01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

Beware this fake Windows 11 update: a warning for Lichfield businesses

A fake Windows 11 update page is doing the rounds, and it looks almost identical to the real thing. Here is how it works and the one habit that keeps your Staffordshire team safe.

Andy Price · Founder3 August 2026 · 5 min read

There is a fake Windows 11 update doing the rounds that looks almost identical to the real thing. A page built to look like an official Microsoft support site offers you a normal-looking update for Windows 11. Click the button and you are not installing an update, you are installing malware. The rule that keeps you safe is simple: real Windows updates never come from a website. They come through Windows Update, inside Settings, and nowhere else.

Hi, I am Andy from Initial IT in Lichfield. We look after cyber security for small businesses across Staffordshire and the West Midlands, and this one worries me precisely because it targets a habit we all have: clicking through updates without a second thought. Here is how it works and how to stay ahead of it.

Key takeaways

  • The fake page copies an official Microsoft support site, right down to the layout and language. At a glance there is nothing obvious that gives it away.
  • The download is malware, built and packaged with legitimate developer tools, so even security software can struggle to flag it straight away.
  • Real Windows 11 updates never arrive through a web page, pop-up or email link. They come through Windows Update in Settings, full stop.
  • The safer habit for your team: if anything outside Settings offers you an update, close it and check Settings, then Windows Update, directly.
  • Attacks have evolved. The scruffy fake update is gone; the new ones blend into trusted routines, and that is exactly what makes them dangerous.

What is the fake Windows 11 update scam, and why is it so convincing?

You probably do not think twice when you see a Windows update. A quick click, a short wait, job done. Updates are there to protect your system, so the whole process feels safe by default. That is exactly why this scam is catching people out.

The scam page presents what appears to be a normal update for Windows 11 and invites you to download it. The design, wording and layout are close enough to Microsoft’s own that busy people click without hesitating. Someone on your team sees the prompt, installs it, and carries on with their day. That habit is normally fine. When attackers start mimicking trusted processes, that same habit becomes the way in.

Why does security software not catch it straight away?

This is not a rough, badly put-together scam. The file is built using legitimate tools that developers use every day, and it is packaged with familiar labels and properties that suggest it comes from Microsoft. On the surface, everything checks out, which is why even good security software can take time to flag it.

In the past, fake updates were easier to spot. The designs were poor, the wording was odd, something always felt off. Now they are designed to blend in. That is the shift worth explaining to your team: the absence of obvious warning signs is no longer evidence that something is safe.

What should you and your team do instead?

Keep updates inside Windows. If you want to check whether your PC needs one, go to Settings, then Windows Update, and check there. If an update is genuinely available, that is where it will be. The same goes for your business apps: update from the app itself or the vendor’s own update mechanism, never from a link that arrived by email or a page that appeared mid-browse.

Better still, take the decision away from busy people. On a properly managed Microsoft 365 setup, updates are controlled and rolled out centrally, so nobody on the team ever needs to fetch one themselves. The National Cyber Security Centre also has clear, free guidance on spotting and reporting fake pages like this.

How do Staffordshire businesses build the habit that stops this?

You do not want a paranoid team. You want a team that knows one simple rule and a culture where checking takes thirty seconds and nobody feels silly for asking. The more normal something looks, the less likely people are to question it, and attackers are counting on that.

You will not block every scam page, but you can stack the odds in your favour: managed updates so nobody downloads them by hand, strong email and web filtering, multi-factor authentication so one mistake is not a disaster, and short, regular awareness training. That mix is what we set up through our cyber security and IT support for firms across Lichfield and the West Midlands.

Quick check: where does your business stand on cyber security?

The questions in our free 2-minute Cyber Security Health Check are the eleven we ask every new client first. Score yourself, see the per-category breakdown, and get the three highest-impact fixes for your specific gaps. No marketing list.

Take the 2-minute Cyber Health Check

If you are not completely confident your team would spot something like this, that is worth fixing before it is tested for real. We would far rather have a quiet word now than a difficult one later.

Frequently asked questions

How do I tell a real Windows 11 update from a fake one?

Location is the giveaway, not looks. A real update only ever appears in Settings, under Windows Update. Anything offering an update from a web page, a pop-up, or an email link is fake, no matter how official it appears. Close it and check Settings directly.

Will our antivirus stop it if someone clicks the download?

Maybe, but do not rely on it. The file is built with legitimate developer tools and packaged to look genuine, so security software can take time to flag it. Prevention beats detection here: the habit of only updating through Windows Update costs nothing and works every time.

What should we do if someone thinks they have installed one?

Act quickly and do not tidy up quietly. Disconnect the machine from the network, leave it switched on, and call your IT support provider straight away. Change the passwords for anything used on that machine from a different device, starting with email. Speed matters far more than blame.

How do we stop fake update pages reaching the team at all?

Centrally managed updates are the biggest single fix, because nobody ever needs to download an update by hand again. Add web filtering, multi-factor authentication and short awareness sessions, and the odds swing heavily in your favour. That is the setup we run for businesses across Lichfield and the West Midlands.

– Andy Price, Founder & MD, Initial IT · 01543 524 594 · hello@initialit.co.uk

Related reading

Read nextHow Much Does Managed IT Support Cost in the UK?Read nextIn-House IT vs Outsourced MSP: Which Is Right for a UK SMB?Read nextFrom freelancer to MSP: how to switch IT providers without downtime