

While there are thousands of various messages and sites sending them, and messages evolve over time, these are the most common seen in April 2021: What other messages should I be on the lookout for? Alternatively, you can disable notification prompts altogether.Īs the saying goes, an ounce of prevention is worth a pound of cure. The simplest way is to carefully read such authorization prompts and only click Allow on sites that you trust. Great, but how can this be prevented in the future? Search for the site name and click the 3 dotes next to the entry.

Clicking on the messages lead to various websites informing the user their subscription has expired, that McAfee has detected threats on their system, or providing direct links to purchase a McAfee subscription. In several other examples, social engineering is crafted around the McAfee name and logo.

Clicking the message leads to an imposter Windows Defender alert website, complete with MP3 audio and a phone number to call. Some sites send notifications as often as every minute. Users willingly opt-in uncoerced.Īfter Allowing notifications, messages quickly start being received. In other cases, there is no deception involved.

In many cases scammers use deception to trick users into Allowing push notifications to be delivered to their system. A significant portion is attributed to browser-based push notifications, and while there are a couple of simple steps users can take to prevent and remediate the situation, there is also some confusion about how these should be handled. McAfee is tracking an increase in the use of deceptive popups that mislead some users into taking action, while annoying many others.
