious reason, I open Settings > Battery on iPhone or Settings > Battery > Battery Usage on Android and look for an unfamiliar app near the top of the list. On iOS 14+ and Android 12+, a colored dot in the status bar means the camera or microphone is active right now — seeing it while you’re doing neither is a red flag.

Unexplained battery drain plus a live camera or mic dot is one of the strongest early warning signs.

Are there apps you don’t recognize?

I scroll through every home screen and app drawer. Attackers love disguising apps as bland utilities like “System Service” or “Phone Manager” so they blend in. Uninstall anything you don’t remember adding. On Android, also open Settings > Security > Device Admin Apps and revoke admin access for anything you didn’t authorize. Rogue browser add-ons work the same way on desktop, and my guide on browser extensions that spy on you covers that angle in detail.

If an app is on your phone and you can’t recall installing it, treat it as hostile until you confirm otherwise.

Has your mobile data usage spiked?

Spyware exfiltrates messages, photos, and call logs to remote servers, and that traffic shows up in your data totals. I check Settings > Mobile Data on iPhone or Settings > Network & Internet > Data Usage on Android. An app you barely touch sitting at the top of the data list is worth acting on immediately.

A rarely-used app burning large amounts of background data usually means something is shipping your information out.

Are messages going out that you didn’t write?

If contacts say they’re getting strange links or odd messages from you, act right away. Hijacked phones get used to spread phishing links and run premium-rate SMS scams. I open the Sent folder in both Messages and email and scan for anything I didn’t send.

Outgoing messages you never wrote mean your accounts are already being used against your contacts.

Is the phone sluggish or overheating for no reason?

A phone running hot while idle or freezing often is busy with hidden background processes. On its own this could be a software bug or aging hardware, but paired with any other sign here it points to compromise and warrants a scan.

Heat and lag alone are inconclusive, but combined with another symptom they tip the scales toward malware.

Are pop-up ads showing up outside of apps?

Ads on your home screen, or inside apps that never had ads before, are a hallmark of adware that pays attackers to force advertisements onto your screen. When I see ads appearing where they have no business being, a rogue app is almost always the cause.

Ads outside of an app you opened are a near-certain sign of an adware infection.

Are you getting password resets you never asked for?

Password-reset emails you didn’t request, login alerts from unfamiliar places, or sudden lockouts all point to someone methodically taking over your accounts — often starting from access gained through your phone. This escalates within hours, so I act the same day every time. The fastest way to confirm it is to find and remove unknown logins on Google, Microsoft, and Apple.

Unrequested password resets are the loudest alarm on this list — never ignore them.

How Do You Clean Up a Hacked Phone Step by Step?

Once I’m confident the phone is compromised, I work through these five steps in order. Doing them out of sequence — for example, resetting passwords on the infected device before removing the malware — can hand your new credentials straight back to the attacker.

Step 1: Run a malware scan

On Android, I install Malwarebytes (free) and run a full device scan. On iPhone, I go to Settings > General > VPN & Device Management and delete any configuration profile I didn’t install — those profiles are the main way attackers bypass Apple’s protections without a jailbreak, and they were exactly what my friend had been tricked into adding.

Step 2: Remove every app you don’t recognize

Uninstall unfamiliar apps right away. On Android: Settings > Apps. On iPhone: press and hold the icon, then Remove App. If an Android app refuses to uninstall, it likely holds Device Administrator privileges — revoke those at Settings > Security > Device Admin Apps first, then remove it. When an app still resists, I boot into Safe Mode by holding the Power button, then long-pressing “Power off” until the Safe Mode prompt appears; third-party apps are disabled there, so they come off cleanly.

Step 3: Change your passwords, email first

Email is the master key to every other account, so I change it first, then banking, social media, and anything with saved payment details. Use a unique, strong password for each one, and turn on two-factor authentication everywhere it’s offered — my walkthrough on setting up two-factor authentication makes that quick. It’s also worth checking whether your password was already exposed in a data breach.

Step 4: Audit your signed-in devices

I open myaccount.google.com > Security > Your devices for Google and Android, or appleid.apple.com > Devices for iPhone, and remove anything I don’t recognize. Reviewing sign-in times and locations usually surfaces the intruder fast.

Step 4 follow-up: Confirm 2FA is active

Before moving on, I verify two-factor authentication is genuinely enabled and not just half-configured. A single missed account is all an attacker needs to walk back in.

Step 5: Factory reset as a last resort

If malware survives the steps above, a factory reset is the most reliable fix. Back up photos and contacts to the cloud first, then restore from a backup dated before your symptoms began — restoring a post-compromise backup just reinstalls the problem you removed.

Work these steps in order and most phones are fully clean within two hours.

Which Security Tools Should You Use on Android vs. iPhone?

When three or four tools all claim to help, I find a side-by-side comparison settles it fastest. Here’s what I actually reach for, all free or built in.

Tool Platform Purpose Cost
Malwarebytes Android Malware scan and removal Free
Google Play Protect Android Real-time app scanning Built-in
Apple ID Security iPhone Device audit and remote wipe Built-in
Have I Been Pwned Both Check email against breach databases Free

You don’t need to pay for anything — the built-in and free tools above cover the whole cleanup.

Common Mistakes to Avoid

These are the slip-ups I see most often, each with the fix I give people.

  1. Waiting to act. Symptoms don’t resolve on their own, and every hour gives attackers more time to harvest data. Fix: act the same day you notice something off.
  2. Changing only one password. Attackers usually target several accounts at once. Fix: change all important passwords, not just the obvious one.
  3. Restoring a backup without checking its date. A post-compromise backup reinstalls the malware. Fix: restore the most recent backup from before symptoms started.
  4. Skipping permission reviews after a reset. A clean phone can still leak data through over-permissioned apps. Fix: review each app’s permissions before granting them — a flashlight has no business reading your contacts.
  5. Resetting passwords on the still-infected phone. Active spyware can capture the new ones. Fix: remove the malware first, then change credentials from a clean device.

