Summary
We analysed how subscription scams are distributed through Google Ads. These schemes lure consumers into entering payment details for seemingly cheap or simple services, such as IQ tests, PDF tools, or CV creation, while the actual subscription costs are hidden in the fine print or not disclosed transparently at all. Google becomes a central distribution channel because these ads appear prominently above organic search results and can therefore exploit the trust users place in top-ranked sponsored results.
To assess the scale of the problem, we reviewed the 100 most recent Watchlist Internet entries in the category "subscription scams”, extracted the associated domains, and checked whether and how they were advertised through Google’s ad library. We found ads for 43 of the 100 Watchlist entries, run by 34 accounts - some running ads for multiple domains. We then tracked how many ads these accounts ran in total between January 1st to November 30th 2025, identifying 27,775 ads shown to Austrian users.
Our findings point to clear enforcement gaps. ÖIAT reported 19 of the initially 43 identified ads as a Trusted Flagger, yet even after more than six weeks there was no substantive response beyond the automatic confirmation of receipt. Google’s ad library also falls short as a DSA transparency tool. It provides only broad reach estimates, offers no meaningful breakdown of targeting parameters, and allows searches only by advertiser name or specific URL, not by keywords, content, or product category. This makes thematic research and the identification of problematic advertising much harder, especially in cases where the advertiser or domain is not already known.
Recommendations
Improve the Google Ads Library's search and transparency: Google should enable keyword- and content-based search in its ad library, and provide granular targeting and reach data.
Treat deceptive subscription advertising as a systemic risk: Google should recognize the scale and consistency of subscription scam advertising documented here as a systemic risk under Article 34 DSA, and implement effective measures to prevent it, as required under Article 35 DSA.
Respond to Trusted Flagger reports within a reasonable timeframe: Google should ensure timely, substantive responses to Trusted Flagger reports.

