You know the text. Maybe not word for word, but you know the shape of it.
"Is this real?" A screenshot of an email that looks like it's from the bank. A link that showed up from a relative's number, except it doesn't quite sound like them. A pop-up saying the computer is infected, with a phone number to call right now.
Or the harder version, the one that comes after something already happened. Not "is this real," but "I think I did something." A gift card already purchased. A password already typed into a page that wasn't what it looked like. That one's harder because there's nothing left to catch. Just cleanup.
If you're the person who gets those messages, you already know the job. Nobody handed you a title. You fixed the Wi-Fi once, and now you're also the password recovery line, the "is this legit" hotline, and the one who has to explain, again, why the browser is doing that thing. You're your family's IT department, and the part of the job that actually keeps them safe, the security part, is the part nobody trained you for.
Here's how to actually cover it, including what to set up for your parents, what to install, and where a browser extension like Haven fits into all of it.
Why "just be careful" stopped being enough
For years, the standard advice held up reasonably well: check the sender's address, look for typos, don't click links from strangers. That advice made sense when phishing attempts were often rushed, generic, and a little clumsy, because they usually were.
They aren't anymore. IBM's X-Force security team ran an experiment comparing phishing emails written by their own red team against ones generated by an AI chatbot. Their researchers typically spend around 16 hours crafting a convincing phishing email by hand. With five prompts, they produced one just as convincing in about five minutes. The output wasn't a rough draft. It was polished, personalized, and built to sound exactly like whoever it was impersonating, a bank, a delivery service, a family member.
The financial impact of that shift is already visible in the data. The FBI's Internet Crime Complaint Center reported that adults 60 and older lost more than $7.7 billion to online scams in 2025, a 59 percent increase over the year before, driven in large part by investment fraud and increasingly convincing impersonation attempts. That's not a story about people being careless. It's a story about the signals everyone was trained to look for quietly disappearing at the exact moment attacks got cheaper and easier to produce at scale.
We've written before about the specific scam patterns this shows up as, the "grandchild in trouble" call, the fake bank alert, the tech support pop-up, and what to actually do if a parent has already sent money or shared account information. If you haven't seen that breakdown, it's worth a read: How to Protect Your Parents from Online Scams: A Practical Guide. This piece is less about spotting individual scams and more about the role you're already playing, and how to make the security part of that role sustainable.
Because teaching someone to be careful still matters. It's just no longer the whole plan.
The Part of the Job No One Prepared You For
Here's the actual job description, even though nobody wrote one. You reset the passwords nobody remembers. You talk someone through why the printer won't connect, again. You get the "is this real?" texts, and the harder ones that come after something's already happened.
You've also done the responsible things beyond that. Gotten them to install antivirus software. Sat down once and gone through what a scam email looks like. Forwarded an article about whatever the latest trick is. All of that is good. None of it is there for the one moment that actually decides the outcome.
That moment looks like this: an email shows up with the real logo, the right colors, a subject line about unusual account activity. Or a search for "Wells Fargo login" turns up a result that leads to a page built to look pixel-for-pixel like the real one. Nothing about it trips an antivirus scan, because nothing technically malicious has happened yet, just a link and a form waiting for a password. And the scam-awareness talk from three months ago doesn't help either, because this one looks more convincing than the examples you showed them.
That decision gets made in about two seconds. Click or don't. Type the password or don't. Download the file or don't. You can't be standing over their shoulder for it, and you shouldn't have to be, you have a job, a life, a phone that's sometimes in another room.
So the real question was never whether they know better. It's who, or what, is actually there in that exact second to help them decide.
How Haven protects you and your parents
Haven is a browser extension that checks links and websites for phishing before anyone lands on them. It runs automatically in the background of normal browsing, so it doesn't depend on your parent remembering to look something up, or knowing what a fake login page looks like compared to a real one. If a link leads somewhere designed to steal information, whether it arrived by text, email, or a search result, Haven flags it before the page finishes loading.
A few honest notes on what that does and doesn't cover:
It covers the link-based part of most scams. Fake bank pages, phishing emails, malicious sites, and look-alike login pages are squarely in scope. Phone call scams and in-person schemes aren't, since those don't route through a browser. That's still a job for the conversation and the safeguards below.
It's free for individual use. Each person installs it on their own browser, at no cost, with no account needed just to check a single link.
It's built for the exact moment described above. The second someone is rushed, unsure, or trusting, and about to click before thinking to check.
That's the actual value here. Fewer decisions depend entirely on someone catching their phone at the right second, including you. It's peace of mind on both ends of the relationship, not just theirs.
Setting it up for your parents
Install the extension on their browser. Add Haven to Chrome directly, either on their device or walking them through it on a call. It takes about as long as installing any browser extension.
Finish creating an account. The extension alone doesn't turn protection on. Haven needs an account signed in to actually check links and pages, so don't stop at "installed." Confirm the account setup is complete before considering the job done.
Do one test run together. Try Haven's link checker on a known-safe site and, separately, on an example of a suspicious link so they see what a flag actually looks like. Familiarity now means less panic later.
Set expectations, calmly. Let them know Haven will occasionally flag something, and that a flag is a "pause and check," not a malfunction or an accusation. The goal is for a warning to feel like a second opinion, not an alarm.
Check back periodically. Confirm every so often that the extension is still active and signed in, the same way you'd check in about anything else on their devices.
What Else to Set Up (With Actual Tools, Not Just Advice)
Use a password manager. 1Password and Bitwarden (which has a solid free tier) generate and store unique passwords per account, so one leaked password doesn't unlock everything else. Both offer family or shared plans, which also means you can help manage a parent's passwords without needing to know them yourself.
Turn on two-factor authentication. An authenticator app like Authy or Google Authenticator is stronger than a text message code, though a text code still beats having none at all. Prioritize email, banking, and anything tied to money.
Check for known data breaches. Have I Been Pwned is a free, well-established tool that tells you whether an email address has shown up in a known breach. It takes under a minute and tells you exactly which passwords need changing.
Turn on automatic updates, for both the browser and the operating system. Most fixes for newly discovered scams and exploits ship quietly through routine updates people tend to postpone.
Turn on transaction alerts through the bank or card issuer's own app. If something does go through, you find out in minutes instead of at the next statement.
Consider a robocall blocker like Nomorobo or a carrier-provided spam filter for the phone side of things. It won't stop every call, but it cuts down the volume of "tech support pop-up" style scams that start with a phone number, not a link.
Back up what matters. A cloud service like Backblaze, or the built-in options from Google or Apple, means a bad click involving ransomware or a wiped device costs frustration, not everything.
Set these up once, and most of them keep working without anyone thinking about them again, which is exactly the point.
The part that actually changes
Install Haven, get the passwords into a manager, turn on the alerts, and the plan becomes something sturdier than a person hoping to be free at the right moment. Less depends on a coincidence. More depends on something that was already there before the moment showed up.
You'll probably still get the text. "Is this real?" isn't going away, and honestly, it shouldn't. Family checking in on family is a good thing. It just stops being the only thing standing between them and a convincing fake, and neither of you has to carry that alone.
For the specific scam patterns to watch for, and exactly what to do if something's already happened, our guide on protecting your parents from online scams walks through that in detail. Consider this piece the setup. That one's the field guide.
