Google Ads Security: How to Protect Your Account from Recent Hacks

In my first year working in paid media, I caught my first major account hack… almost by accident.

I was easing into the day, scanning our agency’s Google Ads MCC and doing a quick gut check on top-level client metrics. At the time, we used a strict account naming convention that included each client’s monthly budget, which made any pacing issues jump out immediately.

As I scrolled down, I hit a cluster of accounts managed by a close colleague, and something stopped me. One account showed today’s ad spend at more than three times its entire monthly budget of $1,000.

Not for the month. For the day. At around 10am.

Within minutes, it was clear what had happened: the account had been compromised and hijacked for ad spend. The goal wasn’t subtle; buy as many ads as possible, as fast as possible, and let someone else pick up the tab.

A few years later, during the COVID era, we saw a different version of the same story. A client was using a shared login for their Meta Ads account, a shortcut that may have felt harmless at the time. That account was eventually hacked, and while DTC had no role in the vulnerability itself, the recovery took literally months. Endless back-and-forth with support. Rebuilding trust. Cleaning up access. Freezing credit cards (which affected other funding). Rebuilding and restarting campaigns.

In both cases, the damage wasn’t just financial (in fact, the ad platforms helped ensure legitimate companies weren’t charged for fraudulent ad spend). It was unnecessary anxiety, distraction, and an enormous amount of people-time spent on work that produced zero value. More than mildly inconvenient. And in both cases, the end goal was the same: hijack legitimate ad accounts to fund someone else’s campaigns.

That’s why recent reports of Google Ads and Meta Ads account compromises, including agency-level access (recent MCC hacks), aren’t just “industry news.” They’re a reminder that small security gaps can create outsized problems, even when no one has done anything wrong intentionally.

Most (if any) Google Ads and Meta Ads account “hacks” don’t involve someone breaking into Google or Meta’s infrastructure. In almost every case, attackers are exploiting access, trust, or routine behavior. And the attacks are evolving; many attempts may look legitimate at first glance.

The goal is rarely data theft. It’s much simpler: hijack real ad accounts to spend money quickly and disappear before anyone can react.

Here are the most common attack paths we’re seeing today.

1. Fake “Official” Outreach

Attackers frequently impersonate Google, Meta, or partner programs using emails or ads that look legitimate.

These messages:

  • Reference real programs (Google Partners, onboarding, betas)
  • Use official-looking branding and language
  • Ask users to continue setup, verify access, or become a partner

Clicking through often leads to convincing fake login pages designed to capture credentials or session access. In some cases, attackers have even used Google Ads to promote these fake pages, adding another layer of credibility.

One tell in the email above is the “email from” line – if it’s not the main Google TLD, it’s not legitimate (though, still watch for spoofing and close domain variants!). And if you’re an actual Google Partner, they would reference your CID. 

(Source: https://cybernews.com/security/hackers-stealing-google-ads-accounts-publish-fake-ads/)

2. 2FA Fatigue

Even with two-factor authentication enabled, attackers may repeatedly trigger login attempts until a user approves one just to stop the alerts.

This works because:

  • Push notifications feel routine
  • Approvals happen quickly
  • The request doesn’t always feel dangerous

Once approved, access is granted legitimately. And while 2FA is essential, we need to stay vigilant on what requests we approve. 

3. Malicious Extensions & Third-Party Tools

Some compromises don’t involve logins at all.

Malicious or over-permissioned browser extensions and tools can:

  • Steal session cookies or OAuth tokens
  • Bypass passwords and 2FA
  • Maintain access without triggering alerts

These often pose as analytics, automation, or AI tools. If a tool asks for broad access, it deserves scrutiny.

(Source: https://www.esecurityplanet.com/news/chrome-add-on-steals-meta-ad-accounts/ https://www.esecurityplanet.com/news/chrome-add-on-steals-meta-ad-accounts/)

4. Credential Theft & Reuse

If a password is reused or shared, it may already be exposed.

Attackers test known email/password combinations across ad platforms. If 2FA isn’t enforced everywhere, that can be enough to gain access.
(Source: https://www.huntress.com/blog/account-takeover-what-it-is-and-how-to-protect-against-it)

This is why individual logins and unique passwords still matter.

5. “Too Good to Be True” Offers

Some attacks rely entirely on incentive. Below is an example of a recently received example: 

These include promises of:

  • Free ad credits
  • Exclusive access
  • Beta features
  • Urgent approvals or uploads
  • Huge deals & partnerships

It can seem enticing as this version often mentions major brands that smaller agencies could only dream of working with. But, as we’re already a Google Partner (in fact, a Premier Partner – which has a different version of the partner’s badge) this becomes easy to categorize as a scam. At DTC, we similarly receive “leads” that dangle another version of this carrot via our website. Hackers posing as large brands with big ad spends reach out saying they need our help and request email addresses of our experts to provide account access. Our priority will always be the security of our accounts, and we have created a checklist below to help protect your accounts.

Key Steps to Protect Your Accounts:

  • Be cautious with access and linking requests
    • Do not accept unexpected Google Ads, MCC, or CID requests.
    • Always verify requests directly with your agency or marketing partners.
    • Be careful where you sign in with your account credentials & validate all websites/tools.
  • Require two-factor authentication (2FA)
    • Enable 2FA for all users wherever possible.
    • Stay vigilant on what you approve 
  • Use corporate email domains
    • Limit Google Ads access to company-managed emails.
    • Avoid personal Gmail accounts when possible as Gmail is the main attack vector in these recent hacks.
  • Eliminate shared logins
    • Each user should have individual access at all times.
  • Use strong, unique passwords
    • Never reuse passwords across platforms.
  • Clean up account access
    • Remove users who no longer need access across Google Ads, GA4, GTM, and related tools.
  • Be selective with third-party tools
    • Carefully review any tools requesting access via CID or API connections & remove these links when they are no longer needed.
  • Apply the same precautions across platforms
    • These principles apply to Meta, LinkedIn, and other ad platforms as well.


At the end of the day, it’s unlikely we see an end to these account hacks. The best we can do is stay vigilant and informed about the latest attack methods. From there, educate your teams & keep your access tight. View-only access can at worst, create a data leak, and admin access can go as far as locking your whole team out of your accounts while you work with support to make the situation right. These attacks are becoming more sophisticated over time and a far cry from our old friend, the Nigerian prince: best of luck out there!

Read more from our blog