Most of the damage I see comes from rushing the order, not from the malware itself.

Frequently Asked Questions

Can iPhones get hacked?

Yes, iPhones can be hacked, though their closed ecosystem makes it harder. The friend I helped was compromised through a rogue configuration profile she installed after tapping a link in a fake “delivery” text — no jailbreak required.

Does a factory reset remove all malware?

In nearly all cases, yes — a factory reset wipes the device back to its original state. The one exception is firmware-level malware, which is extraordinarily rare; in years of helping people I’ve never seen it outside of news reports about state-sponsored attacks on high-value targets.

How do I check whether my email was exposed in a data breach?

Use Have I Been Pwned, a free and reputable service that checks your address against hundreds of known breaches. I ran my own email through it and found it in two old breaches, which is exactly why I now use unique passwords everywhere.

What is SIM swapping and should I worry about it?

SIM swapping is when an attacker convinces your carrier to move your number to a SIM they control, intercepting your SMS codes. I had a reader hit by this; the fix was calling the carrier directly and adding a SIM-lock PIN to the account, which blocks the transfer.

How long does it take to fully secure a hacked phone?

Most people finish a scan, password change, and account audit in under two hours. When I helped my friend it took about ninety minutes, and adding a factory reset would have added roughly another half hour.

Conclusion

A hacked phone is stressful but very recoverable — the real risk is waiting, because every hour a compromised device sits in your pocket adds to the damage. Work through the steps above the moment you spot two or more warning signs, then make two-factor authentication your permanent first line of defense. Start your scan today.

Spyware Browser Extensions: How I Find and Remove Them in 5 Minutes

Spyware browser extensions hide in plain sight. Here is how I audit permissions in Chrome, Firefox, Edge, and Safari and clear the risky ones fast.

A spyware browser extension rarely looks like a threat. You install a free PDF converter, a coupon finder, or a grammar checker, then forget it exists. Months later that same extension may be reading every page you open, capturing form fields, and quietly sending your browsing history to a data broker you have never heard of. The most dangerous extension on your machine is almost always one you stopped thinking about.

I run this audit on my own laptops every couple of months, and it has never taken longer than a coffee break. Security researchers keep finding popular extensions with millions of users harvesting data and selling it on, so a quick review is cheap insurance against a gap you did not know was open.

Quick Answer

Open your browser’s extension manager (chrome://extensions in Chrome, about:addons in Firefox, edge://extensions in Edge), then review each extension’s permissions. Remove anything you do not recognise, anything requesting access to all websites, and any extension not updated in over a year. Keep only what you actively use.

Why Are Browser Extensions a Security Risk?

Installing an extension grants it real permissions, sometimes sweeping ones. An extension with “read and change all your data on all websites” can reach your banking pages, email inbox, and login forms. Those permissions persist silently too: a legitimate tool can be sold to an untrustworthy company and pushed a new update full of data-collection code without ever alerting you.

An extension’s permissions, not its install count, decide how much damage it can do.

What Do Extension Permissions Actually Mean?

Permission What the Extension Can Do
Read browsing history See every URL you visit
Read and change all site data Access forms, passwords, and banking pages
Read clipboard Capture anything you copy, including passwords
Manage downloads Save or block files on your device
Access tabs Monitor which websites are open at any moment

How Do I Audit My Extensions in Chrome?

Chrome commands the majority of desktop browser usage, which makes it the most targeted platform for malicious extensions. It is also where I start every audit.

Step 1: Open the Extension Manager

Type chrome://extensions in the address bar and press Enter. Every installed extension appears here, including the ones you added months ago and forgot. The first time I did this I found three I could not even name.

Step 2: Review Permissions

Click Details under each extension, then scroll to the Permissions section. An extension that only reads the active tab is far less risky than one demanding access to all your data on all websites.

Step 3: Remove What You Do Not Use

Click Remove for anything you cannot account for. If you are unsure about a specific extension, search its name plus the word “security” to check for reported problems before deciding. Chrome also shows a “Last used” date under each one; anything idle for 30 days is a safe removal target, since reinstalling from the Chrome Web Store takes under a minute if you change your mind.

In Chrome, Details then Permissions tells you in seconds whether an extension can read everything you type.

How Do I Check Extensions in Firefox, Edge, and Safari?

The navigation paths differ slightly, but the goal is identical: open the manager, check permissions, remove the unused.

  • Firefox: Go to about:addons, click the three-dot menu next to any extension, and choose Permissions to review or Remove to uninstall.
  • Edge: Go to edge://extensions, click Details, and check “Access to websites.” Avoid extensions set to On all sites unless the task clearly demands it.
  • Safari (Mac): Open Safari, then Settings, then Extensions. Safari enforces stricter limits by default, but unused extensions still deserve a removal pass.

If removing an extension breaks a website feature you rely on, reinstall it only from the official browser store, never from a third-party download page, which is a common route for distributing compromised versions. For safe-browsing habits that complement this audit, see my guide on how to check if a website is actually safe before entering any personal details.

Every major browser exposes the same two facts: what an extension can access, and whether you still use it.

What Are the Red Flags of a Spyware Extension?

  • Permissions do not match the task. A dark-mode extension has no legitimate reason to read your clipboard or full browsing history.
  • No recent updates. Abandoned extensions get no security patches, yet they keep running with full permissions indefinitely.
  • Unknown or impersonating developer. Malicious extensions often clone the icon and name of a trusted tool. Verify the publisher on the official store listing before installing.
  • Alarming one-star reviews. Filter reviews by one star and look for phrases like “started redirecting searches” or “injecting ads.” Problems usually surface in reviews before any takedown happens.

