arstechnica.com 25 Sept 2026, 19:38 UTC

Google Ads Faked Browser Lockups to Push Tech Support Scams

Google Ads Faked Browser Lockups to Push Tech Support Scams

RESEARCHERS say Google ads recently delivered a sophisticated tech-support scam across legitimate websites, including maps, weather, property, document-hosting and sports services. Netskope observed users from 619 customer organisations click the malicious adverts between 31 August and 14 September; it blocked the content, so none of those users was scammed. About 62% of the organisations were in the US, followed by Japan and Australia. Netskope tracked more than 250 campaign IDs across at least 284 publisher sites, although it said the campaign’s overall reach was probably much larger.

The adverts displayed fake security warnings that made Windows and macOS browsers appear frozen. They hid the address bar, disabled common exit keys, slowed the browser, played sounds and repeatedly urged users not to restart their devices but to call a purported support centre. The code appeared only after mouse movement and was decrypted in browser memory, features that could help evade endpoint security tools and advertising filters.

Victims who called were reportedly pressured to pay, provide personal information or grant remote access. Google said it had “zero tolerance for scams”, was investigating and would act against accounts breaching its policies, but did not say whether all the adverts had been removed.

Netskope said the devices were not actually locked. Users can generally press and hold Escape for several seconds to leave full-screen mode and close the tab. Alternatively, Windows users can use Control-Shift-Escape to end the browser process, while Mac users can press Command-Option-Escape. The article advises not calling numbers shown in such warnings, as legitimate companies do not instruct users to seek help that way.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline