Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

by | Oct 10, 2026 | Technology

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Security researchers have identified a widespread tech support scam campaign being distributed through Google advertisements across numerous legitimate websites. The malicious ads appeared on high-traffic sites including maps, weather, real estate, document hosting, and sports platforms, displaying fake security warnings that appear to freeze both Windows and macOS devices.

From August 31 to September 14, security firm Netskope detected clicks on these ads from users across 619 customer organizations. Approximately 62 percent of affected organizations were located in the United States, with Japan and Australia representing the second and third largest concentrations. Netskope identified more than 250 distinct Google Ads campaign IDs distributed across at least 284 legitimate publisher sites. Although Netskope’s blocking technology prevented actual financial losses among its monitored users, the firm estimates that the total number of people exposed to the scam—including potential victims at organizations outside its visibility—is substantially higher.

The scam operates by displaying a deceptive interface that occupies the entire screen, disables standard browser navigation elements, and simulates computer performance degradation. Users who encounter the fake warning are pressured to contact a telephone number displayed on screen, where they are solicited for payment, remote device access, or personal information. The malware employs sophisticated concealment techniques, including encryption and activation only after mouse movement, which helps it evade detection by security filters and possibly Google’s advertising review systems.

Google stated it has initiated an investigation into the reported campaigns and indicated it maintains a policy of zero tolerance toward scams on its platform. The company noted it blocked over 99 percent of policy-violating ads before distribution in the prior year. However, Google did not specify the reason its detection systems failed to identify this campaign or confirm whether the ads have been completely removed from its advertising network.

Security experts note that while the scam interface appears to lock devices, users can typically exit the fraudulent warning by holding the escape key for several seconds on either Windows or macOS systems, or by using task manager commands to force close the browser. Legitimate technology companies do not contact users by telephone regarding security infections.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI