A new study by NYU and Radboud University researchers revealed Google's advertising platform fails to consistently remove malicious "scareware" ads, even after they are reported. The research analyzed Google's Ads Transparency Center. It found hundreds of ads with deceptive claims and scare tactics. These ads garnered over 100 million impressions in Europe. One advertiser alone was responsible for 90 flagged ads.

The study tested Google's reporting system. It found some ads were removed, but others identified as policy violations remained active. In one instance, researchers reported an ad linked to a known malicious domain. This led to the removal of that single ad. However, 41 other ads pointing to the same malicious domain remained active. The findings expose a significant gap in Google's ad policy enforcement, allowing bad actors to operate at scale for extended periods.