Your Google Ads account was hacked. The first four hours
Most of the difference between full recovery and partial recovery is decided before you finish reading this.
In the first four hours of a Google Ads account compromise: revoke unrecognised access, freeze the payment method, pause campaigns you did not create, and enforce two-factor on every Google account with admin rights. Then stop. Do not delete campaigns, users or history: deletion destroys the evidence a spend recovery claim depends on, and it is the most common self-inflicted wound in these incidents.
Do these four things now
Revoke every access you do not recognise, at both the account and manager level. Remove or freeze the payment method. Pause the campaigns you did not create. Reset passwords and enforce two-factor authentication on every Google account with admin access, starting with whichever is most likely to be the entry point.
That sequence stops the bleeding. Everything after it is about recovering what already left.
A compromised ad account is a finance incident with a marketing surface. Spend leaves in hours, not weeks, which is why containment comes before diagnosis.
Report it to Google in the same window rather than after you have finished tidying. Google's guidance is to report a compromised account as soon as possible, and the report starts a clock you want running early. It also warns that where Google itself suspects compromise, the account is temporarily suspended, so a suspension arriving in the middle of an incident is a symptom rather than a second disaster.
Then stop, and do not delete anything
This is the part people get wrong under pressure. Do not delete the malicious campaigns. Do not remove the unauthorised users beyond revoking their access. Do not clear browser history on the affected machine.
Change history, access records and account security events are the evidence a spend claim rests on. They are finite and time-boxed. Deleting the campaigns feels like cleaning up and is actually destroying the record that proves the spend was not yours.
What change history can and cannot show
Know what that record can and cannot tell you. Google's change history covers the past two years and names the user who made each change, by email address, when the change came through the interface. Automated and API changes appear under system or tool names instead, and the page notes that not every account-level settings change is listed. So the history is strong evidence of campaign and budget manipulation, and weaker evidence of how access was obtained. Both belong in the timeline, labelled for what they are.
Escalation reads evidence
A claim built on a documented, coherent timeline behaves entirely differently in escalation than one built on a description of events. First-line platform support is not where recovery is decided. Escalation is, and escalation reads evidence.
Two-factor is a precondition, not just hygiene
Most people treat enabling two-step verification as the thing you do afterwards, once the emergency is over. On Google Ads it is part of the claim itself. Google states that you must complete account recovery to be eligible for reimbursement, and that a reimbursement request for unauthorised charges is submitted after the account is reactivated and 2-Step Verification is turned on.
Read that as a sequence rather than advice. Recovery, then reactivation, then 2-Step Verification, then the request. An organisation that delays the security change while it debates rollout is delaying the money.
It applies to the Google accounts, not the ad account, because that is where the login lives. Turning on 2-Step Verification on every account with admin access is the actual task, and the weakest one decides the outcome.
Set expectations on timing at the same time, because someone will ask. Google says billing investigations can take 10 to 15 business days. That is the window in which nothing appears to happen, and it is when badly documented claims quietly die.
How this usually happened
Almost always through a compromised Google account with admin access, rather than a breach of Google itself. Phishing, credential reuse, or a session token stolen by a browser extension.
That is why hardening happens at the identity layer rather than inside Google Ads. The advertising account was the target; the person's Google account was the door. Google's own account security best practices put two things first that read as administrative rather than technical: remove access for people who have left, and give every person their own login rather than sharing one.
Shared logins destroy your own timeline
The shared login is worse than it looks, and the reason is forensic. Change history attributes actions to the email address that performed them. If four people use one login, every action in the record belongs to one identity, and the attacker's actions are indistinguishable from your team's. You have destroyed your own timeline before the incident started.
The entry points to check
Accounts with no enforced two-factor and standing third-party access are the usual entry points. If you are reading this preventively, those two are the highest-value things to fix today.
Check the Google account itself as well as the ad account. Google publishes a recent security activity review that shows sign-ins, new devices and permission grants, and it frequently dates the intrusion earlier than the spend does.
Preventive hardening versus incident response
| Preventive hardening | Incident response | |
|---|---|---|
| Trigger | Scheduled | Active compromise |
| Duration | Days | 1 to 2 weeks plus platform time |
| Cost | Materially lower | Higher, plus the lost spend |
| Outcome | Controlled, certain | Depends on a platform decision |
| What you get | Access matrix, 2FA, alerting | Timeline, claim, hardening, report |
The Outcome row is the honest one. Hardening produces a result you control. Recovery produces a claim, and whether it succeeds is Google's decision, not yours or your provider's.
Anyone guaranteeing recovery of hijacked spend is guessing on your behalf. What is genuinely within anyone's control is containment speed and evidence quality.
The Duration row also understates the second column, because platform time runs after your work finishes. Budget for the investigation window on top of the response, and tell whoever is asking about the money that the two are sequential rather than concurrent.
What recovery actually depends on
Three things. How fast containment happened. Whether malicious spend can be cleanly separated from legitimate spend in the same window. And whether the access timeline is documented rather than narrated.
The separation is the part most people underestimate. If your own campaigns kept running throughout, the invoice is a single number covering both, and somebody has to reconstruct which spend was whose, by campaign, by day, from change history and reporting. Do that before you write to Google, not in response to being asked.
Kodelytics led the forensic response on a compromise involving more than $41,000 of unauthorised spend, and recovered it in full: containment, a reconstructed access timeline, a separated spend figure, and a claim pursued past first-line support. That outcome is not a promise for the next incident, because fund recovery is a platform decision.
What generalises is the method, which is what ad account security and compromise recovery is scoped around: contain inside twenty-four hours, document to the standard a credit claim requires, then harden the estate so it does not recur.
After the money question is settled
Hardening is the part that decides whether you do this again. Two-factor enforced rather than encouraged. An access matrix rebuilt so you know who has what at which level. Manager account isolation, so one compromised login does not reach everything. Billing controls, and alerting on spend anomalies so the next event is caught in hours rather than days.
Individual logins are the cheapest item on that list and the one most often skipped, because a shared account is convenient and the cost of it only appears during an incident. It is the difference between a timeline and a guess.
If you run many accounts, the access governance half of that belongs with the MCC layer rather than being handled account by account. Thirty accounts secured individually is thirty chances to miss one.
One last thing worth separating from the security work. If the account was suspended rather than only drained, the reason matters: a compromise suspension and a policy suspension are different processes with different evidence, and treating a policy suspension as a security incident wastes the appeal window.