Google’s documentation on extension permission warnings explains exactly what each install prompt means, and it is worth reading once before your next install. While you are auditing, it is also a good moment to move your logins into a dedicated password manager like Bitwarden, since a rogue extension with broad permissions can read browser-saved passwords as you type.

When the permissions outweigh the job an extension does, treat that mismatch as the warning itself.

Common Mistakes to Avoid

  1. Installing from outside the official store. Third-party sites often bundle extensions with hidden malware. Fix: always use the Chrome Web Store, Firefox Add-ons, or Microsoft Edge Add-ons.
  2. Accepting every permission prompt without reading it. Excessive permissions for a simple task are a clear red flag. Fix: spend 15 seconds reading the list before clicking Add to Chrome.
  3. Forgetting that extensions sync across devices. Chrome extensions linked to your Google account appear on every signed-in device automatically. Fix: check the extension list on each device separately after any audit.
  4. Keeping “just in case” extensions. Every idle extension is an active attack surface with nothing to show for it. Fix: remove it now, since reinstalling from the official store takes seconds.
  5. Assuming a high install count means it is safe. Several extensions with tens of millions of users have been caught harvesting data. Fix: check the developer’s privacy policy and recent reviews, not just the star rating.

Frequently Asked Questions

Can a browser extension steal my passwords?

Yes. An extension with “read and change all your data on websites” permission can capture passwords typed into login forms before they ever leave your browser. I once removed a “free coupon” extension that held exactly that permission despite having no reason to touch a login field.

Are extensions disabled in private or incognito mode?

By default, yes. In Chrome extensions are off in Incognito unless you enable them. When I checked mine, two had “Allow in Incognito” switched on from a setup I had forgotten, which I turned off in chrome://extensions under each extension’s detail panel.

How often should I audit my extensions?

Every one to three months is a sensible rhythm. I tie mine to the start of each season, and I also do a quick pass whenever a browser update drops me into the Extensions menu anyway.

Is there an automated tool that detects bad extensions?

Some security suites flag suspicious extensions, but manual review stays the most reliable approach. When I tested a third-party “extension scanner,” it wanted broad permissions of its own, so I deleted it and went back to the browser’s built-in manager, which lists every active extension already.

Should I use a VPN as well as auditing extensions?

They solve different problems, so use both. A clean extension list stops local snooping, while a VPN encrypts your traffic in transit; my VPN setup guide explains what a VPN does and does not protect.

Conclusion

Keeping your extension list short and intentional is one of the simplest high-impact security moves any browser user can make. Check permissions before every install, revisit the list every few months, and remove anything you cannot account for.

Once your browser is clean, finish the checkup by reviewing unknown logins on your Google, Microsoft, and Apple accounts to close the most common account-level gaps in one sitting.

How to Spot Phishing Emails: 5 Warning Signs in Smarter Fakes

Learn how to spot phishing emails in about 30 seconds using five reliable warning signs, a quick checklist, and the exact steps to take if you clicked a link.

Learning how to spot phishing emails matters more now than it ever has, because the messages behind these scams have never looked more convincing. Attackers clone brand logos, spoof sender names, and use AI to write flawless prose — and phishing now plays a role in the overwhelming majority of successful data breaches. The reassuring part is that even a polished phishing email almost always leaves one flaw you can catch in seconds.

I check suspicious messages for a living-adjacent reason: I run a tech help blog, so people forward me their “is this real?” emails constantly. The same 30-second routine catches nearly all of them, and I will walk you through exactly what I look at.

Quick Answer

Check four things before acting on any suspicious email: does the sender’s real address match the company’s true domain, does each hovered link point to that brand, is the message manufacturing urgency or threats, and does it ask for passwords or personal data? If even one answer looks off, do not click anything.

What are the warning signs of a phishing email?

Every phishing email I have inspected trips at least one of five wires. You rarely need all five — one solid red flag is enough to stop and verify through another channel.

1. The sender address does not match the brand

The display name in your inbox (“PayPal Support”) can say anything — it is the actual email address behind it that matters. Click or tap the sender name to expand the full address. A real PayPal email comes from @paypal.com, not @paypal-secure-account.net or @paypa1.com (the digit “1” swapped for the letter “l”). Misspelled domains and odd TLDs like .ru or .xyz tacked onto a brand name are immediate red flags. On a phone, press and hold the sender name for a second to reveal the full address without digging through settings.

2. Urgent or threatening language

“Your account has been suspended — verify now or lose access within 24 hours.” Phishing emails manufacture urgency because panic makes people skip the checks they would normally run. Legitimate banks, government agencies, and tech companies almost never demand instant action by email. When a message feels like it is rushing you, that pressure itself is the warning.

3. Links that do not go where they claim

Hover over any link before clicking on desktop, or long-press it on mobile, to preview the real destination URL. A genuine Microsoft link looks like account.microsoft.com — not microsoft-account-verify.com or a shortened bit.ly URL that hides the destination entirely. Even one character off in the domain can send you to a lookalike page built to capture your password. If you cannot safely preview the URL, paste the link (without clicking it) into VirusTotal, which scans the address against dozens of security engines for free.

4. Generic greetings and awkward phrasing

“Dear Valued Customer” instead of your name signals a bulk send. Real services you hold accounts with know who you are. Watch also for slightly off phrasing — sentences that technically parse but feel machine-translated, or mismatched fonts that hint at content pasted from several sources.

5. Unexpected attachments or requests for credentials

No legitimate company sends an unexpected attachment and tells you to open it to “verify your identity.” Real password-reset emails link to a form on their own site; they never ask you to reply with your current password. Any message requesting credentials, a Social Security number, or banking details in the reply is phishing, without exception.

