Skip to Content
Department of Information Technology

Browser Push Notification Scams Are on the Rise

Person using a laptop with a digital security warning icon displayed on the screen.A recent alert from the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) warns that cybercriminals are increasingly abusing browser push notifications to deliver fake virus warnings, security alerts and technical support scams. While browser notifications are a legitimate feature used by websites and web applications to deliver timely updates, attackers are exploiting them to trick users into believing their devices have been compromised.

These scams often begin when a user unknowingly grants a website permission to send browser notifications. Once permission is granted, the site can deliver convincing pop-up messages that resemble legitimate antivirus warnings or operating system alerts. The notifications may claim your computer is infected, your subscription has expired or immediate action is required.

Unlike traditional malware, the notification itself cannot infect your computer or steal your information. The real danger occurs when users click the notification or call a phone number included in the message. Victims may be redirected to malicious websites that attempt to install malware, steal passwords or financial information, or persuade them to grant remote access to their devices.

Spot the Scam Before You Click

One of the easiest ways to identify a fake browser notification is to check its true source. Cybercriminals are skilled at making pop-up warnings look like legitimate Windows, macOS or antivirus alerts, so don't rely on the logo or message alone. Instead, focus on the notification's source by looking for:

  • The browser icon. If the notification displays a Google Chrome, Microsoft Edge, Mozilla Firefox or Safari icon, it originated from a website, not your operating system or antivirus software.
  • The website domain. Browser notifications display the website that sent the message. If the notification claims your computer is infected but the source is an unfamiliar website, it's a scam. A website cannot scan your computer for viruses or determine whether your device has been compromised.

Disable Browser Notifications

The most effective way to protect yourself from browser notification scams is to disable browser notification requests altogether. If you don't rely on browser notifications, turning them off prevents websites from asking for permission and significantly reduces your risk of receiving fraudulent alerts.

Google Chrome

  1. Open Chrome and select Settings.  
  2. Go to Privacy and security > Site Settings > Notifications.  
  3. Select Don't allow sites to send notifications.  

Microsoft Edge

  1. Open Microsoft Edge and select Settings.
  2. Go to Privacy, search, and services > Site permissions > Notifications.
  3. Turn off Ask before sending (or Sites can ask to send notifications) to block all website notification requests.

Protect Yourself and the University

If you clicked a suspicious notification or entered passwords, financial information or other sensitive data on a fraudulent website, act immediately. Change your passwords, enable multi-factor authentication (MFA), monitor your accounts for unauthorized activity and contact your bank or credit card provider if financial information was shared.

If you believe your Seton Hall account has been compromised, contact the Technology Service Desk immediately. You should also report the incident to the NJCCIC and the FBI's Internet Crime Complaint Center (IC3) to help track cybercrime trends and prevent future attacks.

Categories: Science and Technology

For more information, please contact: