Tech Support Scams: How Malicious Google Ads Work

A fresh cup of coffee resting on a newspaper, perfect morning routine setup.
Photo by cottonbro studio on Pexels

Tech support scams are evolving into highly sophisticated operations that leverage malicious Google ads to freeze the screens of both Windows and Mac users, according to recent security research.

Key Takeaways

    1. Sophisticated Deception: Malicious ads deliver a “browser locker” that simulates a system infection by freezing the screen and disabling common exit keys.
    2. Widespread Distribution: The ads appeared on high-traffic legitimate sites, including weather, maps, and real estate platforms.
    3. Evasion Tactics: The scam uses encrypted software that only decrypts in browser memory, making it difficult for many endpoint security tools to detect.
    4. Global Impact: While the campaign was observed across 619 organizations, the majority of targeted users were based in the United States, followed by Japan and Australia.
    5. Simple Recovery: Despite the appearance of a locked system, users can escape the scam by using specific keyboard commands to force-close the browser.
    6. What Happened

      Between August 31 and September 14, 2026, security firm Netskope identified a widespread campaign of malicious Google ads designed to facilitate tech support scams. These ads were not confined to obscure corners of the internet; instead, they were strategically placed on high-traffic, legitimate publisher sites, including those dedicated to maps, weather, real estate, document hosting, and sports.

      When a user clicks on one of these ads, the browser appears to seize up, displaying an urgent, full-screen warning that claims the device is infected. The warning instructs the user to call a bogus call center immediately. According to Netskope, the campaign was remarkably broad, involving more than 250 different Google Ads campaign IDs across at least 284 legitimate publisher sites.

      While Netskope observed users from 619 customer organizations interacting with these malicious ads, the firm noted that none of its own clients were actually scammed because the malicious content was blocked. However, because Netskope only sees a small fraction of total internet activity, the true number of victims globally is likely significantly higher.

      Blurred laptop screen displaying code with a white cap in focus, depicting
      Photo by Danny Meneses on Pexels

      Why It Matters

      The significance of this campaign lies in its psychological manipulation and its ability to bypass traditional security measures. Unlike older, more obvious phishing attempts, these tech support scams use “tradecraft” designed to manufacture a genuine sense of panic.

      By hijacking the browser interface, the attackers create a simulated environment where the user feels they have lost control of their hardware. This sense of urgency is a calculated tactic to push individuals—particularly those with limited technical literacy—into making impulsive decisions, such as paying large fees, granting remote access to their computers, or sharing sensitive personal information.

      Furthermore, the campaign demonstrates a growing challenge for major advertising platforms. The fact that these ads were served through legitimate publisher sites and managed to evade Google’s automated scanners highlights the ongoing arms race between cybercriminals and platform security teams.

      The Anatomy of a Browser-Based Locker

      To understand why these scams are so effective, one must look at the specific technical behaviors used to deceive the victim. The software kit used in these attacks is designed to be stealthy and closely mimic the symptoms of a real malware infection.

      When the malicious ad is triggered, the following behaviors typically occur:

    7. Screen Seizure: The warning occupies the entire screen, effectively hiding the browser’s address bar.
    8. Input Disruption: The software hides the mouse cursor and disables common exit keys, such as the Escape key, to prevent the user from simply closing the window.
    9. Performance Degradation: The browser begins to lag significantly, and sometimes even plays sounds, to reinforce the illusion that the computer is struggling under the weight of an infection.
    10. Conditional Triggers: Interestingly, the warnings often only appear after the user makes a mouse movement, a tactic used to ensure the user is actively engaged with the page before the “attack” begins.
    11. This combination of visual and functional disruption is intended to convince the user that their machine is broken, making the call to the number on the screen seem like the only available solution.

      Evasion Tactics and Detection Challenges

      One of the most concerning aspects of this campaign is how the attackers manage to bypass endpoint security software. Most traditional security tools look for malicious files being downloaded or executed on the hard drive. However, this scam operates differently.

      According to researchers, the software is encrypted and is only decrypted and displayed within the browser’s memory. Because the malicious activity is contained within the temporary memory of the browser rather than being saved as a file on the device, many endpoint security products—and potentially Google’s own ad filters—struggle to identify the content as malicious before it is served to the user.

      This “fileless” approach to delivering the scam message makes the campaign much harder to intercept at the perimeter. It allows the ads to remain active across hundreds of different campaign IDs, making it a moving target for security researchers and platform moderators.

      Global Distribution of the Campaign

      The reach of the campaign was not limited to a single region. Netskope’s data indicates a widespread geographic distribution, with a heavy concentration in Western markets.

      Region Observed Impact
      United States Approximately 62% of observed organizations
      Japan Second most frequent location
      Australia Third most frequent location
      Other Remaining percentage of the 619 organizations

      This distribution suggests that the attackers are targeting regions with high internet penetration and significant economic activity, where the potential for high-value financial fraud is greatest.

