Millions tricked by fake browser lock screens as Cypher Loc scam spreads through clever phishing emails and hidden web traps | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
New 'scareware' attack hits 2.8 million victims, pretending to lock them out of your browser — here’s how you can stay safe
Cypher Loc scam turns harmless web pages into panic machines
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Cypher Loc tricks users into believing their browser is completely locked
Fake support numbers lead victims straight into identity theft traps
Phishing emails remain the main entry point for the scam
A massive wave of digital deception has swept across the internet since early 2026, catching millions off guard with a clever browser trick.
Security researchers at Barracuda have warned how a strain called Cypher Loc has targeted roughly 2.8 million people through phishing and psychological manipulation.
Unlike traditional malware that actually damages files or systems, this attack relies entirely on making users believe they have lost control of their own machines.
'What begins as a phone call from 'IT support' ends with a fully instrumented network compromise': This fake tech support scam tricks employees into infecting their own company devices
Watch out Microsoft Teams users - hackers are spreading a dangerous new phishing scam, here's what we know
New cyber scam abuses Microsoft Teams to steal your data
The process typically commences with a phishing email which contains either a malicious link or an infected attachment.
Clicking this link directs the user to what first appears as a completely harmless webpage, though this calm is merely a disguise.
Barracuda associate threat analyst Megharaj Balaraddi notes that the scareware activates only under certain conditions, like when a system lacks proper security scanning tools.
This activation allows the attack to evade standard detection methods while keeping the malicious page hidden from automated security checks.
Once activated, the browser transforms into what feels like a digital prison with no obvious escape route.
The attack forces full-screen mode, disables standard context menus, hides the cursor, and blankets everything with alarming security messages.
A fraudulent support phone number appears prominently on the screen as the supposed only solution to this manufactured crisis.
'Cybercriminals are industrializing deception': new report reveals how major global cybercrime syndicates have infiltrated trusted domains with millions now at risk - here's what you need to know
Experts reveal how fake CAPTCHAs are driving a global SMS scam campaign
Microsoft phishing threat report shows 146% surge in quishing
When users click anywhere or attempt to regain control, the browser emits warning sounds that further escalate their panic and confusion.
The attackers added several layers of emotional manipulation to make their scheme more convincing than older scareware variants, with Cypher Loc retrieving and displaying the victim’s public IP address directly on the screen, a move designed to personalize the threat and intensify fear.
“Showing this IP address is a psychological tactic, made to make the warning feel personal and increase the sense of urgency,” Balaraddi explains in his analysis of the campaign.
When frightened victims finally call the displayed number, human operators posing as Microsoft support staff take over the conversation.
From this point, the scammers can extract banking details, passwords, payment information, or any other sensitive data they wish to obtain.
To stay safe, users must exercise extreme caution when checking their inboxes, social media feeds, or any text messages arriving from unknown senders.
Cypher Loc campaign succeeds primarily because it preys on human fear rather than any sophisticated technical breach of your actual system - so messages that invoke a strong sense of urgency should raise immediate suspicion, as scammers deliberately pressure you to click or call without thinking clearly.
Avoid clicking on links or downloading attachments from people you do not know personally and trust completely.
Installing reliable antivirus software provides a critical layer of defense against many threats, including scareware that tries to exploit browser vulnerabilities.
Some identity theft protection services also include antivirus tools, offering multiple security layers within a single subscription for those seeking extra protection.
Legitimate security alerts never lock your browser, do not display phone numbers for you to call, and never demand immediate action through pop-up windows.
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a Ph D in sciences, which provided him with a solid foundation in analytical thinking.
You must confirm your public display name before commenting
1 Best Buy's video editing laptop and PC deals end in a matter of hours — and they're packed with DDR5 memory, and RTX 5060, 5070, and 5080 graphics cards that are perfect for content creators
2FBI warns of Kali phishing scam hitting Microsoft OAuth tokens — warns 'Kali 365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures'
3 How to quickly create and generate animation using Adobe Firefly
4 Amazon’s Memorial Day Lego sale is packed with Star Wars, Botanicals, Art, and Creator set deals – but it's ending soon
5 The Many Lives of Benjaman Kyle on HBO Max had Natalia Grace producer 'in tears' after man found naked behind Burger King with total amnesia couldn't remember past — 'I felt like I was never going to be normal again'
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



