A sophisticated tech support scam has been exploiting Google's advertising platform to freeze browsers and trick users into calling fraudulent call centers, according to research by security firm Netskope.

Between August 31 and September 14, Netskope tracked more than 250 Google Ads campaign IDs deploying malicious ads across at least 284 legitimate publisher sites — including high-traffic maps, weather, real-estate, document-hosting, and sports websites. Users from 619 customer organizations clicked on the ads, though Netskope's blocking prevented any from being actually scammed.

**How the scam works.** When a user clicks a malicious ad, the software performs an elaborate simulation of a real infection. The browser address bar disappears, the warning screen goes full-screen, the cursor vanishes, and common keyboard shortcuts are disabled. Browser performance degrades, sounds play, and pages lag — all creating the convincing illusion of a compromised machine.

The warnings appear only after a mouse movement, and the malicious content is encrypted, only decrypting in browser memory — a technique that evades many endpoint security tools and possibly Google's own ad scanners. The scam displays differently depending on whether the target is running Windows or macOS.

**The human cost.** Victims who call the displayed number are urged to pay hefty fees, grant remote access to their devices, or share personal information. As Netskope noted, the scam specifically targets people with limited technical knowledge — a demographic that ridicule-heavy discussions often dismiss.

"For the victim, that tradecraft turns an ordinary ad click into a browser that appears to seize up on a fake security warning," Netskope explained. "Nothing on the computer is actually locked, but in the moment it is convincing enough to push people toward the scam."

**The escape route.** For anyone caught by such scams: on both Windows and macOS, holding the Escape key for several seconds forces the browser out of full-screen mode and releases the keyboard lock. Alternatively, users can invoke Task Manager (Ctrl+Shift+Escape on Windows, Cmd+Option+Escape on Mac) to close the browser.

Google's response was measured: "We have zero tolerance for scams," a spokesperson said. "We're actively investigating the campaigns in this report and will take action against accounts that violate our policies." The company claimed to block over 99% of violating ads before they're served, but the scale and sophistication of this campaign suggest significant gaps remain.