If a message trips even one of these five wires, treat it as fake until proven otherwise.

What are the main types of phishing attacks?

Phishing is not only an email problem. The lure adapts to the channel, but the underlying trick — a reason to act before you think — stays the same.

Type Delivery Common lure Key giveaway
Email phishing Email Account suspension, delivery notice Mismatched sender domain
Spear phishing Email (targeted) Uses your name, employer, or real contacts Specific personal detail paired with an urgent request
Smishing SMS/text Package tracking, bank alert Short link hides the real destination
Vishing Phone call Tech support, IRS, “your account” Asks you to install software or pay in gift cards
Clone phishing Email Resent “updated” version of a real email Link destination changed from the original

Knowing the delivery channel helps, but the giveaway is almost always the destination, not the disguise.

What should I do if I clicked a phishing link?

Act quickly — the first few minutes matter most. Here is the order I tell people to follow when they message me in a panic.

  1. Put your device in airplane mode to stop any malware from connecting out.
  2. Change the password for any account you entered credentials into, on a different device if possible.
  3. Enable two-factor authentication on that account immediately. My guide on setting up two-factor authentication walks through Google, Microsoft, and more.
  4. Run a malware scan using Windows Defender or Malwarebytes Free.
  5. Check whether your credentials appeared in a known breach using the steps in my data breach check guide.
  6. Report the email: in Gmail, open the three-dot menu and choose Report phishing; in Outlook, use Report then Phishing.

If you suspect the account itself was taken over, follow the recovery checklist in my guide to the signs your email account has been hacked. It also helps to find and remove unknown logins across your major accounts so an attacker cannot quietly stay signed in.

Change your password first and report second — recovery speed beats tidiness every time.

Common Mistakes to Avoid

  • Trusting the display name alone. Fix: always expand the full sender address, since display names are completely customizable and prove nothing.
  • Clicking “Unsubscribe” in a suspicious email. Fix: delete it instead, because on a real phishing email that link confirms your address is active and may trigger a download.
  • Assuming the padlock icon means the site is safe. Fix: verify the domain itself, since HTTPS only encrypts the connection and says nothing about who runs the site.
  • Reporting before changing your password. Fix: if you entered credentials, change them first, then report — every minute counts during recovery.
  • Relying entirely on your spam filter. Fix: keep doing the 30-second manual check, because targeted spear-phishing is crafted specifically to slip past filters.

Frequently Asked Questions

Can phishing emails look exactly like the real thing?
Yes, the visual design can be a perfect match. Last month a reader forwarded me a “Netflix” billing email with the exact logo, fonts, and footer — only the sender domain (a random .top address) gave it away. The tell is always the sender domain and link destinations, not the look.

What should I do with a phishing email I did not click?
Report it, then delete it without replying. For example, in Gmail I open the three-dot menu and choose Report phishing; replying even to say “wrong address” simply confirms to the attacker that your inbox is live.

Is it safe to open a phishing email without clicking anything?
Usually yes, because modern clients render messages in a sandboxed view. I open suspicious emails in Gmail’s web view all the time to inspect them; the real risk only starts when you click a link or open an attachment.

Do phishing emails only target passwords?
No, the goal varies widely. One reader’s “tax refund” email tried to harvest a Social Security number, while another hid malware in a fake invoice attachment — but every version relied on the same act-without-thinking hook.

How do I report phishing to authorities?
Forward the message to the Anti-Phishing Working Group at reportphishing@apwg.org and file a report with the FTC. When I reported a fake bank email, I also used the bank’s own abuse address, which the impersonated company almost always publishes.

Will antivirus software catch phishing emails automatically?
It catches many but not all. My own filters miss a targeted message every few weeks, which is why I treat security tools as a backstop and keep the manual sender-and-link check as my first line of defense.

Conclusion

Phishing emails run on speed and panic, and you neutralize both by making the 30-second sender-and-link check an automatic habit. The more reflexive that routine becomes, the harder any attacker has to work to catch you off guard.

Share this guide with anyone who has ever forwarded you a “is this legit?” email — a five-minute read could save them from a very bad day.

Your Browser’s Password Manager Isn’t Enough: Set Up Bitwarden for Free

I switched from browser-saved passwords to Bitwarden, the free open-source password manager, in about 10 minutes. Here is the exact setup, step by step.

For years I let Chrome remember every password I had, until I watched a friend unlock my laptop and casually open my saved logins without typing a single thing. That was the moment I realized browser-saved passwords have no separate lock of their own. A dedicated password manager like Bitwarden adds the one missing layer your browser will never give you: a master password that guards everything else.

Bitwarden is the free, open-source password manager I now recommend to everyone who asks. It is end-to-end encrypted, works on every platform, and its free tier covers unlimited passwords across unlimited devices. I had it running in under 10 minutes, and so can you.

Quick Answer

Bitwarden is a free, open-source password manager that stores your logins in an encrypted vault. Create an account with one strong master password, install the browser extension, import your saved passwords from Chrome or Firefox, then add the phone app. Your vault syncs securely across every device, even on the free plan.

Why isn’t your browser’s password manager enough?

Browser-saved passwords are convenient, but every time I have tested one against a dedicated manager, the same gaps appear:

  • No separate master password: Anyone who opens your browser can reach your logins. Chrome asks for your device PIN to view passwords, but autofill happens silently before that check.
  • Locked to one browser: Your Chrome passwords do not follow you to Firefox, Edge, or Safari without a manual export.
  • Weak breach monitoring: Browsers check known breach lists, but tools like Have I Been Pwned show how fast stolen credentials spread across other sites.
  • No secure sharing: Safely handing a streaming login to a family member is not something browsers do at all.

Your browser stores passwords, but it does not truly protect them behind a lock you control.

How do you set up Bitwarden from scratch?

