TutorialsSecurity

The Hijacked Ad Accounts: How Media Buyer Logins Became a Black-Market Commodity

propellerads-hikacked-ad-accounts

A media buyer logs into what looks like the Google Ads homepage after a routine search. Nothing about the page feels wrong. A few clicks later, a stranger in another country owns the account, the campaigns, and whatever budget is still sitting in it. By the time the real owner notices, the account has often already been sold.

Ad account hijacking has stopped being a rare, unlucky event. Search Engine Land reported a surge in Google Ads manager account (MCC) takeovers through late 2025, with agencies describing the same pattern on LinkedIn, Reddit, and Google’s own help forums: an account with admin access to dozens of client accounts falls, and every campaign underneath it falls with it.

This guide explains why these accounts have become worth stealing in the first place, how the theft actually happens, and what a buyer can realistically do about it.


Key Takeaways:

  • Stolen ad accounts are resold on criminal forums because a verified account with real spending history is worth more than the cash sitting in it.
  • Most hijacks do not rely on stolen passwords. They rely on convincing phishing pages, fake job offers, and OAuth-style access requests that look like routine platform emails.
  • Financial damage moves fast: one documented case saw tens of thousands of dollars spent within 24 hours of a takeover.
  • Recovering a hijacked account can take anywhere from a few days to several months, and reputation with the platform can take even longer to rebuild.
  • Regulators are starting to expect platforms, and not only individual users, to carry some responsibility for account security.

What Ad Account Hijacking Is and Why It Became a Black-Market Trade

Ad account hijacking is the unauthorized takeover of an advertiser’s account, usually through stolen credentials or a fraudulent access grant, followed by the attacker using that account to run their own campaigns, drain its budget, or sell access to someone else. It is a specific and more damaging cousin of ordinary account fraud, because an ad account works as a spending vehicle with a credit history attached. Losing one means losing more than a login.

That history is the real prize. A new, unverified account can only spend so much before a platform’s own risk systems start throttling it.

An account with months of clean spend, a verified business identity, and no policy strikes can push a much larger budget through before anyone looks twice. Malwarebytes documented a campaign where criminals phished thousands of Google Ads accounts specifically to resell them on blackhat forums, keeping only some for their own use. The stolen login is a commodity because the trust attached to it is transferable.

That distinction matters for anyone trying to defend against this. A buyer who only thinks about protecting their password is defending the wrong thing. What is actually being targeted is the reputation the account has accumulated, and reputation cannot be reset with a password change.


Inside the Attack: How Media Buyer Logins Get Stolen

Almost none of the recent large-scale incidents involved brute-forcing a password. The attacks that worked were social engineering, dressed up to look exactly like something the victim already expected to see.

The most documented pattern starts with a fake ad. Someone searches “Google Ads” to get to their login page, a habit most buyers have without thinking about it, and clicks the sponsored result at the top.

That result leads to a page hosted on Google Sites or a similar trusted domain, which then forwards to a phishing kit built to harvest the exact credentials and two-factor codes a real login would ask for. Search Engine Land and Malwarebytes both traced this pattern to multiple criminal groups operating in parallel, some Brazilian, some based in Asia, running near-identical kits with different regional targeting.

A second pattern skips the fake ad entirely and goes after the person instead of the login page. Google’s Threat Intelligence Group documented a Vietnam-based cluster, tracked as UNC6229, that posts fake remote job listings aimed specifically at people who work in digital advertising and marketing. Applicants who respond are sent what looks like a skills test or an onboarding file. Opening it installs malware that gives the attacker remote access to the device, and from there, to whatever ad accounts that device can already reach.

How an Ad Account Hijack Unfolds

Five stages, not one event. Only two of them are still the buyer’s to control.

  1. 01

    Lure arrives

    A fake sponsored ad or fake job offer reaches the target.

  2. 02

    Target acts on it

    They click through or open the file, expecting something routine.

  3. 03

    Access is captured

    Credentials, or the device itself, are handed to the attacker.

