<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se" -->

---
title: Your uncle’s frozen Mac says it’s infected after viewing...
description: A tech support scam campaign has been spreading through Google Ads on high-traffic websites like maps, weather, real-estate, and sports sites, affecting both...
canonical: https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what? | daily.dev
og:description: A tech support scam campaign has been spreading through Google Ads on high-traffic websites like maps, weather, real-estate, and sports sites, affecting both...
og:url: https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se
og:image: https://api.daily.dev/og/posts/Q7zjAf9se.png
og:image:alt: Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 0 upvotes · 0 comments

## Summary

A tech support scam campaign has been spreading through Google Ads on high-traffic websites like maps, weather, real-estate, and sports sites, affecting both Windows and Mac users. The ads trigger a fake browser lockup that hides the cursor and blocks exit keys, displaying a bogus security warning urging victims to call a scam number. Security firm Netskope tracked the campaign from August 31 to September 14, observing clicks from 619 customer organizations across more than 250 Google Ads campaign IDs and 284 publisher sites, with the US, Japan, and Australia most affected. No customers were actually scammed since Netskope blocked the malicious content, but the firm believes broader exposure is likely far higher given its limited visibility into overall internet traffic.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/09/google-ads-caught-delivering-convincing-scareware-ads-to-unsuspecting-users>

## Questions this post answers

### What is the browser lockup scam that shows a fake security warning and tells you to call a phone number?

It is a scareware tech support scam delivered through malicious Google Ads on legitimate high-traffic sites like maps, weather, and real-estate pages. The ad triggers a fullscreen overlay that hides the cursor, blocks normal exit keys, and lags the browser to simulate a frozen or infected machine, pressuring victims into calling a bogus number where scammers demand fees, remote access, or personal information. Nothing is actually locked or infected.

_Staying current on scam techniques like this one helps you protect family members before they get caught out; daily.dev surfaces security research for exactly that._

### How widespread was the recent Google Ads tech support scam campaign detected by Netskope?

Netskope observed clicks on the malicious ads from 619 customer organizations between August 31 and September 14, tracking more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites. About 62 percent of affected organizations were based in the US, with Japan and Australia ranking second and third. None of Netskope's customers were actually scammed since the firm blocked the content, but real-world exposure is likely much higher.

_Tracking the scale of scams like this helps security teams gauge real risk; daily.dev keeps that kind of research close at hand._

## Similar posts on daily.dev

- [Crooks push Mac malware through fake OpenAI Codex ads](https://daily.dev/posts/crooks-push-mac-malware-through-fake-openai-codex-ads-ncfmsadff) · The Register · 0 upvotes · 0 comments
- [Gizmodo readers hit with ClickFix malware prompts after account compromise](https://daily.dev/posts/gizmodo-readers-hit-with-clickfix-malware-prompts-after-account-compromise-xl32lvmpa) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?","url":"https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se"},"datePublished":"2026-09-26T02:13:55.069Z","dateModified":"2026-09-26T02:14:19.849Z","description":"A tech support scam campaign has been spreading through Google Ads on high-traffic websites like maps, weather, real-estate, and sports sites, affecting both...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/525c1d892ac59eb31eb0109e0b679c12?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/525c1d892ac59eb31eb0109e0b679c12?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/your-uncle-s-frozen-mac-says-it-s-infected-after-viewing-a-google-ad-now-what--q7zjaf9se#faq","mainEntity":[{"@type":"Question","name":"What is the browser lockup scam that shows a fake security warning and tells you to call a phone number?","acceptedAnswer":{"@type":"Answer","text":"It is a scareware tech support scam delivered through malicious Google Ads on legitimate high-traffic sites like maps, weather, and real-estate pages. The ad triggers a fullscreen overlay that hides the cursor, blocks normal exit keys, and lags the browser to simulate a frozen or infected machine, pressuring victims into calling a bogus number where scammers demand fees, remote access, or personal information. Nothing is actually locked or infected. Staying current on scam techniques like this one helps you protect family members before they get caught out; daily.dev surfaces security research for exactly that."}},{"@type":"Question","name":"How widespread was the recent Google Ads tech support scam campaign detected by Netskope?","acceptedAnswer":{"@type":"Answer","text":"Netskope observed clicks on the malicious ads from 619 customer organizations between August 31 and September 14, tracking more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites. About 62 percent of affected organizations were based in the US, with Japan and Australia ranking second and third. None of Netskope's customers were actually scammed since the firm blocked the content, but real-world exposure is likely much higher. Tracking the scale of scams like this helps security teams gauge real risk; daily.dev keeps that kind of research close at hand."}}]}
```

