Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

by | Sep 30, 2026 | Technology

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Security researchers identified a widespread tech support scam operating through Google advertisements on prominent websites including maps, weather, real estate, and sports platforms. Between August 31 and September 14, security firm Netskope detected users from 619 organizations clicking on the malicious ads, though protective measures prevented actual fraud in those instances. The firm documented more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites.

When clicked, the advertisements deliver a sophisticated display that freezes on users’ screens and presents urgent messages instructing them to contact a bogus call center. The scam’s technical design creates the impression of an actual system infection by disabling browser controls, degrading performance, and filling the entire screen with warning content. Callers are then pressured to pay fees, grant remote access to their devices, or share personal information.

Geographic analysis showed approximately 62 percent of affected organizations were located in the United States, with Japan and Australia representing the second and third largest concentrations. Given that Netskope has visibility into only a fraction of internet activity, the total number of people exposed to these ads is substantially higher than observed figures. The scam exploits vulnerabilities in Google’s advertising platform that allowed the malicious content to evade detection systems.

Google stated it has zero tolerance for scams and is investigating the campaigns while pledging action against violating accounts, though the company did not explain how the ads bypassed its filters or confirm complete removal from its platform. Experts advise that devices are not actually locked despite disabled keyboard functions, and users can typically exit the scam by holding the escape key or using task manager functions. Security professionals recommend documenting these exit methods for less technical users, and emphasize that legitimate companies never request phone calls for infection assistance.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI