Google Tech Support Scams Explained: How Malicious Ads Work

A dramatic studio portrait of a woman with eyes closed, posing against a glowing blue abstract background.
Photo by cottonbro studio on Pexels

Google tech support scams are leveraging increasingly sophisticated, malicious advertisements to freeze the screens of both Windows and Mac users, creating a sense of digital crisis designed to trick victims into calling fraudulent call centers.

Key Takeaways

    1. Sophisticated <a href="https://news.quantosei.com/2026/09/24/cloudflare-security-block-explained-why-you-get-blocked/” title=”cloudflare security block Explained: Why You Get Blocked”>browser Lockers: malicious Google ads are triggering “locker” scripts that freeze browsers and disable standard exit keys to simulate a system infection.
    2. Widespread Reach: Security firm Netskope identified over 250 fraudulent campaign IDs appearing across more than 284 legitimate publisher sites.
    3. Global Impact: While 62 percent of affected organizations were based in the U.S., significant activity was also tracked in Japan and Australia.
    4. Stealth Tactics: The scam software uses encryption in memory to bypass many endpoint security tools and Google’s own ad filters.
    5. Immediate Remedy: Users can typically bypass these freezes by using specific keyboard shortcuts like Task Manager on Windows or Force Quit on macOS.
    6. What Happened

      Between August 31 and September 14, 2026, security researchers identified a widespread campaign of malicious Google ads designed to facilitate tech support scams. According to a report from the security firm Netskope, these ads were distributed across a variety of high-traffic websites, including those dedicated to maps, weather, real estate, document hosting, and sports.

      When a user clicks on one of these ads, the browser undergoes a sudden, simulated failure. The screen appears to seize up, often displaying an urgent, high-pressure message claiming the device is infected and must be repaired immediately via a provided phone number. Netskope observed that these malicious ads were clicked by users from 619 different customer organizations. Fortunately, in the specific instances tracked by the firm, no users were actually scammed because Netskope was able to block the content before the fraud could be completed.

      Close-up of a laptop screen displaying green code text. Perfect for cybersecurity
      Photo by Rafael Minguet Delgado on Pexels

      Why It Matters

      The significance of this campaign lies in its technical sophistication and its ability to exploit human psychology. Unlike older, less effective scams that relied on simple pop-ups, these Google tech support scams utilize a “locker” mechanism that effectively hijacks the user’s immediate digital environment.

      By disabling the cursor, hiding the address bar, and swallowing standard exit keys, the attackers manufacture a state of panic. This psychological pressure is intended to bypass a user’s critical thinking, pushing them toward the only perceived solution: calling the bogus number. The scale of the operation is also concerning; because Netskope only sees a small fraction of total internet traffic, the true number of people exposed to these ads—and the number of successful victims—is likely significantly higher than the observed data suggests.

      The Anatomy of a Fake Infection

      To understand how these scams bypass modern defenses, one must look at the specific tradecraft used by the attackers. The software kit is designed to mimic the symptoms of a real, critical system failure.

      The “Locker” Mechanism

      When the malicious ad is triggered, the browser begins to lag and perform poorly. According to Netskope, the software “fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser.” This creates a convincing illusion that the computer is physically broken or compromised. The warning screen often occupies the entire display, preventing the user from seeing other tabs or windows.

      Stealth and Evasion

      One of the most difficult aspects of these scams to combat is their method of evasion. The software is encrypted, and the decryption process occurs only within the browser’s memory. This specific tactic is highly effective at evading many endpoint security products that scan for known malicious files on a hard drive. Furthermore, the scam is designed to be reactive; the warning messages often only appear after the user makes a mouse movement, which can help the script evade automated scanners that do not simulate human interaction.

      Feature Scam Behavior Purpose
      Cursor Control Hidden or disabled Prevents the user from clicking away
      Keyboard Input Escape and other keys disabled Prevents closing the tab or browser
      Visual Display Full-screen, no address bar Removes context and ability to navigate
      Performance Intentional lagging and sound effects Simulates a system-wide infection
      Detection Method Encrypted in browser memory Bypasses traditional file-based security

      Stakeholders and Reactions

      The Security Community

      Security firms like Netskope are sounding the alarm on the increasing difficulty of filtering these ads. The ability of attackers to use 250 different campaign IDs across hundreds of legitimate sites demonstrates a high level of coordination and a desire to overwhelm automated detection systems.

      Google’s Position

      Google has acknowledged the issue but has not provided a specific explanation for why its scanners failed to detect these particular campaigns. In a statement, the company said, “We have zero tolerance for scams. We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.”

      Google also noted that it blocked over 99 percent of violating ads before they were ever served in the previous year. However, the emergence of this sophisticated campaign suggests that the remaining 1 percent represents a significant and evolving threat to users.

