Technology
Ars Technica - All content

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Source Entity

Dan Goodin

September 28, 2026
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Cybersecurity researchers have identified a sophisticated tech support scam leveraging Google ads to lock user devices. By displaying fake infection alerts, attackers attempt to trick victims into calling bogus support lines to steal sensitive data and money.

The Rising Threat of Malicious Advertising

Recent findings by cybersecurity firm Netskope have uncovered a sophisticated and pervasive tech support scam circulating through Google’s advertising network. These malicious ads are designed to target unsuspecting users by freezing their screens—on both Windows and Mac operating systems—while displaying urgent, fraudulent notifications. The primary objective of this scheme is to coerce victims into contacting a bogus call center, where attackers attempt to solicit hefty fees, gain remote access to personal devices, or harvest sensitive personal information.

Pervasiveness Across Digital Platforms

The reach of these malicious campaigns is alarmingly broad. The ads have been identified across a wide spectrum of high-traffic websites, including platforms dedicated to maps, weather tracking, real estate, document hosting, and sports news. By infiltrating these trusted domains, the attackers exploit the familiarity and perceived safety of these sites to lower user defenses. This strategy represents a significant escalation in malvertising, where the sheer volume of exposure increases the likelihood of user interaction.

The Anatomy of the Scam

The workflow of this attack is simple yet psychologically manipulative. Once a user clicks a compromised ad, the device interface is locked to simulate a system failure or security breach. By creating a false sense of urgency, the attackers pressure victims into calling the provided phone number. Once contact is established, the 'support' agents use social engineering tactics to extract payments or gain administrative control over the victim's hardware, turning a simple ad click into a severe security compromise.

Global Impact and Defensive Measures

Data gathered by Netskope between August 31 and September 14 reveals the global scale of this threat. During this two-week window, users from 619 distinct customer organizations clicked on these malicious advertisements. While the majority of these targets—roughly 62 percent—were based in the United States, significant activity was also observed in Japan and Australia. Fortunately, the implementation of proactive security measures by Netskope allowed these organizations to avoid falling victim to the scam, demonstrating the critical role of network-level protection in modern digital environments.

Future Trends in Malvertising

The evolution of these tech support scams suggests that attackers are becoming increasingly adept at navigating ad-tech ecosystems to bypass traditional filters. As users rely more heavily on cloud-based document hosting and real-time data services, the potential attack surface for malvertising continues to grow. Organizations and individual users must remain vigilant, prioritizing the use of robust threat-detection software and maintaining skepticism toward urgent browser-based warnings that demand phone contact or remote access.

Conclusion

This incident highlights a significant vulnerability within the digital advertising landscape. While security firms like Netskope are currently effective at mitigating these threats, the sophisticated nature of these scams necessitates a more comprehensive approach to ad vetting and platform security. Users are reminded that legitimate software providers will never freeze a screen to demand a phone call for support, and any such interaction should be immediately terminated.

Verification Required?

Read the full report from the primary source

Go to Ars Technica - All content