Google Ads used to push fake Windows and Mac lockup scareware, Netskope finds

Google Ads used to push fake Windows and Mac lockup scareware, Netskope finds

Researchers at security firm Netskope found Google ads delivering a tech support scam that freezes the screens of both Windows and Mac devices and displays messages urging victims to phone a bogus call center. Once someone calls the number, scammers push them to pay hefty fees, grant remote access to their device, or hand over personal information. The malicious ads ran across the open web, appearing on high-traffic maps, weather, real-estate, document-hosting, and sports sites, riding alongside legitimate advertising. From August 31 to September 14, Netskope observed users from 619 of its customer organizations click on the malicious ads. None of those users were actually scammed, because Netskope blocked the content before it could execute. About 62 percent of the affected organizations were based in the US, with Japan and Australia rounding out the top three. Since Netskope can only see a small slice of overall internet traffic, the true number of people exposed to the campaign, including anyone who did fall for it, is likely much higher than what the firm recorded. Netskope tracked more than 250 distinct Google Ads campaign IDs spread across at least 284 legitimate publisher sites carrying the scam. Describing the mechanics, Netskope said the trick turns an ordinary ad click into a browser that appears to seize up on a fake security warning: a locker screen fills the display, hides the cursor, blocks the usual exit keys, and slows the browser down, all to manufacture the impression of a broken machine and pressure the person into calling the number shown. Nothing on the computer is actually locked, but the effect is convincing enough in the moment to push people toward the scam. The article frames this as a problem that disproportionately catches internet users who have little grasp of how computers and the web work, people it nicknames "Uncle Louie," arguing that mockery of scam victims ignores how large that group of vulnerable users actually is.

Key facts

  • Netskope observed users from 619 customer organizations click malicious Google ads between August 31 and September 14
  • About 62 percent of affected organizations were in the US, with Japan and Australia next
  • The scam displays a fake lockup screen on Windows and Mac browsers, hiding the cursor and blocking exit keys to pressure victims into calling a bogus support number
  • Netskope tracked over 250 Google Ads campaign IDs running across at least 284 legitimate publisher sites, including maps, weather, real-estate and sports sites
  • None of the observed clicks led to an actual scam because Netskope blocked the malicious content, though the firm says real exposure is likely far higher than what it saw

Why it matters

The campaign shows scammers successfully placing convincing fake-lockup ads through Google's ad network onto mainstream, high-traffic websites, meaning ordinary browsing on trusted sites can still expose users to social-engineering attacks that mimic a broken computer.

Who it affects

Anyone browsing maps, weather, real-estate, document-hosting or sports sites could encounter the ads; Netskope's data shows the effect reached users across 619 organizations, mostly in the US, with Japan and Australia also significantly affected, and the article stresses that less tech-savvy users, family members without technical knowledge, are the most likely to be fooled.

How to use it

There is no product or fix to adopt here; the practical takeaway is awareness, since the fake freeze is not a real lockout, closing or force-quitting the browser (or restarting the device) clears it, and no one should call the number shown or grant remote access based on such a warning.

How solid is it

The account rests on data directly from Netskope, a security firm that observed and blocked the campaign during a specific two-week window, and it names concrete figures for organizations affected, campaign IDs, and publisher sites; it does not name who is behind the campaign, nor does it state whether Google removed the ads or provide figures on actual financial losses from victims who did fall for it.

Risks and caveats

Netskope's numbers cover only its own customer base, so the real scale of the campaign and how many people actually paid money, granted remote access, or handed over personal information is unknown and, per the firm, likely much larger than what was recorded.

“The locker fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser, all to manufacture the sense of a broken machine and pressure the person into calling the number on the screen. Nothing on the computer is actually locked, but in the moment it is convincing enough to push people toward the scam.”

— Netskope