Signum
Feed
Useful signal25 Sept 2026medium confidence

Google Ads served tech-support scam that freezes Windows and Mac browsers, security firm Netskope reports

Between August 31 and September 14, 2026, security firm Netskope observed users at 619 customer organizations clicking on malicious Google Ads that deliver a browser-locker tech support scam (fake full-screen warning, disabled keys, cursor hidden) across at least 284 legitimate publisher sites via more than 250 Google Ads campaign IDs. Netskope blocked the content for its customers; the ads' status on Google's platform is unconfirmed, and Google says it is investigating.

AccessGovernance

Entities: Google, Netskope, Google Ads

60Useful signal
1 source
0 primary
Was this useful?
01

What happened

Security vendor Netskope reports that between 31 August and 14 September 2026, users at 619 of its customer organisations clicked malicious Google Ads that delivered a browser-locking tech-support scam, a fake full-screen warning that disables keys and hides the cursor, differently on Windows and Mac. The ads ran across at least 284 legitimate publisher sites via more than 250 distinct Google Ads campaign IDs. Netskope blocked the content for its own customers; it is unconfirmed whether Google has removed the ads, and Google says only that it is investigating.

02

Why it matters

This affects anyone browsing ad-supported sites, consumers and enterprise staff alike, since the scam evaded both endpoint security and Google's ad review process. The real exposure is almost certainly larger than the 619-organisation figure, which reflects only Netskope's own customer base, not the wider internet. For businesses, it is a reminder that browser isolation and user training remain necessary even when relying on ad-platform vetting and endpoint tools.

03

What is noise

The "likely much higher" exposure claim is an extrapolation from one vendor's limited visibility, not a measured figure, so treat it as a guess. Browser-locker tech-support scams are a long-running, well-documented fraud genre, not a new attack technique, despite the "unusually sophisticated" framing. Google's response is boilerplate "we are investigating" with no confirmed takedown, campaign suspension, or policy change, so there is no evidence yet that anything has actually been fixed.

04

Watch next

  1. 01Whether Google confirms takedown of the 250+ campaign IDs or names an advertiser/network responsible, rather than a generic statement
  2. 02Whether other security vendors (Malwarebytes, Microsoft, CrowdStrike) independently corroborate scale beyond Netskope's 619-organisation sample
  3. 03Any follow-up reporting on financial losses, remote-access compromises, or law enforcement action tied to this specific campaign

Coverage

1 story

More distribution signals

Full feed →