Drooid Logo
Back to story perspectives

Full Breakdown

User Warns of Google Sponsored Scam Targeting Mac Users

4/12/2026, 9:36:11 PM

Incident Overview: Scam Encounter on Google

A Reddit user, known as Questionaccount2022, recently shared a troubling experience on the r/MacOS forum, detailing how he fell victim to a scam linked to a Google-sponsored search result. The user encountered a URL with the misspelled domain "goolge," which led to a deceptive pop-up that prompted him for sensitive information. Initially mistaking the unusual verification steps for a new anti-AI CAPTCHA method, he proceeded with the commands until he noticed red flags when asked for his administrative password. Fortunately, he refrained from entering the password and restarted his Mac, which he described as "my saving grace."

Community Response and Advice

The Reddit community reacted with a mix of sympathy and concern. Commenters highlighted the legitimacy of the sponsored link, with one user stating, "That's crazy that Google even allows this." Others warned the original poster that he might have already compromised his keychain and advised immediate actions, such as changing passwords and enabling two-factor authentication (2FA). The OP acknowledged the gravity of the situation, noting that he had over 500 accounts accumulated over 15 years.

User's Reflection and Recommendations

In a message to Newsweek, the OP reflected on his experience, attributing his vulnerability to a misunderstanding of the command line. He emphasized the importance of verifying commands before execution, stating, "Never use the command line without understanding the input. It’s the biggest line of defense that all people say." He also cautioned others against blindly trusting Google's top search results, as this type of attack, identified as AMOS infostealer, has been targeting Mac users for the past two years. The malware is particularly dangerous, capable of stealing extensive personal data and bypassing both passwords and 2FA.

Official Responses and Future Implications

As of now, Newsweek has reached out to Google for comments regarding this incident. The OP expressed hope that his data had not been compromised, crediting his decision to avoid the fake malware prompts as a key factor in his defense against the scam.

Criticism of Google's Ad Placement

Critics have raised concerns about the placement of such misleading ads on Google's platform. One commenter remarked, "That's crazy that Google even allows this," highlighting the potential risks posed to users who may not be as tech-savvy. The incident underscores the need for increased vigilance and better protective measures against online scams.

Verbatim Quotes

  • “Never use the command line without understanding the input. It’s the biggest line of defense that all people say. I even thought I would never fall for something like this. Verify everything.” — Questionaccount2022, Reddit User
  • “This type of attack is called AMOS infostealer, and it’s been targeting Mac users for the past two years,” — Questionaccount2022, Reddit User
  • “I hope my data wasn’t exfiltrated,” — Questionaccount2022, Reddit User

This incident serves as a cautionary tale for users navigating online platforms, emphasizing the importance of critical thinking and verification in the digital age.