Users Are Getting Flooded With Fake Security Notifications in Edge

0
2
Asked By MellowPine47 On

I manage IT for a small company of roughly 70 users. Recently, several employees started receiving nonstop Windows notifications claiming their computers were unsafe and that they needed to scan with McAfee or take similar action. Dismissing the alerts only caused more to appear.

All affected users run Microsoft Edge. I checked for suspicious extensions and installed applications, but nothing unusual was present. The notifications pointed to a strange domain, d9kbc46bvlls73a28fr0.lcgi-protect.co.in. Blocking that domain in Edge stopped the alerts, and full disk scans with our endpoint security platform found nothing.

Has anyone dealt with this before? I'm trying to determine whether this is malware or simply a browser notification permission that users accidentally granted, and what the best company-wide fix would be. I'm also considering blocking the domain at the firewall and deploying an ad-blocking extension.

5 Answers

Answered By SilverMaple18 On

I would not assume the router is compromised based on this alone. The symptoms fit a browser notification subscription much more closely. Remove the permission from Edge, push a policy that blocks notification requests, and investigate whether any user clicked through and downloaded a file separately.

Answered By AmberKite904 On

The clean endpoint scans make sense here: nothing necessarily ran on the computer. These campaigns are often delivered through malicious ads, redirects, or misleading articles, and they can continue until the browser permission is removed. User training is useful, but technical controls such as browser policies, DNS filtering, and application execution controls are more reliable.

Answered By CopperSparrow8 On

This is usually caused by someone clicking Allow on a website’s notification prompt. The site can then send browser notifications designed to look like McAfee or other security warnings. They’re essentially spam messages from the browser, not proof that anything was installed. The real danger is a user clicking the notification and downloading whatever scam it leads to. Clear the site’s notification permission, and use policy to prevent sites from asking in the first place.

Answered By NorthstarJade62 On

Use the Edge administrative policy DefaultNotificationsSetting and disable notification prompts across the company. An allow-list approach is better if a few legitimate services need notifications. The permission is stored in the browser profile, so blocking the domain at the firewall may not remove the existing subscription or stop all notification traffic. An ad-blocking extension can help prevent the original lure, but policy control is the main fix.

QuietOrbit5 -

You can still allow specific sites after disabling notifications globally—for example, an approved webmail service—so users don’t have to lose every legitimate browser notification.

Answered By CrispWillow31 On

We handle this by disabling browser notifications company-wide and enabling Edge’s built-in scareware protection. We also deploy content filtering or an approved ad blocker to reduce the chances of users encountering the notification prompt. For affected machines, remove the site’s notification permission or reset the browser settings, then check for downloads and run an endpoint scan as a precaution.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.