Ad account compromise · Security & incident response

$41K+ hijacking, fully recovered.

Context
An advertising account compromised through unauthorized access, with malicious campaigns spending against the client's payment method over a short window.
Problem
More than $41,000 of unauthorized spend, active malicious campaigns, and no documented timeline of how access was obtained. First-line platform support was responding with templates, and the evidence needed for a credit claim was degrading by the day.
Role
My role: led the forensic response, the documentation, and the platform escalation end to end. Team: the client's internal IT secured the surrounding Google Workspace accounts.
Work
Contained the incident (access revoked, payment methods frozen, malicious campaigns paused) then reconstructed the access timeline from change history and account security events, separated malicious from legitimate spend, and prepared the unauthorized spend claim to a standard that would survive escalation past first-line support. Hardened the estate afterwards: two-factor enforcement, an access matrix rebuild, manager account isolation, and spend anomaly alerting.
Outcome
Full recovery of the $41,000-plus in unauthorized spend, and a hardened access model across the remaining accounts.
Stack
  • Google Ads
  • Google account security
  • MCC access governance

Containment first, then evidence

In an active account compromise the order of operations is not optional. Containment came first: access revoked, payment methods frozen, and the malicious campaigns paused, because every hour of delay was more unauthorised spend against the client's card. Only once that stopped did the work turn to evidence, and it turned there quickly, because the record needed for a credit claim was degrading by the day as new events pushed older ones out of view.

Reconstructing the access timeline meant working back through change history and account security events to establish how access was obtained and what was done with it, then separating malicious spend from legitimate spend so the claim covered exactly the unauthorised amount and no more. First-line platform support was answering with templates, so the evidence had to be assembled to a standard that would survive escalation past it.

A claim that holds, and an estate that is harder to hit

The unauthorised-spend claim was prepared to that standard deliberately, because a claim that falls apart under scrutiny returns nothing however real the loss. Full recovery of the more than forty-one thousand dollars followed from the documentation being good enough to withstand escalation, not from the size of the loss alone.

Recovery is only half of an incident response worth the name; the other half is making the same attack harder next time. Afterwards the estate was hardened: two-factor enforcement, a rebuilt access matrix, manager-account isolation, and spend-anomaly alerting so an unusual pattern is noticed early rather than reconstructed later. The client's internal IT secured the surrounding Google Workspace accounts, because the advertising account is rarely the only door once one has been found open.

An access problem wearing a spend problem's clothes

The recovery got the attention, but the reconstruction is what revealed the real issue: this began as an access problem, not a bidding one. Rebuilding who had access to what consumed more of the effort than the containment did, and the answer, as it usually is, was that more people had more access than anyone believed. An incident is often the first time an organisation learns the true shape of its own access model.

That is why the hardening afterwards was not a formality. Two-factor enforcement, a rebuilt access matrix, manager-account isolation, and spend-anomaly alerting each close a specific door the incident showed to be open. The uncomfortable part is that the control which would have prevented the whole episode was a policy decision available months earlier and far cheaper than the recovery. That is the general lesson worth taking from one specific bad day: the access model is the cheapest part of this to get right early, and the most expensive to fix late. Every control added afterward was one that could have been set before the account was ever touched, at a fraction of the cost of the recovery it followed.

Further reading