      Gloved hands holding a smartphone displaying an emergency SOS screen.
      Photo by Tima Miroshnichenko on Pexels

      Google’s Response and the Platform Challenge

      Google has faced scrutiny regarding how these ads were able to bypass its massive advertising filters. While the company maintains a high level of security, the presence of over 250 malicious campaign IDs suggests gaps in the automated detection process.

      In a statement, Google said, “We have zero tolerance for scams. We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.” The company also noted that in the previous year, it had successfully blocked over 99 percent of violating ads before they were ever served to users.

      However, the 1 percent that slips through can still represent millions of impressions and potentially thousands of victims. The core challenge for Google remains the scale of the platform; with millions of ads being served every minute, even a tiny failure rate in detection can be exploited by sophisticated actors using encrypted, memory-only payloads.

      What It Means for You

      If you or a family member encounters a screen that appears to be “locked” by a security warning, it is vital to remain calm. In almost all cases involving these tech support scams, your computer is not actually infected; it is merely a browser-based illusion.

      Immediate Action Steps

      If you find yourself staring at a frozen, alarming warning, do not call the number on the screen. No legitimate technology company—including Microsoft, Apple, or Google—will ever instruct you to call a phone number to resolve a security issue.

      To exit the scam window, follow these steps based on your device:

      For Windows Users:

    12. The Escape Method: Press and hold the Escape (Esc) key for several seconds. This can often force the browser out of full-screen mode and release the keyboard lock.
    13. The Task Manager Method: If the Escape key fails, press Ctrl + Shift + Esc to open the Windows Task Manager. From there, locate your web browser in the list of processes and select “End Task.”
    14. For Mac Users:

    15. The Escape Method: Similar to Windows, press and hold the Escape (Esc) key for several seconds to attempt to break the full-screen lock.
    16. The Force Quit Method: If the browser remains unresponsive, press Command (cmd) + Option + Escape. This will bring up the Force Quit Applications window, allowing you to select your browser and shut it down immediately.
    17. Crucial Note: Once you have successfully closed the browser, reopen it, but do not restore your previous session. Restoring the session may simply reload the malicious tab and trigger the scam again.

      An engineer monitors multiple screens in an industrial control room, ensuring smooth
      Photo by Sergey Sergeev on Pexels

      Counterpoints and Open Questions

      While the technical advice for escaping these scams is clear, several questions remain regarding the long-term efficacy of current defenses.

      Critics of large-scale ad platforms argue that the “99 percent” success rate claimed by companies like Google is insufficient given the sheer volume of global web traffic. There is an ongoing debate about whether the responsibility for security lies primarily with the platform providers to catch ads, or with the endpoint security software to detect the behavior once the ad is clicked.

      Furthermore, an open question remains: how long will it take for these specific campaign IDs to be fully purged from the ecosystem? Even as Google investigates, the decentralized nature of ad networks means that new, slightly modified versions of the same scam can appear almost as quickly as the old ones are removed.

      What Happens Next

      As of late September 2026, the investigation by Netskope and the subsequent review by Google are ongoing. Security researchers will continue to monitor for any shifts in the “tradecraft” used by these scammers, particularly whether they move away from browser-based lockers toward more traditional malware downloads.

      Users should also expect an increase in the sophistication of these warnings. As attackers learn which specific keyboard commands are most effective at bypassing their “locks,” they may develop new methods to further restrict user control.

      Frequently Asked Questions

      Is my computer actually infected if I see a security warning in my browser?

      In the case of these specific tech support scams, your computer is likely not actually infected. The “infection” is a visual trick played by a malicious advertisement. The software is designed to make the browser look like it has seized up, but it is not actually locking your operating system or stealing files from your hard drive at that moment. However, the goal is to trick you into calling a scammer who will then attempt to steal your information or install actual malware.

      Should I ever call a phone number provided by a pop-up or an ad?

      No. Never. No legitimate software company, such as Apple, Microsoft, or your antivirus provider, will ever display a pop-up message telling you to call a support number to fix a security problem. If you see a phone number on a screen that claims your computer is compromised, it is a scam. Hang up, close the browser, and contact a known, trusted support channel if you are genuinely concerned about your device’s security.

      How can I prevent these ads from appearing in the first place?

      While it is difficult to block every single malicious ad, you can reduce your risk by using reputable ad-blocking extensions, keeping your browser and operating system updated, and being cautious when clicking on ads in unfamiliar or high-traffic environments. Additionally, ensuring that you have active, updated endpoint security software can help catch some of these threats if they attempt to move beyond the browser.

      Conclusion

      The resurgence of tech support scams via Google ads serves as a stark reminder that digital literacy is a critical component of modern cybersecurity. By combining psychological pressure with clever technical evasion, scammers continue to find ways to exploit the gaps in both automated security systems and human awareness

      References

    18. arstechnica.com

Featured image: Photo by cottonbro studio on Pexels

Leave a Reply