In my first year working in paid media, I caught my first major account hack… almost by accident.
I was easing into the day, scanning our agency’s Google Ads MCC and doing a quick gut check on top-level client metrics. At the time, we used a strict account naming convention that included each client’s monthly budget, which made any pacing issues jump out immediately.
As I scrolled down, I hit a cluster of accounts managed by a close colleague, and something stopped me. One account showed today’s ad spend at more than three times its entire monthly budget of $1,000.
Not for the month. For the day. At around 10am.
Within minutes, it was clear what had happened: the account had been compromised and hijacked for ad spend. The goal wasn’t subtle; buy as many ads as possible, as fast as possible, and let someone else pick up the tab.
A few years later, during the COVID era, we saw a different version of the same story. A client was using a shared login for their Meta Ads account, a shortcut that may have felt harmless at the time. That account was eventually hacked, and while DTC had no role in the vulnerability itself, the recovery took literally months. Endless back-and-forth with support. Rebuilding trust. Cleaning up access. Freezing credit cards (which affected other funding). Rebuilding and restarting campaigns.
In both cases, the damage wasn’t just financial (in fact, the ad platforms helped ensure legitimate companies weren’t charged for fraudulent ad spend). It was unnecessary anxiety, distraction, and an enormous amount of people-time spent on work that produced zero value. More than mildly inconvenient. And in both cases, the end goal was the same: hijack legitimate ad accounts to fund someone else’s campaigns.
That’s why recent reports of Google Ads and Meta Ads account compromises, including agency-level access (recent MCC hacks), aren’t just “industry news.” They’re a reminder that small security gaps can create outsized problems, even when no one has done anything wrong intentionally.
Most (if any) Google Ads and Meta Ads account “hacks” don’t involve someone breaking into Google or Meta’s infrastructure. In almost every case, attackers are exploiting access, trust, or routine behavior. And the attacks are evolving; many attempts may look legitimate at first glance.
The goal is rarely data theft. It’s much simpler: hijack real ad accounts to spend money quickly and disappear before anyone can react.
Here are the most common attack paths we’re seeing today.
Attackers frequently impersonate Google, Meta, or partner programs using emails or ads that look legitimate.

These messages:
Clicking through often leads to convincing fake login pages designed to capture credentials or session access. In some cases, attackers have even used Google Ads to promote these fake pages, adding another layer of credibility.
One tell in the email above is the “email from” line – if it’s not the main Google TLD, it’s not legitimate (though, still watch for spoofing and close domain variants!). And if you’re an actual Google Partner, they would reference your CID.
(Source: https://cybernews.com/security/hackers-stealing-google-ads-accounts-publish-fake-ads/)
Even with two-factor authentication enabled, attackers may repeatedly trigger login attempts until a user approves one just to stop the alerts.
This works because:
Once approved, access is granted legitimately. And while 2FA is essential, we need to stay vigilant on what requests we approve.
Some compromises don’t involve logins at all.
Malicious or over-permissioned browser extensions and tools can:
These often pose as analytics, automation, or AI tools. If a tool asks for broad access, it deserves scrutiny.
(Source: https://www.esecurityplanet.com/news/chrome-add-on-steals-meta-ad-accounts/ https://www.esecurityplanet.com/news/chrome-add-on-steals-meta-ad-accounts/)
If a password is reused or shared, it may already be exposed.
Attackers test known email/password combinations across ad platforms. If 2FA isn’t enforced everywhere, that can be enough to gain access.
(Source: https://www.huntress.com/blog/account-takeover-what-it-is-and-how-to-protect-against-it)
This is why individual logins and unique passwords still matter.
Some attacks rely entirely on incentive. Below is an example of a recently received example:

These include promises of:
It can seem enticing as this version often mentions major brands that smaller agencies could only dream of working with. But, as we’re already a Google Partner (in fact, a Premier Partner – which has a different version of the partner’s badge) this becomes easy to categorize as a scam. At DTC, we similarly receive “leads” that dangle another version of this carrot via our website. Hackers posing as large brands with big ad spends reach out saying they need our help and request email addresses of our experts to provide account access. Our priority will always be the security of our accounts, and we have created a checklist below to help protect your accounts.
At the end of the day, it’s unlikely we see an end to these account hacks. The best we can do is stay vigilant and informed about the latest attack methods. From there, educate your teams & keep your access tight. View-only access can at worst, create a data leak, and admin access can go as far as locking your whole team out of your accounts while you work with support to make the situation right. These attacks are becoming more sophisticated over time and a far cry from our old friend, the Nigerian prince: best of luck out there!