A scareware campaign delivered through Google Ads made Windows and Mac browsers appear frozen and urged viewers to call a bogus support number. Netskope tracked more than 250 campaign IDs across at least 284 legitimate publisher sites.

How the fake browser locker created urgency

Scareware is a fake security warning designed to frighten someone into taking action. In this case, the alert made the browser look as if it had seized up. The fake locker hid the cursor, swallowed common exit keys and caused browser lag to make the device seem broken. Netskope said the computer itself was not actually locked.

What Netskope’s tracking counted

From August 31 through September 14, users at 619 Netskope customer organizations clicked the ads. That figure counts organizations whose users clicked—not individual people or confirmed victims. Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites, including maps, weather, real-estate, document-hosting and sports websites.

About 62% of the observed customer organizations were based in the US. Japan and Australia were the next most represented countries. Netskope’s telemetry covered only a small fraction of internet activity.

What callers were pressured to do

People who called the number were reportedly pressured to pay fees, grant remote access or disclose personal information. Netskope blocked the content for its customers, and none of those customers was scammed.