Malicious Google Ads Turn Browser Tricks Into Cross-Platform Tech-Support Fraud
Malicious Google Ads sent Windows and macOS users to browser lockers mimicking system infections to push fake support calls across 619 organizations.
Illustrative image generated with AI
Hundreds of organizations encountered the advertising campaign
A large-scale tech-support scam used Google advertisements to send Windows and macOS users into convincing browser-based lock screens. The findings surfaced on September 25, 2026, after researchers documented exposure across hundreds of organizations and legitimate websites.
Netskope observed users from 619 customer organizations clicking the malicious ads between August 31 and September 14. Its security controls blocked the scam content, and the company said none of the users in that dataset was successfully defrauded.
That figure represents only the activity visible through Netskope’s customer base. The true number of exposed users, including people who may have paid the scammers or granted them remote access, is not known and could be considerably higher.
Around 62% of the affected organizations were in the United States. Japan had the second-largest share, followed by Australia.
The distribution was broad rather than confined to suspicious or obscure websites. Advertisements appeared on at least 284 legitimate publisher sites, including heavily visited maps, weather, real-estate, document-hosting, and sports services. Netskope identified more than 250 separate Google Ads campaign IDs associated with the operation.
This reach gave the fraud an important advantage: victims could encounter it while visiting a familiar website, with no obvious indication that the advertisement would trigger a scam.
A browser locker creates the illusion of a disabled computer
The operation relies on a browser-based locker rather than an actual operating-system lock. After a victim interacts with the malicious advertisement, the page takes over the display and presents alarming messages claiming that the computer has suffered a serious infection.
The behavior is designed to remove the visual and practical cues that would normally reveal a simple web page. It fills the screen, conceals the browser’s address bar and mouse cursor, interferes with the Escape key and other common keyboard controls, and deliberately reduces browser responsiveness.
Audio alerts, flashing warnings, and noticeable lag reinforce the claim that something is wrong. The page tells users not to restart the device and prominently displays a telephone number for supposed technical support.
Attempts to close the browser may instead cause the fraudulent page to refresh. That reaction can convince a victim that the browser is no longer under their control.
The scam also waits for mouse movement before showing its warnings. Until the user interacts with the page, the most conspicuous malicious behavior remains hidden.
Despite these effects, the computer is not truly locked. The page has not disabled the operating system, and users can recover control without calling the displayed number. The technical restrictions exist primarily to create panic and delay an ordinary response such as closing the tab or terminating the browser.
In-memory decryption may complicate automated detection
The scam content is encrypted and decrypted only when it is rendered in browser memory. Netskope assessed that this design, combined with delayed activation after mouse movement, may help the campaign avoid endpoint security tools and possibly Google’s advertising review systems.
Static scanners may therefore see different content from the code ultimately presented to an interacting user. The delayed warnings also reduce the chance that an automated process will reproduce the complete scam sequence unless it simulates realistic browser activity.
The pages tailor their appearance according to the victim’s platform. Windows users and macOS users receive different presentations, allowing the warnings and interface elements to look more credible on each operating system.
No affected software versions have been identified because this is not a conventional product vulnerability. There is no disclosed CVE, patch, or vulnerable browser release associated with the campaign. The attack instead abuses web behavior, advertising distribution, and social engineering.
Specific malicious domains, telephone numbers, and campaign identifiers were not disclosed in the available details. Defenders therefore have no published indicator list to match directly against network or advertising telemetry. Behavioral signals are more useful: unexpected full-screen warnings, disappearing browser controls, audio alerts, blocked keyboard input, severe browser lag, and instructions to call “support.”
The telephone call is the real objective
The browser locker is only the first stage. Its purpose is to persuade victims that professional assistance is urgently required, then move the interaction from the browser to a fraudulent call center.
Users who call the displayed number may be pressured to pay substantial fees, reveal personal information, or install remote-access software. Granting remote access can expose documents, saved credentials, communications, and other sensitive material, while also giving the scammer another opportunity to demand payment.
The campaign does not need to compromise the operating system to cause serious harm. A victim who believes the screen is genuine may voluntarily provide everything the attackers want.
People with limited technical experience are likely to face the greatest risk, particularly when the warnings imitate system interfaces and resist familiar keyboard shortcuts. The scale of the advertising campaign also means that exposure is not limited to users who intentionally visit risky websites.
No confirmed victim total or aggregate financial-loss figure is known. Netskope’s observation that its protected users were not scammed should not be interpreted as evidence that the broader campaign failed.
Google is investigating, but full removal is unconfirmed
Google did not explain why its advertising scanners failed to stop the campaigns before users encountered them. The company also did not confirm that every related advertisement had been removed.
Google said it does not tolerate scams, is investigating the campaigns identified by researchers, and will take action against accounts that violate its policies. It has separately stated that it blocked more than 99% of policy-violating advertisements last year before they were served.
The remaining fraction can still matter when campaigns are distributed across hundreds of advertising IDs and legitimate publisher sites. In this case, Netskope’s measurements documented more than 250 campaign IDs, indicating that the operation was not dependent on a single advertisement or account.
The activity has no formal severity rating. Its danger comes from the combination of wide distribution, platform-specific deception, browser interference, and direct pressure to contact the scammers.
How users can regain control safely
Users who encounter one of these pages should not call the displayed telephone number. Legitimate technology companies do not respond to detected infections by forcing a browser into full-screen mode and ordering the user to contact an unsolicited support line.
On either Windows or macOS, pressing and holding Escape for several seconds should exit full-screen mode and release the page’s keyboard lock. The user can then close the affected tab.
If that does not work, Windows users can press Control-Shift-Escape to open Task Manager and terminate the browser. Mac users can press Command-Option-Escape and force-quit it.
When restarting the browser, users should avoid restoring the previous session. Session restoration could reopen the same fraudulent page and reproduce the apparent lock.
Anyone who already called the number should stop communicating with the operator and avoid installing requested remote-access software. If remote access was granted or personal information was disclosed, the incident should be treated as a potential compromise rather than merely an unwanted advertisement.
The key distinction is simple: the page is trying to simulate loss of control. Closing the browser ends that illusion without paying, sharing information, or giving a stranger access to the device.
Sources
This article is an original reworking based on the sources below.




