Google Ads ‘Locked PC’ Scam Pushes Fake Support Calls

TechSpot · Medium sophistication
Last updated September 28, 2026

A malicious Google Ads campaign showed convincing “computer locked/infected” warnings to Windows and Mac users and pressured them to call fake tech-support numbers. The goal was to confuse people into paying for bogus support, sharing personal information, or allowing remote access, not to actually lock the computer or install malware.

Key findings

  • Attack delivered via Google Ads placed on legitimate high-traffic publisher sites (maps, weather, real estate, sports, document-hosting).
  • Clicking the ad opened a browser page that mimicked a device infection/lockout and attempted to trap the user in full-screen mode.
  • Primary objective was to get victims to call a fraudulent tech-support number, then pressure them to pay, share personal data, or grant remote access.
  • Netskope observed users at 619 customer organizations clicking ads between Aug 31 and Sept 14; it identified 250+ related Google Ads campaign IDs and ads on 284 publisher sites.
  • The page used browser manipulation (hide address bar/cursor, block shortcuts, slow browser, play sounds) and delayed display until mouse movement; code was encrypted and decrypted only in memory shortly before showing the warning.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Helpdesk/IT support, Finance (common scam target for payments).
  • Affected industries: Multiple industries (cross-sector).
  • Attack channels: website, email.
  • Impersonated: Fake Microsoft/Apple/technical support alert (brand implied by Windows/macOS targeting), Internal IT Security / Helpdesk.

Awareness takeaways

  • Treat sudden “computer locked/infected” pop-ups (especially after clicking ads) as scams and do not call any number shown.
  • Use known-good support channels (company IT/helpdesk, official vendor sites) instead of reacting to on-screen instructions.
  • Train users to recognize browser-takeover behavior as manipulation (full screen, hidden cursor/address bar, blocked exit keys).
  • Provide simple escape steps so employees don’t panic (exit full-screen, force quit, task manager) and can report the incident.

Red flags to watch for

  • Unexpected lock/infection warning immediately after clicking an ad
  • Page forces full-screen, hides controls/cursor, and interferes with keyboard shortcuts
  • Pressure to call a number rather than use normal company IT/helpdesk channels
  • Urgent language pushing immediate action
  • Link leads to a page that tries to look like a system failure
  • Any instruction to call an unknown number instead of using official IT channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You click a weather or maps link, and suddenly: “Security Alert: Your computer has been locked. Call Support now.” This is a Google Ads tech-support scam. The ad opens a page that grabs full screen, hides the address bar and cursor, blocks your shortcuts, and blasts a fake Microsoft or Apple-style lock message with a phone number. Here’s the trick: your computer is not actually locked. It’s just the browser. The scam page is stalling, playing sounds, and trapping the screen to panic you into calling so they can demand money, personal info, or remote access. If you ever see this kind of “locked PC” pop-up, do not call the number. Hit Escape to leave full-screen or force-quit the browser, then contact our IT helpdesk through the usual channel.

Similar attacks

EvilTokens Used Device-Code Phish to Fuel BEC

EvilTokens Used Device-Code Phish to Fuel BEC

Microsoft disrupted “EvilTokens,” a subscription cybercrime service that stole Microsoft account access using device-code phishing and then used AI-style automation to rapidly mine victims’ inboxes for payment and org-chart details. The goal was to quickly craft believable payment-fraud messages…

September 23, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
60,000 Fake LinkedIn Jobs Used to Scam Applicants

60,000 Fake LinkedIn Jobs Used to Scam Applicants

Scammers are using realistic LinkedIn recruiter profiles and even verified company pages to post fake jobs that push people to off-platform sites or email addresses. The scams aim to take money (e.g., paid “resume help”) or collect sensitive personal data like driver’s licenses or Social Security…

September 23, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a real phishing campaign offering a “free” Claude Max upgrade to trick people into signing in with Google. The site uses a fake, draggable Google login pop-up (“browser-in-the-browser”) that looks legitimate and captures credentials. A stolen Google account can expose email and…

September 23, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and…

September 23, 2026