Scammers used Google Ads on at least 284 legitimate websites to make Windows and Mac users think their computers were locked. A click opened a fake security warning that pushed people to call a scam support number; Netskope observed clicks at 619 customer organizations from August 31 to September 14, 2026.
The campaign reached those sites after Alphabet reported that impressions across its website-ad network had fallen 12% year over year. The publisher sites had not been compromised: the ads were the route in.
Timeline
- August 31, 2018, Google said it would restrict third-party tech-support ads worldwide.
- September 9, 2019, Google said it would continue blocking those ads after testing a verification program.
- Q2 2026, Alphabet reported falling Google Network revenue and ad impressions.
- August 31-September 14, 2026, Netskope observed malicious ad clicks at 619 customer organizations and traced more than 250 campaign IDs across at least 284 publisher sites.
- September 24, 2026, Netskope published its investigation.
- September 25, 2026, Ars Technica published Google’s statement that it was investigating the campaigns.
Netskope Threat Labs traced the clicks from ordinary-looking ads to storefront-style pages. Moving the mouse triggered a Windows- or Mac-specific warning. The page decrypted its warning code in browser memory, then went full-screen, hid the address bar and cursor, interfered with exit keys and slowed the browser. It made a browser look like a locked computer without locking the operating system.

A warning instructed the user to call for help. Ars Technica reported that callers were urged to pay fees, grant remote access or disclose personal information. The trick depended on getting someone to treat the number on a webpage as the way to regain control of their machine.
Netskope counted more than 250 Google Ads campaign IDs and 457 scam hosts. About 62% of the customer organizations where it saw clicks were in the US, 16% in Japan and 14% in Australia. Applying its rounded US share to the 619 organizations gives about 384 US organizations, organizations where Netskope saw a click, not people who paid a scammer.
Netskope blocked the malicious content for the users it observed.
Google’s tech-support ad restriction
Google had already named this category of abuse. In 2018, it restricted ads for third-party tech-support services, citing misleading experiences, and in 2019 said it would keep blocking them. The scammers’ route through storefront-looking pages shows how a prohibited pitch can arrive as the destination of an apparently ordinary ad.
There was a warning from outside Netskope’s investigation, too. On August 5, 2026, a website publisher described separate AdSense ads on his site that led to Apple- and Microsoft-themed scareware pages. He said he removed AdSense from the site. His account predates Netskope’s observation window; it describes the same kind of failure without identifying the same campaigns.

An earlier independent measure gives the broader problem some scale. GeoEdge’s Q2 2025 ad-quality report measured malicious impressions at 0.32% on Google’s ad supply, compared with 1.09% and 0.61% on two other platforms. Across the platforms it measured, tech-support scams accounted for 18% of malicious advertising activity that quarter.
Google told Ars Technica it was investigating:
“We have zero tolerance for scams. We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.”
Google did not explain why its checks missed the campaigns. Its Q2 2026 filing puts the business backdrop in numbers: Google Network revenue slipped from $7.354 billion a year earlier to $7.303 billion, primarily because of lower AdSense revenue. Impressions fell 12% while revenue per impression rose 13%.
The documented failure is narrower and firmer: despite a longstanding restriction, Google’s ad system carried campaigns that sent clicks from legitimate sites to fake computer emergencies. Netskope traced more than 250 campaign IDs in just over two weeks.
Further Reading
- A Fake Security Locker, Delivered by Google Ads, Netskope’s investigation of the campaigns and browser-locker technique.
- Your uncle’s frozen Mac says it’s infected after viewing a Google ad, Reporting on Google’s response and Netskope’s blocked users.
- Alphabet Inc. Form 10-Q, Alphabet’s Q2 2026 network-ad figures.
- Restricting ads in third-party tech support services, Google’s 2018 restriction and 2019 update.
- Q2 2025 Ad Quality Report, GeoEdge’s earlier cross-platform malicious-ad measurements.