  4. 04

    Attacker takes over

    A new admin appears on the account. Spending or resale starts.

  5. 05

    Owner finds out

    A billing alert or locked login is the first signal, often days later.

The last point the buyer controls

Everything before stage three is a decision. Everything after it is cleanup, and documented cases show most of the money leaving before stage five arrives.

What connects both patterns is timing. The attacker does not need the account for long. Malwarebytes reported that in one wave, criminals kept at least one malicious ad running around the clock even as dozens were reported and taken down, because the economics only require a short window of live access to extract value.


The Real Cost: Money, Time, and Reputation

The financial hit lands fast. Search Engine Land’s coverage of the MCC hijacking wave cited a case where attackers burned through tens of thousands of dollars in fraudulent spend within 24 hours of gaining access to a single manager account. Recovery timelines varied wildly across the reported cases, from a few days to several months, depending on how quickly the takeover was noticed and how much documentation the account owner could produce for the platform.

Money is the visible damage. The quieter cost is what happens to the account’s standing once a platform’s fraud systems have flagged unusual activity on it, even after access is restored.

An account that briefly ran phishing ads or malware-laced campaigns under someone else’s control does not automatically get a clean slate. Rebuilding trust signals with a platform’s automated systems, and sometimes with a human reviewer, is a slower process than restoring login access.

There is a third cost that rarely makes it into the incident reports: client relationships. An agency that loses control of a manager account ends up explaining a lost or misspent budget to every client whose account sat underneath that manager account (MCC), on top of explaining the security failure to the platform itself. Some of those clients will not wait around for a full post-mortem before asking whether their money is safe with that agency at all.

propellerads-adware-detection

Why a Verified, High-Spend Account Is Worth More Than the Cash Inside It

Here is the part most coverage of this problem skips. Buyers tend to assume the incentive for hijacking an account ends once the remaining budget is spent. It does not. The account itself, once verified and carrying a track record, keeps generating value long after its original balance is gone.

A fresh account with no history gets rate-limited fast by most platforms’ own anti-fraud logic. A verified account with months of clean, tier-1 spend behind it does not trip those same limits, at least not immediately.

That is exactly why resale is part of the business model documented by both Malwarebytes and Google’s threat researchers.

Criminals are extracting a reusable asset, worth more to someone else than the leftover budget was worth to them directly, rather than simply spending down a balance.

From a buying-side perspective, this changes what “protecting the account” should actually mean. Rotating a password after a scare treats the account like a wallet that got picked once. Treating it like what it actually is, a trust profile that took months to build and can be resold the moment it is compromised, changes which defenses are worth prioritizing. Recovery speed and admin-list hygiene matter as much as the login screen itself.

PropellerAds - infostealer marketing tools threatening browser sessions and advertising accounts

What Regulators Are Starting To Require

Account security is no longer treated purely as the advertiser’s problem to solve alone. Ofcom, the UK’s communications regulator, opened a consultation in July 2026 on a draft Fraudulent Advertising Code of Practice that would apply to the largest social media and search platforms operating in the UK.

Two of the proposed measures speak directly to this problem. One would require platforms to run an account security mechanism on every advertising account. Another would require an accessible, easy-to-use reporting channel specifically for account takeovers, with a defined review process for deciding whether a compromise occurred and whether the account still poses a risk before access is restored.

None of this is in force yet. The consultation runs until October 2026, with a final statement expected by mid-2027 at the latest. It signals a direction rather than an immediate obligation, but the direction matters for a buyer’s own risk calculus.

Platforms are moving toward duties around detecting and undoing a takeover, not toward eliminating the underlying phishing and social engineering that causes one, which means the buyer’s own habits stay the first line of defense regardless of what the regulation eventually requires.

Our Ads Safety Report Q2 2026 breaks down what's changed since Q1: malware overtakes adult content as the top rejection driver, cloaking stays the leading cause of suspensions, and Tier-1 markets and Turkey remain under close watch.

