[HEADS UP] Allowing Site Notifications Can be Very Costly

Stu Sjouwerman | Nov 18, 2020

Allowing Site Notifications Can Be CostlyKrebs on Security reported that there have been an increasing number of websites asking visitors to approve 'notifications'. In most cases these notifications are not malicious, but several firms are paying site owners to install notification scripts to sell to scammers.

Normally, a website will ask permission to send notifications (as long as you approve the request), which results in messages that pop up outside of your browser. Krebs lists an example, "Microsoft Windows systems they typically show up in the bottom right corner of the screen — just above the system clock. These so-called “push notifications” rely on an Internet standard designed to work similarly across different operating systems and web browsers."

Unfortunately many users do not know what they are signing up for to when notification are approved. It's also nearly impossible for a user to tell the difference between a notification sent by a website or one that is made to appear by another program that could be using this information against you.  

For reference, here is what a general pop up looks like: 

Screen Shot 2020-11-18 at 8.57.48 AM

It's important to teach your users to be suspicious of any activity on their workstations, including allowing websites to show notifications. New-school security awareness training can ensure your users know how to stay alert and apply best practices in their day to day tasks. 

Krebs has the full story

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.