Scareware Google Ads Keep Running After Reports

Help Net Security · Medium sophistication
Last updated September 2, 2026

University researchers found large numbers of deceptive “software” ads (including scareware) running through Google’s ad system, generating over 100 million impressions in Europe. They reported some ads via Google’s “Report this ad” flow, but several ads were acknowledged as policy violations and still stayed live, including multiple ads linked to the same malicious domain.

How the attack worked

Researchers mined Google's Ads Transparency Center and identified deceptive software ads at scale, including 238 scareware ads and 3,346 ads making false claims. The flagged ads collectively received well over 100 million ad impressions in Europe alone. The scareware examples used alarming device-infection or storage warnings, such as claims that a phone had been damaged by dozens of viruses, designed to pressure users into clicking or installing a supposed fix. Other ads promised impossible services, like recovering photos deleted years ago or letting a stranger track anyone's phone location just by entering a number. A third category used minimal-content creatives, such as a bare button reading Continue or an unexplained QR code, to obscure who was behind the ad and where it would lead.

Why it succeeded

These ads worked because they exploited trust in a major, widely used advertising platform. Landing pages were linked to malicious domains flagged by multiple protective DNS services, including one associated with the TamperedChef malware campaign. Even after researchers reported ads through Google's Report this ad flow, some were removed, but others were acknowledged as violations and stayed live anyway. Removing a single ad also did not stop the broader campaign: other ads pointing at the same domain kept running, meaning users remained exposed even after individual complaints were resolved.

What to watch for

  • Urgent, alarming messages about viruses or storage problems arriving through an ad rather than a device's trusted security tools or app store
  • Offers that sound too good to be true, such as recovering long-deleted photos or tracking a phone using only a number
  • Ads with almost no information about the advertiser, product, or purpose, including generic Continue buttons or unexplained QR codes
  • Ads that have been running for a long time and accumulated large view counts, which does not indicate legitimacy

How to build resistance

Treat alarming device warnings delivered via ads as suspicious and close the page rather than clicking through; use trusted device settings or app store tools to check for real issues. Be skeptical of any ad promising impossible capabilities, and avoid entering personal data such as phone numbers into unfamiliar landing pages. Do not assume that a platform's ad reporting and removal process fully protects users, since a reported ad or its underlying domain may keep running. Finally, be cautious of ads that hide who is behind them, since a lack of clear company or product information is itself a red flag worth treating as a signal to disengage.

Key findings

  • Researchers mined Google’s Ads Transparency Center and identified deceptive ads at scale, including 238 scareware ads and 3,346 ads making false claims.
  • The flagged ads collectively received “well over 100 million ad impressions in Europe alone.”
  • The scareware ads used alarming device-infection/storage warnings designed to pressure users into clicking or installing something.
  • When researchers reported ads through “Report this ad,” some were removed, but others were “acknowledged as violations and stayed live anyway.”
  • Landing pages were linked to “malicious domains flagged by multiple protective DNS services,” including one associated with the “TamperedChef” malware campaign.
  • Removing one ad did not stop other ads pointing to the same domain: “The other 41 ads pointing at the same domain kept running.”

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT helpdesk/service desk, Security awareness training audience.
  • Affected industries: All industries (general end users exposed to web ads), Information/Media (online advertising platforms), Consumer technology/mobile users.
  • Attack channels: website.
  • Impersonated: A phone security scanner/antivirus or system alert, A ‘data recovery’ or ‘phone tracking’ service provider, Unclear/undisclosed (ad hides who is behind it).

Red flags to watch for

  • Overly alarming language and specific-sounding numbers (“33 types of viruses”) designed to panic the user
  • Unexpected security warning arriving via an ad rather than the device’s trusted security/app store
  • Pressure implied by urgent damage/blocked functionality claims
  • Too-good-to-be-true promises (recovering long-deleted photos; tracking anyone with just a number)
  • Vague advertiser identity or unclear business details
  • Invasive request for personal data (phone number/location-related info)
  • Ad contains almost no information about the company, product, or purpose
  • Generic button-only creative (“Continue”) that hides the destination
  • QR code in an ad with no clear brand or explanation
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is scareware in the context of these Google ads?

Scareware ads use alarming device-infection or storage warnings, such as claims a phone has been damaged by dozens of viruses, to pressure users into clicking or installing something.

Does reporting a bad ad to Google stop it from running?

Not always. Researchers found that reporting a bad ad to Google doesn't mean the ad, or the domain behind it, stops running, and some ads were acknowledged as violations but stayed live anyway.

What other tactics did these deceptive ads use besides scareware?

Some ads promised to recover photos deleted years ago or let a stranger track anyone's phone location just by entering a number, while others used bare 'Continue' buttons or QR codes to hide who was behind the ad.

How many impressions did these deceptive ads generate?

Researchers found that flagged ads, including 238 scareware ads and 3,346 ads making false claims, collectively received well over 100 million ad impressions in Europe alone.

Read the video transcript

You’re scrolling a news site and a banner screams, “Your phone has been severely damaged by 33 types of viruses.” Researchers found hundreds of these scareware ads running through Google’s main ad system, over 100 million impressions, even after some were reported and confirmed as policy violations. Some ads push fake virus fixes. Others promise to recover photos deleted years ago or track anyone’s phone just by entering a number. Behind them: malicious domains and long‑running scam campaigns. If a web ad claims your device is infected or offers impossible tracking, don’t click it, close the page and use your phone’s own security or app store tools instead.

Similar attacks

Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026