On September 25, Google said it was investigating campaigns that used Google Ads to deliver fake security warnings to Windows and macOS users. Netskope Threat Labs tracked the scam kit from August 31 through September 14, 2026.
The warning was a browser-based scareware page designed to frighten people into calling fraudulent support. Netskope said the computer itself was not actually locked.
A fake security warning inside the browser
Scareware uses a false security alert to create urgency and push someone into taking an action. In this campaign, the page could fill the screen, hide the browser’s address bar and cursor, slow the browser, and interfere with ordinary exit keys. The warning appeared after mouse movement.
The goal was to prompt a call to a fake support number. Scammers could then seek money, personal information, or remote access. The campaign’s reported mechanism was a browser warning, not a system-level lock.
What Netskope tracked during the campaign
From August 31 through September 14, 2026, Netskope tracked more than 250 campaign IDs across at least 284 legitimate publisher sites. It observed users at 619 customer organizations clicking the ads. That figure counts organizations where clicks were observed, not individual users or confirmed victims.
Netskope reported that it blocked the content for the customer organizations it monitored and that none of the users it observed was scammed.
How to close the fake warning
Holding Escape for several seconds can restore browser control in many cases. If needed, use the operating system’s force-quit option:
- Windows: Press Ctrl+Shift+Esc to open Task Manager, then close the browser.
- macOS: Press Command+Option+Esc to open Force Quit, then close the browser.
When you reopen the browser, do not restore the previous session.
Google’s September 25 response
Google said it was investigating the campaigns and would take action against accounts that violated its policies.