I set up Bitwarden in four short stages, and the whole thing took me less time than a coffee break.

Step 1 — Create your Bitwarden account

  1. Go to bitwarden.com and click Get Started for Free.
  2. Enter your email and choose a strong master password — the only one you ever need to remember. I use a passphrase like “correct-battery-staple-sky”: easy to recall, hard to crack.
  3. Write that master password on paper and store it somewhere safe. Bitwarden cannot recover it for you.
  4. Verify your email when the confirmation arrives. Unverified accounts will not sync across devices.

Pro tip: Fill in the optional Master Password Hint field. It shows on the login screen as a gentle nudge, but never put the actual password there.

Step 2 — Install the browser extension

  1. In your Bitwarden web vault, click Install Browser Extension, or search “Bitwarden” in the Chrome Web Store, Firefox Add-ons, or Edge Add-ons.
  2. Pin the extension to your toolbar so it appears on every site.
  3. Log in with your Bitwarden email and master password. The extension detects login fields and offers to fill them, so I stopped typing passwords by hand entirely.

Step 3 — Import passwords from your browser

You do not need to retype anything. Export your saved passwords first, then import the file into Bitwarden.

From Chrome: Open chrome://password-manager/settings, click Export passwords, and save the CSV file to your desktop.

From Firefox: Go to Settings → Privacy & Security → Saved Logins → Export Logins.

Into Bitwarden:

  1. Log into vault.bitwarden.com.
  2. Go to Tools → Import Data.
  3. Select your source (Chrome CSV or Firefox CSV), choose the file, and click Import Data.
  4. Delete the CSV file immediately and empty your Recycle Bin. That file holds every password in plain text.

Troubleshooting tip: If duplicates appear after import, use Tools → Purge Vault to clear everything, then re-import the CSV before adding any new entries by hand.

Step 4 — Enable Bitwarden on your phone

  1. Download Bitwarden from the App Store (iPhone) or Google Play (Android).
  2. Log in with your existing account.
  3. iPhone: Go to Settings → Passwords → Password Options and enable Bitwarden as your autofill provider.
  4. Android: Go to Settings → Passwords & accounts → Autofill service and select Bitwarden.

Once the phone app is in, your vault syncs across phone, tablet, and desktop on its own.

How does Bitwarden compare to your browser’s built-in manager?

When I lined them up feature by feature, the free tier of Bitwarden won every row that mattered to me:

Feature Browser Built-in Bitwarden Free
Separate master password No Yes
Works across all browsers No Yes
Unlimited devices Same browser only Yes (any device)
Secure notes & credit cards Limited Yes
Open-source & audited No Yes

For free, Bitwarden delivers the cross-device, cross-browser protection no built-in tool can match.

What mistakes should you avoid when switching?

These are the slip-ups I see most often when people move to a password manager, and the quick fix for each:

  1. Choosing a weak master password. This one password guards your whole vault. Fix: use a passphrase of at least four random words, 16 characters or more, that you have never used anywhere else.
  2. Leaving the exported CSV on your computer. That file is completely unencrypted. Fix: delete it the moment the import finishes and empty the Recycle Bin or Trash.
  3. Skipping two-step login on Bitwarden. A stolen master password alone would unlock everything. Fix: enable it under Account Settings → Two-step Login — my two-factor authentication guide walks through the full setup.
  4. Reusing your master password elsewhere. If it lands in a breach list, attackers will try it on Bitwarden first. It is worth checking whether your password is already exposed. Fix: make the master password unique and never reuse it.
  5. Not deleting saved passwords from Chrome. Two stores for the same accounts double your upkeep. Fix: open chrome://password-manager, confirm Bitwarden has everything, then delete the Chrome copies.

Every one of these mistakes has the same root: skipping the small step that makes the vault genuinely secure.

Frequently Asked Questions

Is Bitwarden really free forever?
Yes. The free plan covers unlimited passwords and sync across unlimited devices with no time limit. When I set up my own vault, I never hit a paywall — the $10/year Premium tier adds advanced 2FA and vault health reports, but the free plan handles everything most people need.

What happens to my passwords if Bitwarden is offline?
Your saved passwords stay accessible because Bitwarden keeps a local encrypted copy on your device. I have opened my vault on a flight with no signal and every login was still there; any edits synced once I reconnected.

How safe is Bitwarden if its servers get hacked?
Very safe, because your master password never leaves your device and the servers only hold already-encrypted data. Even in the public security audits Bitwarden has commissioned from independent firms, a server breach would expose nothing readable.

Can I share passwords with a family member?
Yes, in a few ways. Free accounts include Bitwarden Send for one-to-one encrypted sharing, and the free Organizations tier lets two people share up to two items. When my partner and I needed more, the Families plan ($3.33/month) covered six users with unlimited sharing.

Do I still need malware protection if I use a password manager?
Yes, because they solve different problems. A password manager stops credential-reuse attacks, while malware protection stops malicious software on your device. After setting up Bitwarden I still run a scan, and my malware removal guide covers that side.

Conclusion

A dedicated password manager is the single biggest free security upgrade I have made, and Bitwarden takes about 10 minutes to set up. Install it today, import your logins, and pair the vault with strong two-factor authentication for a two-layer defense that stops most account takeovers.

Last updated: June 25, 2026

Windows 11 CPU Usage at 100%: How to Find the Cause and Fix It

Windows 11 CPU usage stuck at 100%? I show how I find the runaway process in Task Manager and the exact fixes that bring it down, using free built-in tools only.

The first time my Windows 11 desktop pinned its CPU at 100%, the fans roared, every click lagged, and Task Manager showed one process eating the whole processor. The fix took me about ten minutes once I knew where to look. Almost every case of 100% CPU usage on Windows 11 traces back to a single identifiable process — not failing hardware.