      Hands typing on a laptop keyboard in an indoor setting. Perfect for
      Photo by Israel Torres on Pexels

      What It Means for You

      If you or a family member encounters a screen that appears to be “locked” by a security warning, it is vital to remain calm. These Google tech support scams are designed to make you feel that you have lost control, but in most cases, your device is perfectly fine.

      Immediate Action Steps

      If you find yourself targeted by a fake warning, follow these protocols to regain control:

    7. Do Not Call the Number: This is the most important rule. No legitimate company—including Microsoft, Apple, or your internet service provider—will ever instruct you to call a phone number to resolve a security issue.
    8. Try the Escape Key: For both Windows and macOS, pressing and holding the Escape (Esc) key for several seconds can often force the browser out of full-screen mode and release the keyboard lock.
    9. Force the Browser to Close:
    10. On Windows: Press Control-Shift-Escape to open the Windows Task Manager. Find your web browser in the list, select it, and click “End Task.”
      On macOS: Press Command-Option-Escape to bring up the Force Quit menu. Select your browser and click “Force Quit.”

    11. Do Not Restore Sessions: When you reopen your browser, it may ask if you want to “Restore previous session” or “Reopen tabs.” Always select NO. Restoring the session may simply reload the malicious scam page.
    12. Protecting Vulnerable Users

      Many people fall victim to these scams not because they are “unintelligent,” but because they lack technical familiarity with how browsers and operating systems behave. The combination of a high-pressure environment and a lack of digital literacy makes them prime targets. For those who provide informal tech support for friends or elderly relatives, a practical solution is to keep a physical note of the “Force Quit” commands near their computer workstations.

      Counterpoints and Open Questions

      While the immediate threat of these specific ads can be mitigated through technical knowledge, several open questions remain regarding the broader ecosystem of online advertising.

      One major concern is the effectiveness of current ad-filtering technologies. If attackers can use encryption in memory to bypass both Google’s filters and endpoint security, it suggests a widening gap between scammer tradecraft and defensive capabilities. Critics of large ad platforms often argue that the sheer volume of ads makes perfect moderation an impossible task, leading to a reactive rather than proactive security posture.

      Furthermore, it remains unclear whether the removal of these specific 250 campaign IDs will prevent similar attacks from appearing under different IDs. The cat-and-mouse game between scammers and platform moderators is a permanent fixture of the digital economy, and the success of these “stealthy” kits poses a significant challenge to the industry’s ability to provide a safe browsing experience.

      Contemporary computer with black screen placed on stand near row of server
      Photo by Brett Sayles on Pexels

      What Happens Next

      As Google continues its investigation into the flagged campaigns, the industry will be watching for several key signals:

    13. Platform Updates: Whether Google implements new detection methods specifically aimed at detecting “locker” behavior or memory-resident encryption in ads.
    14. Security Software Evolution: How endpoint security providers update their definitions to catch browser-based, fileless scams.
    15. Regulatory Scrutiny: Whether increased frequency of these scams leads to greater pressure on ad networks to take legal responsibility for the content they monetize.
    16. For now, the primary defense remains user education and the ability to recognize the hallmarks of social engineering: urgency, fear, and the demand for immediate, unverified contact.

      Frequently Asked Questions

      How do I know if a pop-up is a scam?

      Legitimate security software (like Windows Defender or macOS built-in security) will notify you through system-level notifications, not through a web browser pop-up. If a message appears within your browser—especially if it covers the entire screen, hides your mouse, or tells you to call a phone number—it is almost certainly a scam. No real tech company will ever ask you to call them via a random pop-up.

      What should I do if my screen freezes after clicking an ad?

      Do not panic and do not call any numbers displayed on the screen. The freeze is a software trick, not a physical hardware failure. Use the keyboard shortcuts to force the browser to close. On Windows, use Ctrl+Shift+Esc to open the Task Manager and end the browser process. On a Mac, use Cmd+Option+Esc to Force Quit the browser. Once closed, reopen the browser but do not restore your previous tabs.

      Can these ads actually infect my computer with malware?

      While the specific “locker” behavior described by Netskope is designed to simulate an infection rather than actually installing a virus, the goal of the scam is to get you to divulge personal information or grant remote access. Once a scammer has remote access to your computer, they can install actual malware, steal your banking information, or lock your files for ransom. The primary danger is the human interaction that follows the initial ad click.

      Does Google prevent these ads from appearing?

      Google states that it has a zero-tolerance policy for scams and claims to block over 99 percent of violating ads before they are served. However, as seen in this recent campaign, sophisticated attackers can still find ways to bypass these filters by using encrypted scripts and hundreds of different campaign IDs. This means that while most ads are safe, users should still remain vigilant.

      Closing

      The emergence of these sophisticated Google tech support scams highlights a persistent vulnerability in the modern web: the intersection of high-speed advertising and human psychology. While technical tools like Task Manager and Force Quit provide a way out, the most effective defense remains a healthy skepticism of any urgent, high-pressure digital warning.

      References

    17. arstechnica.com

Featured image: Photo by cottonbro studio on Pexels

Leave a Reply