A malicious Google Ads campaign showed convincing “computer locked/infected” warnings to Windows and Mac users and pressured them to call fake tech-support numbers. The goal was to confuse people into paying for bogus support, sharing personal information, or allowing remote access, not to actually lock the computer or install malware.
Key findings
- Attack delivered via Google Ads placed on legitimate high-traffic publisher sites (maps, weather, real estate, sports, document-hosting).
- Clicking the ad opened a browser page that mimicked a device infection/lockout and attempted to trap the user in full-screen mode.
- Primary objective was to get victims to call a fraudulent tech-support number, then pressure them to pay, share personal data, or grant remote access.
- Netskope observed users at 619 customer organizations clicking ads between Aug 31 and Sept 14; it identified 250+ related Google Ads campaign IDs and ads on 284 publisher sites.
- The page used browser manipulation (hide address bar/cursor, block shortcuts, slow browser, play sounds) and delayed display until mouse movement; code was encrypted and decrypted only in memory shortly before showing the warning.
Who’s being targeted
- Commonly targeted roles: All employees, Executives, Helpdesk/IT support, Finance (common scam target for payments).
- Affected industries: Multiple industries (cross-sector).
- Attack channels: website, email.
- Impersonated: Fake Microsoft/Apple/technical support alert (brand implied by Windows/macOS targeting), Internal IT Security / Helpdesk.
Awareness takeaways
- Treat sudden “computer locked/infected” pop-ups (especially after clicking ads) as scams and do not call any number shown.
- Use known-good support channels (company IT/helpdesk, official vendor sites) instead of reacting to on-screen instructions.
- Train users to recognize browser-takeover behavior as manipulation (full screen, hidden cursor/address bar, blocked exit keys).
- Provide simple escape steps so employees don’t panic (exit full-screen, force quit, task manager) and can report the incident.
Red flags to watch for
- Unexpected lock/infection warning immediately after clicking an ad
- Page forces full-screen, hides controls/cursor, and interferes with keyboard shortcuts
- Pressure to call a number rather than use normal company IT/helpdesk channels
- Urgent language pushing immediate action
- Link leads to a page that tries to look like a system failure
- Any instruction to call an unknown number instead of using official IT channels
Read the video transcript
You click a weather or maps link, and suddenly: “Security Alert: Your computer has been locked. Call Support now.” This is a Google Ads tech-support scam. The ad opens a page that grabs full screen, hides the address bar and cursor, blocks your shortcuts, and blasts a fake Microsoft or Apple-style lock message with a phone number. Here’s the trick: your computer is not actually locked. It’s just the browser. The scam page is stalling, playing sounds, and trapping the screen to panic you into calling so they can demand money, personal info, or remote access. If you ever see this kind of “locked PC” pop-up, do not call the number. Hit Escape to leave full-screen or force-quit the browser, then contact our IT helpdesk through the usual channel.