Buyer-Side Defenses: What You Can Actually Control

A buyer cannot stop a criminal group from posting a fake job listing or buying a fraudulent search ad. What a buyer can control is how much of that lure actually reaches a real login screen or a real device, and how fast a compromise gets caught if it happens anyway.

A short set of habits accounts for most of the realistic defense available to a buyer today:

  • Type the platform’s URL directly, or use a saved bookmark, instead of searching for “Google Ads” or “Meta Business Suite” and clicking the sponsored result.
  • Treat any unexpected access request, invitation, or “verify your account” email as suspicious by default, even when it carries the right logo and a matching-looking domain.
  • Review the admin and user list on every manager account on a regular schedule, not only after something feels wrong.
  • Be skeptical of unsolicited job offers or freelance gigs in digital advertising that ask for a downloaded “test” or “assessment” file before any real conversation happens.
  • Keep a written record of who has access to which account and why, so a sudden new admin name stands out immediately instead of blending in.

None of these habits are exotic. What makes them effective is consistency, not sophistication. A buyer who reviews the admin list on their manager account (MCC) every week will spot an unfamiliar name faster than one relying on a platform alert that may arrive after real damage is already done.

Attack Vector vs. Buyer-Side Defense

Each lure has one habit that actually interrupts it. A generic checklist does not.

Attack vector How it reaches the buyer Defense that actually helps

Fake sponsored login ad

Search
Sits at the top of the results when you look up the platform name instead of typing its address, and forwards to a login page built to capture credentials and two-factor codes. Bookmark the login page and use only the bookmark. Never arrive at a login screen through a search result, sponsored or not.

Fake job posting with a malware file

Inbox
Arrives as a remote role aimed at advertising and marketing people, with a skills test or onboarding document to open before any real conversation. Treat an unsolicited test or assessment file as a hard no. Legitimate hiring does not open with a download.

Access invitation that looks routine

Email
Impersonates a standard platform notification asking you to grant or confirm access, complete with the right logo and a domain close enough to pass a glance. Check pending access requests inside the dashboard yourself. Act on the platform, never on the link in the message.

Unreviewed admin list

No lure
Nothing arrives at all. Once inside, the attacker adds their own user to a manager account and waits, because an unread admin list is the quietest place to sit. Review the admin and user list on a fixed weekly schedule. An unfamiliar name only stands out to someone who knows the list.

What the Anti-Fraud Layer Does Beyond Your Login

Buyer habits reduce the odds of a hijack starting, but they are not the only layer worth having. Networks and anti-fraud teams sit in a position individual buyers do not occupy, since they can see patterns across many accounts and campaigns at once, well beyond any single buyer’s own view.

Adex, the anti-fraud platform, documented a case where its specialists caught a phishing scheme disguised as a routine mobile subscription offer. The scheme asked users to “confirm” a phone number by entering a code, except the code was a real Telegram login code, and entering it handed the account straight to the attacker. Adex traced the scheme across multiple domains and a cluster of advertisers running the same flow before shutting it down.

The target there was a consumer’s messaging account rather than an advertiser’s ad account, but the mechanic is the one this article is about: a login handed over voluntarily, inside a flow that looked like something routine. The difference between losing a Telegram account and losing a manager account is what the credential is attached to, not how it was taken.

propellerads-ransomware-economy

Buyer vigilance still matters, but that case shows why it is not enough on its own: some fraud patterns are only visible at scale, across many campaigns and accounts at once. 

Detection at that level rarely turns on a single obvious red flag.

It turns on a cluster of small, individually plausible signals: a slightly unusual redirect chain, a landing page copy-pasted across a dozen otherwise unrelated advertisers, a phone-verification step where none should exist. Each of those looks harmless on its own.

Cross-account visibility matters for hijacking specifically, because of what a takeover looks like from a platform’s side. The resale value of a stolen account rests on the assumption that an established account gets treated as established, which means the useful signal is not how old an account is but a change in how it behaves: a new payment method, a sudden shift in the geos being targeted, a creative set with nothing in common with what the account ran last month.

