tech
What We Know About the Google Ads Scareware Campaign Freezing PCs

Google ads delivered a tech support scam that froze the screens of Windows and Mac computers and urged victims to call a fake support line, according to security firm Netskope, cited by Ars Technica.
The ads ran across high-traffic maps, weather, real-estate, document-hosting, and sports sites. Users who clicked were shown a locked-looking screen warning of an infection and pressing them to phone a number on screen. Callers were then asked to pay fees, hand over remote access to their device, or share personal information, Ars Technica reported.
What Happened, Step by Step
- Aug. 31–Sep. 14, 2026: Netskope observes users across 619 customer organizations clicking the malicious ads during this window, per the report.
- During the same period: The firm tracks more than 250 Google Ads campaign IDs running across at least 284 legitimate publisher sites, according to Netskope's findings as relayed by Ars Technica.
- Throughout the campaign: Netskope says it blocks the malicious content each time, so none of the organizations it monitors are actually scammed.
- Sep. 25, 2026: Ars Technica publishes its report on the campaign, quoting Netskope's description of how the scam manipulates victims.
How Widespread Was the Scam?
Roughly 62 percent of the 619 affected organizations were based in the United States, with Japan and Australia ranking second and third, Ars Technica reported, citing Netskope. Because Netskope's visibility covers only a slice of overall internet traffic, the actual number of people exposed to the ads — including anyone who was scammed — is likely much higher, according to the outlet.
How Does the Fake Infection Screen Work?
Nothing on the targeted computer is actually locked. The scam instead uses a browser trick to simulate a broken machine, Netskope told Ars Technica: "The locker fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser, all to manufacture the sense of a broken machine and pressure the person into calling the number on the screen."
According to the report, the kit behind the ads is built for stealth. The browser's address bar disappears. The warning screen takes over the full display. Pressing escape or most other keys does nothing. Fake lag and sound effects reinforce the appearance of a crash. On-screen messages tell victims not to restart the machine and to call immediately. Trying to close the browser window only makes the warning reload.
The warning also waits for a mouse movement before appearing, and the code is encrypted until it decrypts inside the browser's memory, Ars Technica reported. Both tactics are designed to slip past endpoint security software and Google's own ad-review filters, according to the report.
Why Do People Fall For It?
Ars Technica's report pushes back on the instinct to mock victims of the scam. A large share of internet users, the outlet notes, have little or no technical understanding of how computers work, and many are simply trying to get something done quickly on a web that keeps getting harder to navigate. Combined with a screen that convincingly mimics a real system failure, that gap in technical knowledge is what the scam is built to exploit.
What Should Someone Do If They See This Screen?
The underlying report makes clear that the locked appearance is fake: no file has actually been encrypted or damaged, and the browser, not the operating system, is what's misbehaving. For a relative or friend who calls in a panic after seeing one of these warnings, the immediate steps drawn from the report's own description of the mechanism are straightforward: do not call the number on screen, and do not grant remote access to anyone who calls claiming to be from tech support after such a warning appeared. Because the freeze is a browser rendering trick rather than a true system lock, forcing the browser to close — even if the page reloads the warning on a retry — does not put files at risk the way the on-screen message implies.
Netskope's monitoring window ran from Aug. 31 to Sep. 14, 2026, and the firm's campaign-ID count reflects only what it could observe through its own customer base, per Ars Technica. The report does not specify whether Google has removed the identified ad campaigns or whether the scam is still active as of publication.
Read the Full Report
For Netskope's complete technical breakdown and Ars Technica's full account of the campaign, see the original Ars Technica report.
Questions
Is the computer actually infected when the frozen screen appears?
No. Netskope told Ars Technica that nothing on the computer is actually locked; the browser is manipulated to simulate a frozen or infected machine.
How many organizations were exposed to the scam ads?
Netskope observed users at 619 customer organizations click the ads between Aug. 31 and Sep. 14, 2026, though it says it blocked the content before anyone was scammed, according to Ars Technica.