Browser Push Notification Scams Are on the Rise

A recent alert from the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) warns that cybercriminals are increasingly abusing browser push notifications to
deliver fake virus warnings, security alerts and technical support scams. While browser
notifications are a legitimate feature used by websites and web applications to deliver
timely updates, attackers are exploiting them to trick users into believing their
devices have been compromised.
These scams often begin when a user unknowingly grants a website permission to send
browser notifications. Once permission is granted, the site can deliver convincing
pop-up messages that resemble legitimate antivirus warnings or operating system alerts.
The notifications may claim your computer is infected, your subscription has expired
or immediate action is required.
Unlike traditional malware, the notification itself cannot infect your computer or
steal your information. The real danger occurs when users click the notification or
call a phone number included in the message. Victims may be redirected to malicious
websites that attempt to install malware, steal passwords or financial information,
or persuade them to grant remote access to their devices.
Spot the Scam Before You Click
One of the easiest ways to identify a fake browser notification is to check its truelike legitimate
Windows, macOS or antivirus alerts, so don’t rely on the logo or message alone. Instead,
focus on the notification’s
- The browser icon. If the notification displays a Google Chrome, Microsoft Edge, Mozilla Firefox or
Safari icon, it originated from a website, not your operating system or antivirus
software. - The website domain. Browser notifications display the website that sent the message. If the notification
claims your computer is infected but the source is an unfamiliar website, it’s a scam.
A website cannot scan your computer for viruses or determine whether your device has
been compromised.
Disable Browser Notifications
The most effective way to protect yourself from browser notification scams is to disable
browser notification requests altogether. If you don’t rely on browser notifications,
turning them off prevents websites from asking for permission and significantly reduces
your risk of receiving fraudulent alerts
- Open Chrome and select Settings.
- Go to Privacy and security > Site Settings > Notifications.
- Select Don’t allow sites to send notifications.
Microsoft Edge
- Open Microsoft Edge and select Settings.
- Go to Privacy, search, and services > Site permissions > Notifications.
- Turn off Ask before sending (or Sites can ask to send notifications) to block all
website notification requests.
Protect Yourself and the University
If you clicked a suspicious notification or entered passwords, financial information
or other sensitive data on a fraudulent website, act immediately. Change your passwords,
enable multi-factor authentication (MFA), monitor your accounts for unauthorized activity
and contact your bank or credit card provider if financial information was shared
If you believe your Seton Hall account has been compromised, contact the Technology Service Desk immediately. You should also report the incident to the NJCCIC and the FBI’s Internet Crime Complaint Center (IC3) to help track cybercrime trends and prevent future attacks
Categories:
Science and Technology

