| Websites often ask for permission to send you “push notifications.” When used correctly, this feature is highly convenient. If you use a communication tool like Microsoft Teams or a news website in your browser, a small pop-up in the corner of your screen can alert you to a new message or breaking news, even if that specific window is minimized. Unfortunately, cybercriminals frequently abuse this same feature to launch deceptive scam campaigns. |
| The Illusion of Danger vs. Actual Threats |
| It is critical to understand how these scams operate. The most important takeaway is that seeing a scary pop-up notification does not mean your computer is infected. |
| When a malicious or compromised website tricks you into allowing notifications, it gains the ability to send text and images directly to your desktop. Scammers use this to create fake alerts that look identical to official anti-virus warnings, system errors, or security breaches. They may claim your machine is compromised, your subscription has expired, or urgent action is required. |
| At their mildest, these notifications are a nuisance; they flood your screen with unwanted advertisements and consume your computer’s memory (RAM), which can slow down your system. At their worst, they leverage fear to create a threat where none yet exists. |
| How the Trap Snares Users |
| The notification itself cannot harm your computer or steal your data. The danger only begins if you interact with it. |
| The goal of the scammer is to scare you into taking one of two actions: |
| Clicking the notification: When you click the alert, it opens your web browser and often directs you to a malicious website (or redirects you through a chain of hidden sites). Once there, the site uses aggressive scare tactics, such as fake progress bars, flashing red screens, or countdown timers to coerce and pressure you into clicking a link that downloads actual malware onto your device. Calling a phone number: The alert may provide a fake “IT Support” or “Help Desk” number. If you call, a scammer will use social engineering tactics to trick you into handing over passwords, financial information, or granting them remote access to your computer. |
| Spotting the Fake: Check the Source |
| Because scammers are highly skilled at making their alerts look like official Windows or Mac system warnings, you cannot rely on the logos or the text inside the pop-up to determine if it is real. Instead, look at the notification envelope. Every browser push notification must be displayed by the computer’s operating system with its true origin. |
| When an alert pops up in the corner of your screen, look closely at the very top or bottom edge of the notification box. You will see two telltale signs: |
| The Browser Icon: You will see a tiny icon for Google Chrome, Microsoft Edge, or Mozilla Firefox. A real anti-virus program or Windows system update will never appear inside a browser window or carry a browser logo. The Website Domain: You will see the exact web address (for example: best-cleaner-source[.]xyz or prizes-winner[.]net) that is sending the message. |
| If a concerning notification claims your computer is infected with 15 viruses, but the small print at the edge of the box says it is coming from an unfamiliar website address via “Google Chrome,” you are looking at a bluff. A website cannot scan your computer’s hard drive. |
| How to Protect Yourself |
| The most effective defense against this tactic is awareness. By recognizing that these pop-ups are website messages rather than actual system diagnoses, you eliminate the scammer’s primary weapon: panic. |
| If you are already receiving these disruptive alerts, you can easily stop them. You do not need expensive software to fix this; you simply need to revoke the website’s permission within your internet browser. |
| Whether you use Google Chrome, Microsoft Edge, Safari, or Mozilla Firefox, the process is straightforward: |
| Open Browser Settings: All Browsers. Click the three dots or lines in the top-right corner of your browser and select Settings. Navigate to Site Permissions: Privacy & Security. Look for a section labeled Privacy and Security or Cookies and Site Permissions, then click on Notifications. Review the Allowed List: Identify the Culprit. Scroll down to the “Allow” or “Allowed to send notifications” list. Look for any website names you do not recognize or that seem suspicious. Remove or Block: Stop the Alerts. Click the three dots next to the suspicious website and choose Remove or Block. This instantly revokes its ability to send pop-ups to your desktop. |
| Tip: To prevent this from happening in the future, you can go to your browser’s notification settings and toggle the option to “Don’t allow sites to send notifications.” This will stop websites from even asking for permission and, instead, block the scam at the front door. |