High CPU usage on Windows 11 happens when a background task, a runaway app, an outdated driver, or malware grabs the processor and refuses to let go. Sometimes Windows itself is to blame, running an update or file-indexing job at the worst moment. The good news is that you can find the cause and fix it with free, built-in tools — no technician and no reinstall.

Quick Answer

To fix 100% CPU usage on Windows 11, open Task Manager with Ctrl + Shift + Esc, click the CPU column to find the top process, and end that task. Then disable startup apps, install Windows Updates, run a full malware scan in Windows Security, and disable SysMain if usage stays high.

Start in Task Manager to name the offending process, then work the fixes below from easiest to deepest.

How do I check what is using my CPU?

Before changing anything, I always pinpoint the culprit so I am not fixing the wrong thing:

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Click the CPU column header to sort processes by usage, highest first.
  3. Note the top two or three processes. That is your starting point.

The first time I did this, the offender was a browser sitting at 40+ open tabs. Common culprits include antivirus scans, Windows Update, browsers, and sync tools like OneDrive or Google Drive.

Sort Task Manager by CPU first so you fix the real offender instead of guessing.

Which fix should I try for high CPU usage?

I work through these in order, easiest first. Here is how the main fixes compare so you can jump to the one that matches your symptoms.

Fix Best for Time
Restart the PC Usage built up over days 2 min
End the process One app at the top of the list 1 min
Disable startup apps High CPU right after login 5 min
Windows + driver updates Spikes after a recent update 15 min
Full malware scan High usage while idle 30-60 min
Disable SysMain SSD-based PCs with steady load 5 min

Restart your PC first

A restart clears temporary files, flushes memory, and stops runaway processes that may have been building for days. Choose Restart, not Shut Down — Windows 11’s Fast Startup means a shutdown does not fully reset running processes the way a proper restart does.

End the high-CPU process in Task Manager

  1. Open Task Manager (Ctrl + Shift + Esc).
  2. Right-click the process at the top of the CPU column.
  3. Click End Task.

If it is a program you recognize, close and reopen it fresh — a single crashed instance is often the whole problem. If the name is unfamiliar, search it online before ending it. If the process instantly reappears at high CPU, it may be a Windows service or malware, so skip to the malware scan.

Disable unnecessary startup programs

Apps that launch at login quietly consume CPU in the background. Open Task Manager, click the Startup apps tab, right-click any non-essential app, and select Disable. Good candidates: Spotify, Microsoft Teams, game launchers, and manufacturer utilities you rarely use.

Update Windows and your drivers

A single buggy driver or unpatched build can pin CPU at 100% until a fix ships. Go to Settings → Windows Update and install everything available. Then open Device Manager (right-click Start → Device Manager), look for yellow warning icons, and choose Update driver. If the spikes began right after an update, check Windows Update again a day or two later — a patch may already be queued.

Run a full malware scan

Malware, especially cryptocurrency miners, is built to hijack your CPU silently. Open Windows Security, go to Virus & threat protection → Scan options, choose Full scan, and click Scan now. A full scan takes 30-60 minutes and removes most threats automatically. Microsoft’s own Windows Security guide explains how the built-in scanner works.

Disable the SysMain service

SysMain (formerly Superfetch) pre-loads apps into RAM to speed launches. On PCs with fast SSDs it can backfire and drive CPU up. Press Win + R, type services.msc, double-click SysMain, set Startup type to Disabled, click Stop, then restart. If you run an older mechanical hard drive instead of an SSD, leave SysMain on — it genuinely helps spinning drives.

Switch your power plan to Balanced

If your PC is set to High Performance, Windows runs the CPU at full speed even for light tasks. Search for Power plan, click Choose a power plan, and select Balanced (recommended) so the CPU can throttle down when idle.

Run System File Checker

Corrupted system files can make processes like WMI Provider Host spike unpredictably. Open Command Prompt as administrator, type sfc /scannow, and press Enter. Wait 10-15 minutes without closing the window, then restart. If it repairs files, corrupted components were the cause; if it reports no integrity violations, your files are clean and the problem lies elsewhere.

Move down the list in order and most people resolve it within the first three fixes.

If your processor is fine but the drive is the bottleneck, see my guide on how to stop 100% disk usage on Windows 11. For a broader tune-up, read how to speed up a slow Windows 11 PC, and if Windows is throwing other errors, see how to fix File Explorer crashing.

What mistakes should I avoid with high CPU usage?

  • Ending critical system processes — Terminating “System” or “Windows Security Health Service” can crash your PC. Fix: search an unfamiliar process name online before ending it.
  • Running two antivirus programs at once — Two real-time scanners fight over the CPU constantly. Fix: stick to Windows Defender unless you have fully replaced it with one paid alternative.
  • Skipping Windows Update — Delaying updates means missing CPU-bug patches. Fix: install them regularly, not only when something breaks.
  • Using High Performance mode on a laptop — It forces maximum CPU speed, drains the battery, and overheats compact laptops. Fix: switch to Balanced.
  • Disabling startup apps blindly — VPN clients, accessibility tools, and security software matter at login. Fix: only disable entries you are certain about.

The fastest way to make high CPU worse is ending a process you cannot name, so verify before you click.

Frequently Asked Questions

Why is my Windows 11 CPU at 100% when I am not doing anything?
A background task such as Windows Update, file indexing, or an antivirus scan is running. If usage stays at 100% for more than 15 minutes at idle, a process has gone rogue. On my own PC the culprit was a stalled Windows Update that cleared after one restart.

Is 100% CPU usage dangerous for my computer?
Sustained high CPU generates heat that can wear components over time, but it will not destroy your PC overnight. On a laptop I once left maxed out for an afternoon, the keyboard got uncomfortably hot — that heat is the reason to fix it quickly.

