Fake Google Ads Are Delivering Convincing Browser-Locking Scams
Malicious Google ads can imitate a serious Windows or Mac infection, freeze browser controls, and push users toward fraudulent support numbers. Here is how to exit safely.

A sophisticated tech support scam delivered through Google ads can make Windows and Mac computers appear infected or frozen. The browser fills with urgent security warnings, common exit commands stop working, and victims are told to call a fraudulent support number immediately.
Security firm Netskope found the malicious ads across legitimate, high-traffic websites, including maps, weather, real-estate, document-hosting, and sports sites. Although the warnings can be alarming, the affected computer is not actually locked. Users can escape without calling the displayed number or giving anyone access to their device.
How the scam reaches users
The campaign used Google ads shown on otherwise legitimate publisher websites. From August 31 through September 14, Netskope observed users from 619 customer organizations clicking the malicious ads. Netskope blocked the content, so none of those users were successfully scammed.
The activity was widely distributed:
- About 62 percent of the affected organizations were in the United States.
- Japan and Australia ranked second and third among the countries represented.
- Netskope tracked more than 250 Google Ads campaign IDs.
- The ads appeared across at least 284 legitimate publisher sites.
Those figures represent only the traffic visible to Netskope. The total number of people exposed to the campaign—and the number who may have fallen victim—could therefore be much higher.
People who call the fraudulent support number may be pressured to pay large fees, disclose personal information, or grant remote access to their computers. Any of those actions can create risks beyond the initial browser warning.
Why the warning looks like a real infection
The scam is designed to transform a routine ad click into what appears to be a serious computer failure. Its fake warning takes over the entire screen and removes the browser address bar from view. It also hides the cursor, interferes with keyboard commands, plays sounds, and deliberately slows or lags the browser.
Messages flash on the screen telling the user not to restart the computer and to contact a call center immediately. Attempts to close the browser can cause the warning to refresh instead of disappearing. The result is a convincing imitation of malware or a locked operating system, even though the underlying device remains usable.
The presentation is adjusted for the victim’s platform. Windows users and macOS users see different versions intended to resemble warnings appropriate to their respective systems.
This combination of urgency, degraded performance, and restricted controls is intended to keep users from pausing to assess the situation. It can be especially effective against people who have limited experience troubleshooting computers or who are trying to complete a task quickly.
How the campaign avoids detection
Several technical choices make the malicious content harder for security tools and advertising filters to identify.
The warning does not appear until the user moves the mouse. In addition, the software is encrypted before delivery and is decrypted only in the browser’s memory when it is ready to display the fake warning. Netskope said these conditions can prevent many endpoint security products—and potentially Google’s ad filters—from recognizing the malicious behavior in advance.
Google did not explain why its scanners missed the campaign or confirm that all of the associated ads had been removed. In a statement, the company said it has “zero tolerance for scams” and was actively investigating the campaigns described by Netskope. Google also said it would act against accounts that violated its policies.
The company has previously reported that it blocked more than 99 percent of policy-violating ads before they were served last year.
What to do if your browser appears locked
Do not call the phone number displayed in the warning. A legitimate company will not respond to an infection by placing a number in a browser alert and demanding an immediate call. Users should also avoid paying fees, sharing personal details, or allowing the supposed support agent to control the computer remotely.
The browser can generally be recovered with one of these methods:
- Windows or macOS: Press and hold the Escape key for several seconds. This can force the browser out of full-screen mode and release the keyboard lock, allowing the affected tab to be closed.
- Windows alternative: Press Control-Shift-Escape to open Task Manager, then exit the browser.
- Mac alternative: Press Command-Option-Escape to open the Force Quit window, then close the browser.
After closing the browser, reopen it without restoring the previous session. Restoring that session could reopen the tab containing the scam page.
Helping less-experienced users respond safely
Tech support scams often rely less on technical compromise than on confusion and pressure. Ridiculing victims overlooks how difficult these warnings can be to evaluate, particularly when a browser appears unresponsive and repeatedly insists that immediate action is required.
Friends and relatives who provide informal technical support can help by sharing a few simple rules: never call a number shown in an unsolicited security warning, never provide remote access in response to one, and use the operating system’s task-management or force-quit controls when the browser cannot be closed normally.
Conclusion
These ads demonstrate how a legitimate advertising network and familiar websites can be used to deliver a persuasive scam. The most important fact is that the computer is not actually locked. Closing the browser through Escape, Task Manager, or Force Quit can end the incident without contacting the scammers.
Original reporting: Ars
Originally reported by Ars.