The Fake Security Patch
- Richard Stocks
- Jul 21
- 2 min read
Flggd Scam School · Tech Support & Device Takeover · Lesson 12 of 12
An urgent email says a critical vulnerability affects your device and a security patch must be installed today. If an email says install security patch, the email itself is the threat.
The message looks like this

Why this is a scam
Real security updates never arrive as email downloads. Your phone, computer, and browser update themselves through built-in update settings; that's the only channel real patches use. Companies do not email patch files to customers, ever.
The technical dressing (CVE numbers, KB codes, "actively exploited") is copied from real security language to sound authentic. Scammers count on the jargon doing the convincing.
The download installs the opposite of a patch: malware that can watch your typing, steal saved passwords, or hold your files for ransom.
Red flags checklist
Any email, text, or popup offering a downloadable "patch" or "update".
Official-sounding codes used to impress rather than inform.
A deadline: "within 72 hours", "immediately", "today".
A download domain that isn't your device maker's real website.
Threats that unpatched systems "will be compromised".
The manipulation tactic
Authority through jargon. The message imitates the language of real security teams so precisely that compliance feels like good hygiene.
What to do, and what not to do
Never download updates from an email link. Delete the message.
Update the real way: your device's Settings, then Software Update; your apps through the app store.
Turn on automatic updates so real patches install themselves.
If you ran a "patch" file: disconnect from the internet, run a full antivirus scan, and change your key passwords from a clean device.
Report the email as phishing in your mail app.
Not sure about a message you've received? Check it in seconds with the free Flggd app.