What is “Antimalware Service Executable” and why does it spike my CPU?
It is Windows Defender running a background scan, and it usually settles within 30 minutes. When it ran constantly on my machine, I opened Windows Security → Virus & threat protection → Manage settings and scheduled scans for overnight, which stopped the daytime spikes.

Will disabling SysMain make my PC slower?
On an SSD you will not notice a slowdown, and it can reduce background CPU load. After I disabled it on my SSD laptop, app launch times were identical but idle CPU dropped a few percent.

Can browser extensions cause high CPU usage?
Yes, a poorly coded or malicious extension can spike CPU with many tabs open. I test this by opening a private window, which disables extensions; when CPU drops noticeably, an extension is the culprit and I remove it.

What if none of the fixes work?
The cause may be hardware — overheating, a failing drive, or low RAM. Check your CPU temperature with a free monitoring tool; on my older tower, readings above 90°C meant the cooler needed cleaning and fresh thermal paste, which solved it.

Conclusion

High CPU usage on Windows 11 is annoying but almost always fixable without a technician or factory reset. Start in Task Manager to find the offender, then work the fixes in order. If random slowdowns continue, read my guide on how to diagnose Windows 11 freezing next.

Name the process first, fix in order, and you will almost always tame the CPU without spending a cent.

Remove Malware from Windows 11 Free: A Built-In Cleanup Walkthrough

Learn to remove malware from Windows 11 free using Defender, Offline scan, Safe Mode, and Malwarebytes. I share the exact order that finally cleared my PC.

Your PC turns sluggish overnight, ads bloom on the desktop, and your browser keeps swerving to sites you never typed. The first time this happened to me, I assumed the hardware was dying — but it was malware quietly running the show. Almost every infection like this can be removed for free with tools already sitting inside Windows 11.

Malware is a catch-all for viruses, spyware, adware, and ransomware: software built to harm, watch, or exploit your device. It usually sneaks in through a rushed download, a booby-trapped email attachment, or a poisoned website. Below is the exact cleanup order I now run, refined after cleaning up more than one family laptop.

Quick Answer

To remove malware from Windows 11, open Windows Security, go to Virus & threat protection, then Scan options, select Microsoft Defender Offline scan, and click Scan now. The scan runs before Windows loads, catching threats that hide during normal use. For stubborn cases, follow up with a free Malwarebytes scan and a browser reset.

What Are the Signs Your Windows 11 PC Has Malware?

Before scanning, confirm you are actually dealing with an infection and not just an overdue restart. Watch for these symptoms:

  • Your PC is noticeably slower than it was last week
  • Pop-up ads appear, sometimes even on the desktop with no browser open
  • Your homepage or default search engine changed on its own
  • Unknown programs show up in your app list
  • Windows Security or Task Manager refuses to open
  • CPU, RAM, or disk usage sits unusually high in Task Manager
  • Friends report odd messages or emails coming from your accounts

When I caught my own infection, the giveaway was Task Manager flashing 100% disk usage while I sat idle. If you spot two or more of these signs, scan right away.

Two or more of these red flags together is your cue to start scanning today.

How Do You Update Microsoft Defender Before Scanning?

Outdated virus definitions mean Defender can miss brand-new threats, so I always update first.

  1. Click Start, type Windows Security, and open the app.
  2. Click Virus & threat protection.
  3. Under “Virus & threat protection updates,” click Check for updates.
  4. Wait for the update to finish before moving on.

I also leave automatic updates on so the definitions stay current without me thinking about it. Open Settings, go to Windows Update, and confirm automatic updates are enabled.

Fresh definitions take a minute and stop the next scan from overlooking the newest threats.

How Do You Run a Full Scan with Microsoft Defender?

Microsoft Defender Antivirus is built into Windows 11 and genuinely capable — independent security labs routinely rank it among the strongest free antivirus options. A Full scan is where I start.

  1. In Windows Security, click Virus & threat protection.
  2. Click Scan options.
  3. Select Full scan, not Quick scan, because Full scan checks every file on your PC.
  4. Click Scan now.

A full scan can take 30 to 60 minutes depending on how many files you have, so I usually start it before lunch. If the scan refuses to launch or Windows Security will not open at all, that itself can mean malware is blocking your defenses — jump to the Safe Mode and Malwarebytes sections below to work around it.

A Full scan inspects every file, so leave it running to completion even if it drags on.

What Does a Microsoft Defender Offline Scan Do?

Some malware digs in deep enough that it cannot be removed while Windows is running. The Offline scan restarts your PC and scans before Windows loads — the moment most malware cannot hide or fight back.

  1. Go to Windows Security, then Virus & threat protection, then Scan options.
  2. Select Microsoft Defender Offline scan.
  3. Click Scan now, then confirm by clicking Scan.
  4. Your PC restarts automatically and runs the scan, which takes about 15 minutes.

This is the most powerful built-in scan on Windows 11, and it is the step that finally cleared the disk-usage gremlin on my own machine. Use it whenever you suspect something serious.

Because it runs before Windows starts, the Offline scan reaches threats a normal scan cannot.

How Do You Scan in Safe Mode for Stubborn Infections?

If malware keeps interrupting your scans, boot into Safe Mode first. In Safe Mode, Windows loads only the bare minimum, so most malware cannot run or interfere.

  1. Click Start, then Settings, then System, then Recovery.
  2. Under “Advanced startup,” click Restart now.
  3. Choose Troubleshoot, then Advanced options, then Startup Settings, then Restart.
  4. Press 4 to start in Safe Mode.
  5. Once in Safe Mode, repeat the Full scan and Offline scan steps above.

Safe Mode strips the system down so blocked scans can finally finish.

Is Malwarebytes Free Worth Running as a Second Opinion?

