Scam Campaign Used Google Ads for Fake Alerts

A mid-2026 malicious advertising campaign targeted users across 619 organizations with deceptive browser warnings.

Updated on Oct. 4, 2026 in Cybersecurity

Isometric editorial illustration featuring a geometric slate-blue monolith disrupted by sharp mustard shards, symbolizing a cyber-security intrusion.
A mid-2026 malicious advertising campaign used fake Google security alerts to target 619 organizations, routing users to fraudulent call centers. AI Illustration. Upload story photo >

Live Poll

Do you trust that major search engines are doing enough to block malicious advertisements?

Between August 31 and September 14, 2026, researchers tracked a scam campaign that deployed fake security warnings through Google advertisements. These ads appeared on 284 legitimate sites and targeted both Windows and macOS users to drive traffic to fraudulent call centers.

Why it matters

This campaign demonstrates how threat actors leverage large-scale ad networks to impersonate system warnings and manipulate user behavior. By appearing on reputable domains, these malicious ads bypass traditional filters to target organizational networks.

The ads used more than 250 unique campaign IDs to distribute deceptive warnings. These warnings, which disabled keyboard shortcuts, were triggered by mouse movement and operated within browser memory to evade automated detection.

The players

Netskope

A cloud-native security firm that tracks network traffic and identifies malicious web-based campaigns.

Google

The operator of a global advertising network currently investigating the abuse of its platform by these malicious campaign IDs.

The details

The scam employs browser-based obfuscation to trick users into believing their systems are compromised. By running encrypted code directly in the browser's memory, the software disables standard shortcuts to force a full-screen alert. Users are instructed to contact call centers for support, though the devices themselves remain unaffected and can be recovered using task manager commands or the escape key.

Timeline

  1. August 31, 2026: The malicious ad campaign observation period began.

  2. September 14, 2026: The observation period for the campaign concluded.

The Tech Race

The campaign highlights the ongoing struggle between platform providers and attackers over the integrity of digital advertising ecosystems. While automated blockers catch a majority of violations, the use of encrypted memory execution remains a persistent vector for bypassing current security filters.

Users encountering these full-screen browser warnings can exit by using task manager commands or pressing the escape key, as the software does not lock the device. Security teams at affected organizations should monitor browser traffic for patterns associated with the identified campaign IDs.

The takeaway

This event serves as a reminder that browser-based warnings originating from advertisements are frequently engineered deceptions rather than system-level alerts. Organizations should continue to prioritize user education regarding these specific browser-locking techniques to minimize the risk of interaction with fraudulent support centers.

Further reading

For more information on threat actor tactics in digital advertising, visit Cybersecurity.

Source note: This article includes information reported by RocketNews.

Live Poll

Do you trust that major search engines are doing enough to block malicious advertisements?