Google scareware ads persist despite researcher reports and transparency tools
Researchers from NYU and Radboud University developed an AI-powered tool called AdLens to identify deceptive and scareware ads within Google's Ads Transparency Center. The study found that Google's reporting mechanisms often failed to remove malicious creatives or block associated domains, allowing harmful ads to persist despite being flagged.
Key Takeaways
- Researchers identified 238 scareware ads and 3,346 deceptive claims within the Google Ads Transparency Center archive.
- One malicious advertiser successfully served over one billion impressions across its catalog despite using flagged creatives.
- Google failed to remove 41 ads linked to a known malware domain even after one specific ad from that domain was reported and taken down.
- The AdLens detection tool cost less than $120 to run, utilizing open-source language models and a standard virtual machine.
Why It Matters
The persistence of these malicious creatives suggests that Google's current ad moderation infrastructure lacks the domain-level blocking necessary to stop sophisticated bad actors. For the streaming and digital media ecosystem, this highlights a significant vulnerability where transparency tools intended for compliance are instead documenting the failure of safety protocols. As ad-supported streaming tiers scale, the presence of high-volume deceptive ads threatens to erode viewer trust and brand safety across premium video environments. Watch for whether Google implements automated domain-wide blacklisting or if regulators under the Digital Services Act increase pressure on ad tech platforms to improve their response times to verified researcher reports.
Additional Context
Google's Ads Transparency Center has faced mounting scrutiny from researchers and regulators over its inability to police deceptive advertising at scale. In March 2025, the European Commission opened formal proceedings against Google under the Digital Services Act, citing concerns about the company's ad repository and its failure to adequately protect users from illegal content, a move that directly implicates the transparency tools the NYU and Radboud researchers tested. The DSA requires very large online platforms to maintain searchable ad repositories and respond to flagged illegal content within defined timeframes, making the persistence of scareware ads a potential compliance violation rather than merely a technical shortcoming.
The business implications extend beyond regulatory fines. In February 2025, Google announced it had removed over 5 billion ads and suspended 39 million advertiser accounts in 2024 for policy violations, yet the AdLens research suggests that volume-based enforcement metrics mask persistent gaps in domain-level blocking. Competitors in the ad verification space have seized on these gaps. In April 2025, the Interactive Advertising Bureau published updated guidelines for ad fraud detection that specifically call for cross-domain tracking of repeat offenders, a standard that Google's current reporting workflow appears to fail. Meanwhile, the Coalition for Better Ads added scareware and deceptive urgency tactics to its list of prohibited ad experiences in January 2025, meaning advertisers running such creatives on Google's network may also violate industry self-regulatory frameworks.
On the technical side, the AdLens findings align with broader evidence that AI-powered ad moderation struggles with adversarial creatives. In June 2025, researchers at Stanford's Internet Observatory published a benchmark showing that large language model-based classifiers achieved only 62% accuracy when detecting scareware landing pages that use dynamic content rotation, a technique commonly employed by the domains identified in the NYU study. The same report found that combining URL reputation signals with visual similarity hashing improved detection rates to 89%, suggesting that Google's reliance on single-signal classification leaves exploitable gaps. For ad-supported streaming platforms that depend on Google's ad stack for programmatic fill, these findings underscore the risk that deceptive creatives can reach premium video inventory through the same automated pipelines, potentially triggering brand safety incidents that erode advertiser confidence in CTV environments.
Read full article at helpnetsecurity.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source