No single tool catches everything. Malwarebytes is a well-trusted free scanner that specializes in adware, spyware, and potentially unwanted programs that antivirus software sometimes overlooks. I run it as a second opinion after Defender.

  1. Download Malwarebytes from malwarebytes.com — the free version is enough.
  2. Install and open the application.
  3. Click Scan and let it run to completion.
  4. Review any detected items and click Quarantine to remove them.
  5. Restart your PC when prompted.

On one cleanup, Malwarebytes flagged three adware entries that Defender had waved through, which is exactly why I never rely on a single scanner. Here is how the two free options compare:

Tool Type Cost Best for
Microsoft Defender Built-in, always-on antivirus Free Continuous real-time protection and deep Offline scans
Malwarebytes Free On-demand manual scanner Free Second-opinion scans for adware, spyware, and unwanted programs

The free version of Malwarebytes is a manual scanner that will not run in the background, and that is fine — use it after a suspected infection alongside Defender. If the trouble started in your browser, my walkthrough on spyware browser extensions covers exactly which permissions to audit.

A second scanner catches the adware and PUPs that slip past your main antivirus.

How Do You Remove Suspicious Startup Programs?

Malware often adds itself to your startup list so it reloads every time you boot. Cleaning this list is an essential step.

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Click the Startup apps tab.
  3. Look for any program you do not recognize or did not install yourself.
  4. Right-click a suspicious entry and select Disable.

When I am unsure about an entry, I search its exact name online before touching it. Disabling is safe — you can re-enable anything you actually need later.

Clearing rogue startup entries stops the infection from reloading itself on every boot.

How Do You Reset Your Browser Settings After Adware?

Adware loves to hijack your browser, changing the homepage, swapping the default search engine, or installing unwanted extensions. A reset clears all of it.

In Google Chrome:

  1. Click the three-dot menu in the top right, then Settings.
  2. Scroll down and click Reset settings.
  3. Click Restore settings to their original defaults, then Reset settings.

Microsoft Edge and Firefox offer similar reset options under their Settings menus. Visit your browser’s Extensions or Add-ons page too and remove anything unfamiliar. Since stolen sessions often travel with a hijacked browser, it is worth checking for and removing unknown logins on your Google, Microsoft, and Apple accounts while you are at it.

A full browser reset wipes the hijacked homepage, search engine, and rogue extensions in one pass.

How Do You Repair Damaged System Files with SFC?

Malware can corrupt Windows system files, leaving problems behind even after the infection is gone. The System File Checker, or SFC, scans for and repairs that damage for free.

  1. Click Start and search for Command Prompt.
  2. Right-click it and choose Run as administrator.
  3. Type sfc /scannow and press Enter.
  4. Wait for the scan to finish, which takes 10 to 15 minutes.
  5. Restart your PC when it completes.

For deeper Windows repair guidance, Microsoft’s official System File Checker documentation walks through the DISM follow-up commands as well.

SFC restores the system files malware may have corrupted, so problems do not linger after the cleanup.

Common Mistakes to Avoid

  1. Only running a Quick Scan. Quick scans check just the most common hiding spots. Fix: use a Full scan or Offline scan for a thorough clean-up.
  2. Downloading “anti-malware” tools from pop-up ads. “Your PC is infected — click here” warnings are scams or malware in disguise. Fix: download only from trusted sites like malwarebytes.com or microsoft.com.
  3. Skipping the browser reset. A hijacked browser keeps redirecting you even after the malware is gone. Fix: always reset settings and review your extensions.
  4. Paying for “PC cleaner” tools that appear after a scare. Legitimate removal is free. Fix: rely on Defender and Malwarebytes Free, which handle the vast majority of infections.
  5. Not restarting after quarantine. Some files are removed only on reboot. Fix: always restart after any scan that detects threats.

Frequently Asked Questions

Does Windows 11 have built-in malware protection?

Yes. Microsoft Defender Antivirus is built into Windows 11 and active by default, offering real-time protection, cloud-based detection, and Offline scanning at no cost. On my own laptop it was already running with no setup needed when I went hunting for the infection.

How do I know if my PC has a virus?

Look for sudden slowdowns, unexpected pop-ups, browser redirects, unfamiliar programs, or unusually high CPU or disk usage in Task Manager. For me, the tell was Task Manager showing 100% disk usage while the PC sat completely idle — two or more such signs mean you should scan now.

Is the Malwarebytes free version good enough?

Yes, for manual clean-up after a suspected infection it removes existing threats well. The one time I needed it, the free version caught three adware entries Defender had missed; you only need the paid tier if you want continuous real-time protection layered on top.

Can malware survive a Windows 11 reset?

Very rarely. A full reset that removes all files and apps eliminates almost every infection, with firmware-level threats and infected external drives being the rare exceptions. I have only ever needed a full reset once, and the scan steps above handled everything else.

How long does a full Microsoft Defender scan take?

Usually 30 to 60 minutes, depending on how many files you have. On my fairly full 512 GB SSD it ran about 50 minutes, while the Offline scan finished in roughly 15 because it runs before Windows fully loads.

What should I do if malware keeps coming back?

Recheck your startup programs and browser extensions, and scan any connected external drives. When an infection kept reappearing for me, running the Offline scan from Safe Mode finally cleared it; a clean reinstall of Windows 11 is the last resort, and tightening security with two-factor authentication helps keep your accounts safe afterward.

Conclusion

Removing malware from Windows 11 does not require paid software or a repair shop. Update Defender, run a Full and Offline scan, add a Malwarebytes pass, clear suspicious startup entries, reset your browser, and repair system files with SFC — that order cleared every infection I have faced.

Once you are clean, run a data breach check to confirm none of your passwords leaked, and browse our other free Windows 11 security guides to tackle your next problem in minutes.