Any one of those is something a legitimate advertiser does occasionally. Together they are the shape a takeover usually has, and they only become visible after signup, not at it.

The same logic explains where identity verification fits, which is not where most buyers assume. An account only carries resale value if the trust attached to it survives a change of operator. Verification at signup, and re-verification when the details on an account start moving, is what breaks that transfer: whoever buys a stolen login inherits the spend history but not the verified identity behind it.


If Your Account Gets Hijacked: The Recovery Routine

Speed matters more than almost anything else once a hijack is confirmed. The gap between noticing something is wrong and actually locking the attacker out is where most of the financial damage in the documented cases actually happened.

  1. The first move is reporting the compromise to the platform through its official channel, not through a support email address found via a search result, since fake support contacts are part of the same criminal playbook. Most platforms will ask for evidence: unfamiliar login locations, unrecognized admin additions, unexplained campaigns. Having a habit of screenshotting the admin list periodically, mentioned earlier, pays off directly here, because it gives a concrete before-and-after to show a reviewer.
  2. The second move is documentation for reimbursement conversations. AdExchanger’s reporting on the Google Ads hijacking wave noted that affected agencies generally had to submit proof of the compromise and commit to stronger account security practices before a platform would consider reimbursement. That is a real limitation worth stating plainly: reimbursement is not automatic, and it is not guaranteed. Some of the loss may simply not come back, which is exactly why prevention carries more weight than recovery in this particular fight.
  3. The third move is the one buyers skip most often: assuming the account itself needs a trust rebuild rather than only a password reset. Expect closer scrutiny on campaigns from that account for a while after recovery. That is not a punishment so much as the platform doing the same reasonable thing a bank would do after a card gets cloned.
propellerads-malicious-ads-prevention

FAQ

What is ad account hijacking?

Ad account hijacking is the unauthorized takeover of an advertiser’s account, typically through phishing or social engineering rather than brute-force password attacks. Once inside, attackers spend the account’s budget on their own campaigns, use it to distribute malware or further scams, or sell access to the account itself on criminal forums.


Why are ad accounts specifically valuable to criminals?

An account’s spending history and verification status let it push much larger budgets through a platform’s fraud filters than a brand-new account could. That trust profile is the actual asset being stolen, and it retains resale value even after the original budget is exhausted.


How do most ad account hijacks actually happen?

The documented large-scale cases relied on fake sponsored ads that redirect to convincing phishing pages, and on fake job postings targeting people who work in digital marketing, sent with malware disguised as a skills test or onboarding document. Straightforward password brute-forcing was rarely the entry point.


Can a hijacked account be fully recovered?

Access can usually be restored, though the documented timelines ranged from a few days to several months. Financial reimbursement from the platform is not automatic and generally requires documentation of the compromise. The account’s standing with the platform’s fraud systems may also take longer to normalize than the login access itself.


Are regulators doing anything about this?

Ofcom’s draft Fraudulent Advertising Code of Practice, opened for consultation in July 2026, proposes requiring platforms to run account security mechanisms and accessible account-takeover reporting channels. The rules are not yet in force and are not expected before 2027, so buyer-side habits remain the more immediate line of defense.


Wrapping Up

The uncomfortable truth about ad account hijacking is that it rarely takes a sophisticated hack. It takes one click on a search result that looked exactly like the real thing, or one downloaded file that looked exactly like a job application step. The defenses that actually work are just as unglamorous: bookmark your login, review your admin list on a schedule, and treat every unexpected access request as guilty until proven innocent.

The bigger shift worth internalizing is what is actually being stolen. The months of clean spend and verified identity behind the account matter more than the budget sitting inside it, which is precisely why the account keeps having value to a criminal long after the balance hits zero.

Defending the login is necessary. Defending the reputation attached to it is the part most buyers still overlook.

Come join us on Telegram for more insights and communications with fellow-affiliates!

Trends

View more posts