Learn to Identify and Eliminate Phishing Notifications

Email may be the most common form of phishing, but it’s not the only one. Modern Web browsers support a technology that enables websites to display system-level notifications just like regular apps. These push notifications have good uses, such as letting frequently updated websites inform users of new headlines, changed discussion threads, and more.

Unfortunately, push notifications can be subverted for malicious purposes, notably phishing. Here’s what happens. You visit a website that asks you if you’d like to receive notifications.

That request may be introduced with language that implies you must agree in order to get desired content, or it may be a bald-faced request to show notifications. If you agree, the website will be able to display alarming or deceptive phishing notifications even when it’s not open.

The goal is to trick you into clicking the notification, which will load a fake site that attempts to get you to enter login credentials or credit card information to facilitate identity theft.

The danger of phishing notifications is that they come from the system, so they may seem more legitimate than email messages trying to sucker you into revealing personal information. Nevertheless, as you can see in the examples above, they may still look sketchy in ways reminiscent of phishing emails:

  • No legitimate website would use emoji or symbols in a notification, much less multiple ones.
  • Although there are no glaring spelling or grammar mistakes, the use of all caps in the top notification is a giveaway. Similarly, standard notifications wouldn’t use exclamation points.
  • The use of “Click here” is poor information design that’s unlikely to come from a professional programmer or Web designer.

Phishing notifications, although problematic, aren’t a malware infection, and anti-malware packages won’t detect or remove them. Luckily, they’re easy to control and block in Safari and other Web browsers.

Prevent Phishing Notifications

The easy way to ensure you don’t see phishing notifications is to allow only trusted websites to send notifications. In general, we recommend keeping that list small so you’re not frequently interrupted by unnecessary notifications.

If you’re unsure that you’ll be able to identify malicious websites, you can enable a browser setting that prohibits all websites from asking for permission to send notifications. In Safari, choose Safari > Settings > Websites > Notifications, and deselect “Allow websites to ask for permission to send notifications” at the bottom.

Other browsers have similar options, and most will look like Google Chrome, as shown below:

  • Arc: Choose Arc > Settings > General > Notifications and select “Don’t allow sites to send notifications.”
  • Brave: Navigate to Brave > Settings > Privacy and Security > Site and Shield Settings > Notifications and select “Don’t allow sites to send notifications.”
  • Firefox: Go to Firefox > Settings > Privacy & Security > Notifications and select “Block new requests asking to allow notifications.”
  • Google Chrome: Navigate to Chrome > Settings > Privacy and Security > Site Settings > Notifications and select “Don’t allow sites to send notifications.”
  • Microsoft Edge: Choose Microsoft Edge > Settings > Cookies and Site Permissions > Notifications and turn off “Ask before sending.”

Browsers based on Chrome (everything except Firefox in the list above) offer a “Use quieter messaging” option that replaces the permission dialog with a bell icon next to the site name in the address bar—click it to allow notifications from that site.

Eliminating Phishing Notifications

Now you know how to prevent new sites from requesting permission to display notifications. What about sites that already have permission? It’s easy to block them in Safari’s Notifications settings screen. If you have any undesirable sites with Allow in the pop-up menu to the right of their name in the Notifications screen, choose Deny from that menu. You could remove the site instead, but that would allow it to ask for permission again.

Firefox’s interface is similar to Safari’s, but Chrome-based browsers have a different interface that separates the blocked and allowed sites. To block a website whose notifications you no longer want to receive, click the button to the right and choose Block. Again, you could remove undesirable sites if you prefer, but remember that if your notification settings ever change, doing so could allow the site to ask for permission once more.

Ultimately, it’s easy to avoid phishing notifications by paying attention as you browse the Web. Steer clear of websites that make an unexpected request to display notifications. Notifications aren’t necessary on hardly any websites, so there’s no harm in denying such requests unless you’re sure they’re legitimate.

(Featured image based on an original by iStock.com/tadamichi)


Social Media: Did you know that a phishing website can send you a notification right on your Mac? Learn how this could happen and how to prevent it in your favorite Web browser.

Similar Posts

  • Hey Siri, What Can You Do?

    So, I am a little embarrassed to admit it but I bought an Amazon Echo to check out how Alexa compares with Siri. I’m a gadget guy so we will see if we find it useful and if not, I am sure I can find it a home on eBay. I use Siri more and more these days. My most common uses are asking her to settle trivia disputes with Grace or setting the timer for 5 minutes. But there is a lot more that Siri can do!

    Make Relationships with Siri
    When you speak Siri commands, you can refer to people by relationship, rather than name. So, if you want to call your father, you can say “call my father” instead of saying “call Bruce Leibowitz.” But to do this, you need to introduce Siri to your family. First, make sure you have a “card” in the Contacts app for yourself, and then go into Settings > Mail, Contacts, Calendars, scroll down to find and tap My Info, and select your card. Next, make sure you have a contact card for your father, and then tell Siri, “Bruce Leibowitz is my father.” Or, if Siri doesn’t hear you correctly, open Contacts, edit your card (not your father’s!), scroll down, tap “add related name,” tap the default relationship to pick “father,” tap the info “i” icon, select your father’s card, and tap Done.

    You can even use Siri to remember other types of relationships. Artie used to bring manure from his uncle’s farm for my garden and ended up with the nickname, “the spreader”. If I tell Siri “Art Hendrickson is my spreader” I can now just say “text my spreader…” and Siri knows who I am talking about. This works for nicknames but also for lawyers, accountants, doctors or any nickname you want to tell Siri about.

    Take a Picture
    Instead of fumbling to launch the Camera app on your iPhone you can just say “take a picture” and Siri will automatically open the Camera app and you can snap away.

    Siri Converts
    Need to know how many millimeters are in 4 inches? Just ask Siri and you will find that there are 101.6 mm in 4 inches. This works for currency exchange rates, too. Ask Siri how many Euros are equal to $100US you will find that 87.73 Euros is the exchange rate today. Siri has some other strong calculation features too. You can ask Siri how many calories there are in that fish sandwich or to calculate a 20% tip on your restaurant bill. You can ask her to solve math problems involving fractions and other math functions that will be faster than opening the calculator app and punching in the numbers.

    Settling Up
    Okay you can use Siri to look up baseball stats or other information to settle a dispute but what if you are at loggerheads and just want to get a random answer and don’t have a coin to flip. You can ask Siri to “roll the dice”, “flip a coin” or pick a random number.

    Name that Tune
    Siri is integrated with Shazam to help you figure out what song is playing. Just ask her “what song is playing?” and she will listen and let you know and probably try to sell you the song, too!

    Find that Photo
    Siri can search your photo library for you. I know how frustrating it is if your are like me and have literally thousands of photos. You can say something like “find that photo from Daytona Beach from last March” and Siri will launch Photos and take you right to any photos taken at that place and time.

    Siri Takes You Out
    Siri can make your restaurant reservations for you, too! Tell Siri “make a restaurant reservation for four at 7PM” and she will respond with available restaurants nearby and if you have the Open Table app installed can make the reservation for you or give you the phone number to call.

    Are We There Yet?
    If you are using your iPhone for navigation you can just say “ETA” and Siri will let you know how much longer you are gonna be on the road.

    Leave Me Alone
    Siri can do a lot for you but sometimes you just want alone time. You can tell Siri to turn on “do not disturb” and you will not be bothered. Or tell her to “turn on airplane mode” and she will turn off Wi-Fi and cellular signals.

  • Find Some Ham Amidst Your Email Spam

    Spam filters work pretty well—99% of the messages in your spam mailbox are probably spam. But it’s frustrating to miss an important message…