Widespread Google Ads scam delivers convincing lock screens and fake support calls

A global security threat has emerged as a Google Ads campaign spreads a sophisticated tech-support scam, freezing browsers and prompting users to call deceptive helplines, affecting hundreds of organisations across multiple countries.

Security researchers have identified a Google Ads campaign delivering a highly convincing tech-support scam that can freeze browsers on Windows and Mac devices and display urgent warnings telling users to call a fake helpline. Netskope said the campaign used cloud-hosted pages and deceptive ad flows to create the impression that a machine had been compromised, when in fact the browser was only being manipulated into appearing locked.

According to Netskope Threat Labs, the operation was unusually widespread. Between August 31 and September 14, 2026, the firm observed activity affecting at least 619 customer organisations, with the majority based in the US and smaller clusters in Japan and Australia. Netskope said it tracked more than 250 Google Ads campaign IDs spread across 284 legitimate publisher sites, suggesting a much broader reach than its own telemetry can directly measure.

The scam itself relied on layered social engineering. Netskope described a sequence in which a user lands on a page that first shows a loading spinner and then an apparently ordinary online store interface, before the fake warning is revealed only after interaction. The kit also used anti-analysis tricks, including waiting for mouse movement before decrypting the alert in browser memory, which makes automated detection harder. Once the warning appears, victims are pushed to call a bogus support line and may be urged to pay fees, reveal personal information or hand over remote access to their devices.

The campaign adds to a wider pattern of abuse around search and advertising platforms. Bitdefender has separately reported hijacked Google Ads accounts pushing fake downloads for well-known software, while other security researchers have documented malicious campaigns using Google’s broader ecosystem to spread scareware and malware. Google’s own scam guidance advises users to slow down when confronted with urgency, verify claims independently and avoid sending payment or personal data on the spot. The company also says users should report suspected scams so they can be investigated and disrupted.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.