Advertisement
Advertisement
Advertisement
26 September 2026ยท8 min readยทBy Markus Heill

Google ads scareware freezes Macs and PCs, Netskope finds

Netskope says Google ads delivered scareware that freezes Macs and PCs with fake infection warnings, pushing users to call bogus support lines.

Google ads scareware freezes Macs and PCs, Netskope finds

Google Ads Scareware Freezes Browsers on Macs and PCs

Google ads scareware isn't just a pop-up nuisance. It's worse. Much worse. Researchers say they recently found Google ads delivering a sophisticated tech support scam that freezes the screens of both Windows and Mac devices and displays messages urgently instructing users to phone a bogus call center. The ads ran all over the web, including on high-traffic maps, weather, real-estate, document-hosting, and sports sites. And anyone who called that number, well, they're pushed to pay hefty fees, hand over remote access to their device, or spill personal information. So you can't ignore it.

The scale is uncomfortable. From August 31 to September 14, security firm Netskope watched users from 619 customer organizations click on those malicious ads, and while none of them were actually scammed because Netskope blocked the content, the sheer reach of the operation still stands out. Roughly 62 percent of those organizations were based in the US. Japan and Australia took second and third. Since Netskope sees only a tiny sliver of Internet activity, the real number of people exposed to Google ads scareware, including those who fell for it, is likely much higher, and that's a gap we can't easily measure. The firm tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites.

The Trick That Makes a Browser Look Broken

Here's what sets this campaign apart from those cheap fake antivirus pop-ups of a decade ago. The software kit behind it is built to be stealthy, and it's designed to closely mimic the signs of a real infection, which means it doesn't just look convincing on the surface but works hard to keep you from noticing the trick. The browser address bar disappears. The warning screen takes over the entire display. Escape and many other keys stop responding. And browser performance degrades, sounds play, and pages lag, all so they can sell the impression that something is seriously wrong.

The screen flashes messages. Don't restart the machine. Call a call center right away. Try to close the browser, and the scam message simply refreshes, which means the warning won't go away no matter how many times you click that little X in the corner. The warnings only appear after a mouse movement. The payload is also encrypted, decrypted only in browser memory, and both of those conditions together keep many endpoint security tools, and possibly Google's own ad filters, from detecting the malice hiding underneath. But they're not the only trick. The warning ads even render differently depending on whether the targeted machine runs Windows or macOS. So the scam adapts.

Netskope stated that for the victim, that tradecraft turns an ordinary ad click into a browser that appears to seize up on a fake security warning. The locker fills the screen. It hides the cursor. It swallows the usual exit keys and lags the browser, all to manufacture the sense of a broken machine and pressure the person into calling the number on the screen. Nothing on the computer is actually locked. But in the moment it's convincing enough to push people toward the scam.

Why Smart Users Are Not the Only Targets

By now, plenty of people ridicule anyone who falls for this stuff. They just laugh. A sizable portion of Internet users have little or no understanding of how computers and the Internet work. Add the pressure to get things done quickly and the growing difficulty of navigating the web, and you have a large group of prime targets. But some of the loudest critics have close friends and family in exactly that group.

Market Context: According to the FBI, losses attributable to tech support scams in 2024 were a whopping $1.464 billion.

That is the part the smugness skips. A frozen screen with a phone number on it does not look like a scam to someone who has never been taught what a real security alert looks like. It looks like an emergency.

Google Says It Is Investigating

Google did not say what caused its scanners to miss the campaign, and it gave no indication the ads have been fully removed from its ad platform. The company issued a statement defending its record.

A computer screen showing a chatbot interface

"We have zero tolerance for scams. We're actively investigating the campaigns in this report and will take action against accounts that violate our policies."

The company says it blocked over 99 percent of violating ads last year before they were ever served. That figure deserves a pause. It's the ads they caught. And it's not the ones that slipped through, which is the part that matters most here. The gap between 99 percent and 100 percent, that tiny sliver of failure sitting right at the edge of a number that sounds like perfection, is exactly where this campaign lived for two weeks.

How to Escape a Fake Lock Screen

The devices aren't actually locked. Netskope noted that. Most of the usual keys for closing the scam window have been disabled, and that's the part that sounds like a dead end, the kind of thing that makes people assume they've got no move left at all. But there's a way out. And it's simple enough to teach someone over the phone.

  • On both Windows and macOS, press the escape key and hold it for several seconds. That forces the browser out of full screen and releases the keyboard lock, so the tab can be closed.
  • On Windows, invoke Task Manager with control-shift-escape and exit the browser there.
  • On a Mac, use cmd-option-escape to bring up the force quit window.
  • In both cases, reopen the browser without restoring the previous session.

One rule sits above all the keyboard shortcuts. No legitimate company will ever tell a user to call a phone number because their machine is infected, and that's true no matter how urgent the warning sounds or how convincing the person on the other end of the line happens to be. Anyone hit by a tech support scam should not call the number. Full stop. But we've all seen the pop-ups, and they're designed to scare you. So don't call. It's that simple.

A Post-it Note Worth Writing

People who provide informal tech support for friends and family might consider writing that advice on a Post-it and sticking it to the screen. It sounds like a joke. It is not. When the browser locks up and messages start flashing, the person at the keyboard will not remember a tip they read once. They will remember the note taped to the monitor.

The deeper problem is structural. Google ads scareware works because it exploits the one thing users are trained to trust: the ad slot on a legitimate site. The publisher is real. The page is real. Only the ad is hostile, and it arrives wearing the costume of a security alert. Until ad platforms can screen for payloads that stay encrypted until they reach browser memory, campaigns like this one will keep finding the gap. The tools to escape already exist. Getting them into the hands of the people who need them is the harder part.

Frequently Asked Questions

What did researchers discover Google ads were delivering?

Researchers found Google ads delivering a sophisticated tech support scam that freezes the screens of both Windows and Mac devices. The ads displayed messages urgently instructing users to phone a bogus call center, and they ran on high-traffic maps, weather, real-estate, document-hosting, and sports sites.

Why is this Google ads scareware campaign harder to detect than typical fake antivirus pop-ups?

The software kit behind the campaign is built to be stealthy and closely mimics the signs of a real infection. The payload is encrypted and decrypted only in browser memory, and the warnings appear only after a mouse movement, which together keep many endpoint security tools and possibly Google's own ad filters from detecting the malice.

How can a user escape the fake lock screen on both Windows and macOS?

On both Windows and macOS, the user should press the escape key and hold it for several seconds, which forces the browser out of full screen and releases the keyboard lock so the tab can be closed. On Windows, the user can invoke Task Manager with control-shift-escape, and on a Mac, use cmd-option-escape to bring up the force quit window, then reopen the browser without restoring the previous session.

When did Netskope observe users clicking on the malicious ads, and how many organizations were affected?

From August 31 to September 14, security firm Netskope watched users from 619 customer organizations click on those malicious ads. Roughly 62 percent of those organizations were based in the US, with Japan and Australia taking second and third.

What did Google say in response to the reported campaign, and what does its 99 percent figure actually represent?

Google stated it has zero tolerance for scams, is actively investigating the campaigns, and will take action against accounts that violate its policies, though it did not say what caused its scanners to miss the campaign or indicate the ads were fully removed. The company says it blocked over 99 percent of violating ads last year before they were ever served, but that figure represents the ads they caught, not the ones that slipped through.

Markus Heill
Written by
Gadgets and Software Writer

Markus Heill writes about technology and the tools we use every day, from smartphones to the services that run in the background. He is interested in how good design makes technology easier to live with.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement