Browser Push Notification Scams Are on the Rise
Browser Push Notification Scams Are on the Rise
A recent alert from the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) warns that cybercriminals are increasingly abusing browser push notifications to deliver fake virus warnings, security alerts and technical support scams. While browser notifications are a legitimate feature used by websites and web applications to deliver timely updates, attackers are exploiting them to trick users into believing their devices have been compromised.
These scams often begin when a user unknowingly grants a website permission to send browser notifications. Once permission is granted, the site can deliver convincing pop-up messages that resemble legitimate antivirus warnings or operating system alerts. The notifications may claim your computer is infected, your subscription has expired or immediate action is required.
Unlike traditional malware, the notification itself cannot infect your computer or steal your information. The real danger occurs when users click the notification or call a phone number included in the message. Victims may be redirected to malicious websites that attempt to install malware, steal passwords or financial information, or persuade them to grant remote access to their devices.
One of the easiest ways to identify a fake browser notification is to check its true source. Cybercriminals are skilled at making pop-up warnings look like legitimate Windows, macOS or antivirus alerts, so don't rely on the logo or message alone. Instead, focus on the notification's source by looking for:
The most effective way to protect yourself from browser notification scams is to disable browser notification requests altogether. If you don't rely on browser notifications, turning them off prevents websites from asking for permission and significantly reduces your risk of receiving fraudulent alerts.
If you clicked a suspicious notification or entered passwords, financial information or other sensitive data on a fraudulent website, act immediately. Change your passwords, enable multi-factor authentication (MFA), monitor your accounts for unauthorized activity and contact your bank or credit card provider if financial information was shared.
If you believe your Seton Hall account has been compromised, contact the Technology Service Desk immediately. You should also report the incident to the NJCCIC and the FBI's Internet Crime Complaint Center (IC3) to help track cybercrime trends and prevent future attacks.
Categories: Science and Technology
Related Stories
Cybersecurity
Ransomware attack on Health Sciences Centre affects doors, ventilation and air
1 week ago
Cybersecurity
Did Iran hack water systems in seven US states?
2 weeks ago
Cybersecurity
Cyberattacks on water systems are growing in the U.S.
2 weeks ago
Cybersecurity
Cyprus startups urged to prioritise cybersecurity before expansion
1 month ago
Cybersecurity
Leeds
1 month ago
Cybersecurity
Trump uses address to lay out litany of election integrity claims
1 month ago
Cybersecurity
'I'm dying laughing'
1 month ago
Cybersecurity
Federal agency touts operation of cybersecurity sensors across the North
1 month ago