$41K+ hijacking, fully recovered.
- Context
- An advertising account compromised through unauthorized access, with malicious campaigns spending against the client's payment method over a short window.
- Problem
- More than $41,000 of unauthorized spend, active malicious campaigns, and no documented timeline of how access was obtained. First-line platform support was responding with templates, and the evidence needed for a credit claim was degrading by the day.
- Role
- My role: led the forensic response, the documentation, and the platform escalation end to end. Team: the client's internal IT secured the surrounding Google Workspace accounts.
- Work
- Contained the incident (access revoked, payment methods frozen, malicious campaigns paused) then reconstructed the access timeline from change history and account security events, separated malicious from legitimate spend, and prepared the unauthorized spend claim to a standard that would survive escalation past first-line support. Hardened the estate afterwards: two-factor enforcement, an access matrix rebuild, manager account isolation, and spend anomaly alerting.
- Outcome
- Full recovery of the $41,000-plus in unauthorized spend, and a hardened access model across the remaining accounts.
- Stack
Containment first, then evidence
In an active account compromise the order of operations is not optional. Containment came first: access revoked, payment methods frozen, and the malicious campaigns paused, because every hour of delay was more unauthorised spend against the client's card. Only once that stopped did the work turn to evidence, and it turned there quickly, because the record needed for a credit claim was degrading by the day as new events pushed older ones out of view.
Reconstructing the access timeline meant working back through change history and account security events to establish how access was obtained and what was done with it, then separating malicious spend from legitimate spend so the claim covered exactly the unauthorised amount and no more. First-line platform support was answering with templates, so the evidence had to be assembled to a standard that would survive escalation past it.
A claim that holds, and an estate that is harder to hit
The unauthorised-spend claim was prepared to that standard deliberately, because a claim that falls apart under scrutiny returns nothing however real the loss. Full recovery of the more than forty-one thousand dollars followed from the documentation being good enough to withstand escalation, not from the size of the loss alone.
Recovery is only half of an incident response worth the name; the other half is making the same attack harder next time. Afterwards the estate was hardened: two-factor enforcement, a rebuilt access matrix, manager-account isolation, and spend-anomaly alerting so an unusual pattern is noticed early rather than reconstructed later. The client's internal IT secured the surrounding Google Workspace accounts, because the advertising account is rarely the only door once one has been found open.
An access problem wearing a spend problem's clothes
The recovery got the attention, but the reconstruction is what revealed the real issue: this began as an access problem, not a bidding one. Rebuilding who had access to what consumed more of the effort than the containment did, and the answer, as it usually is, was that more people had more access than anyone believed. An incident is often the first time an organisation learns the true shape of its own access model.
That is why the hardening afterwards was not a formality. Two-factor enforcement, a rebuilt access matrix, manager-account isolation, and spend-anomaly alerting each close a specific door the incident showed to be open. The uncomfortable part is that the control which would have prevented the whole episode was a policy decision available months earlier and far cheaper than the recovery. That is the general lesson worth taking from one specific bad day: the access model is the cheapest part of this to get right early, and the most expensive to fix late. Every control added afterward was one that could have been set before the account was ever touched, at a fraction of the cost of the recovery it followed.
Further reading
- Bidding on competitor brand terms in Canada
The keyword question and the ad copy question have different rules, and most arguments about this conflate them.
- Structuring an account that runs four months a year
The problem with a seasonal account is not the season. It is the eight months of nothing that sit in front of it.
- LegitScript certification for Google Ads, explained
It is an evidence exercise with renewal dates, not a one-time form.
- The feed fields that actually decide whether you show
The product data specification lists dozens of attributes without ranking them. Working through it top to bottom is how a feed project takes six weeks and still gets disapproved.