Skip to main content

How Ad Accounts Get Hacked: Five Common Attack Paths

Five common routes into advertising accounts: infostealers, phishing, malicious app access, stale permissions, and credential stuffing.

Ad accounts combine valuable billing access with established business identities. Attackers may abuse that access to publish unauthorized campaigns, change destinations, or lock legitimate operators out. Account restrictions and disputed charges can follow, but recovery and reimbursement outcomes vary.

Key takeaways

  • Infostealers, phishing, malicious or compromised app access, stale user permissions, and reused credentials are five common paths—not an exhaustive taxonomy.
  • Multi-factor authentication reduces risk, but stolen sessions and real-time phishing can bypass some login defenses.
  • Recovery requires explicit session and app revocation; changing a password alone may not remove every form of access.

Why advertising accounts are targets

A compromised business account may already have billing, users, and campaign history. Meta says business-targeting malware has been used to compromise people connected to business pages and advertising accounts, including malware that scans for links between personal and business accounts in its business-malware report.

Unauthorized use can result in fraudulent campaigns, payment disputes, and platform restrictions. It does not follow that every established account will evade review, that every charge will remain payable, or that every restriction will be permanent.

Attack path 1: Infostealer malware

Infostealers collect data from a device, which may include stored credentials and browser session cookies. A valid stolen session may bypass a fresh password or MFA challenge while that session remains accepted.

DUCKTAIL

WithSecure’s July 2022 DUCKTAIL research describes malware aimed at people with access to Facebook Business accounts. The malware stole browser cookies, used authenticated Facebook sessions, and attempted to hijack business accounts to which the victim had sufficient access. WithSecure also documented targeting of people in marketing and advertising, including LinkedIn-themed lures, in its follow-up report.

The important distinction is that DUCKTAIL is a named operation with specific observed variants. Not every infostealer uses the same lure or account-change technique.

Meta’s May 2023 report describes NodeStealer as one of several malware families targeting business users and explains that some malware attempted to evade two-factor authentication or identify connected business accounts in its malware threat analysis. That supports layered defenses; it does not mean every stolen cookie grants permanent access.

Attack path 2: Phishing and fake support

Phishing messages impersonate a platform, vendor, or colleague and direct the victim to a lookalike sign-in or consent page. Some kits proxy the login as the victim enters it, which can capture credentials and relay one-time codes.

Do not decide whether outreach is legitimate from the sender name alone. Open the platform independently, check its official support or account-quality surfaces, and verify the case there. Legitimate support should not ask you to disclose a password or one-time code; Google likewise says it does not ask for passwords in email, messages, or phone calls.

Attack path 3: OAuth and app permissions

A malicious or compromised third-party app can abuse permissions a user granted through an authorization flow. Permission names, token lifetimes, and revocation behavior differ by platform, so ads_management should not be presented as a universal scope.

Password changes do not necessarily revoke every app token or active integration. Review connected apps and integrations in each platform, remove those you no longer trust, and rotate any vendor credentials or secrets the incident may have exposed.

Attack path 4: Stale employee, contractor, or agency access

Former staff, freelancers, or agencies may retain direct or partner access after work ends. That access may be abused deliberately or compromised later. Shared logins make attribution harder and expand the number of people who can expose the same credential.

Use named user seats, least privilege, and a documented offboarding process. Review people, partners, service accounts, payment roles, and connected tools on a recurring schedule appropriate to your organization.

Attack path 5: Credential stuffing

Credential stuffing replays username-and-password combinations exposed elsewhere. Unique passwords and MFA reduce this risk, but MFA is not a guarantee against phishing proxies, stolen sessions, malicious recovery flows, or compromised endpoints.

Prefer phishing-resistant sign-in methods where supported. Google explains that passkeys are more resistant to phishing, and its general security guidance recommends unique passwords and 2-Step Verification.

What unauthorized use may look like

Some incidents develop in stages: initial access, low-volume tests or permission changes, and then broader campaign activity. That is an example pattern, not a universal sequence or a claim that attacks usually occur on weekends.

Potential indicators include:

  • campaigns, ads, destinations, languages, or geographies you did not approve;
  • budget, bid, schedule, or payment changes you cannot explain;
  • unfamiliar users, partners, apps, or service accounts;
  • security or policy messages tied to ads you did not create; and
  • account activity attributed to an unexpected actor or integration.

One indicator alone may have a benign explanation. Correlate it with account activity, access records, billing, and your launch plan. If you see unauthorized Facebook campaigns, use the guide to identifying ads running on your account.

How to reduce the risk

1. Strengthen sign-in

  • Require MFA for every user and use passkeys or hardware security keys where supported.
  • Give each person an individual seat; do not share passwords or recovery channels.
  • Store unique credentials in a password manager.
  • Protect email and identity-provider accounts as carefully as the ad platforms.

2. Reduce standing access

  • Apply least privilege to people, partners, apps, and service accounts.
  • Remove access promptly during offboarding.
  • Review third-party applications and revoke permissions you no longer need.
  • Treat unexpected “job brief,” “campaign asset,” and browser-extension downloads as untrusted.

3. Revoke sessions deliberately

A local browser logout is not a universal “log out everywhere” control. Use each platform’s security page to review and revoke sessions or devices explicitly. For example, Google lets users review devices and sign out individual sessions. Also revoke suspicious apps and rotate relevant secrets; otherwise another access path may remain.

4. Monitor account behavior

Stolen sessions or app tokens may bypass a fresh login challenge. Review spend, campaign inventory, destinations, access, billing, and change history. Native spend alerts across Meta, Google, and TikTok can help surface some metric changes, but they do not detect every security event or guarantee containment.

FAQ

Can an ad account be compromised with MFA enabled?

Yes. MFA protects an authentication step, but a valid stolen session, compromised endpoint, app token, real-time phishing proxy, or account-recovery abuse may create another route. Use phishing-resistant authentication where available and combine prevention with explicit session revocation and account review.

What is DUCKTAIL?

DUCKTAIL is a financially motivated malware operation documented by WithSecure in 2022. Its observed malware stole browser cookies and used authenticated Facebook sessions to target associated Facebook Business accounts; see WithSecure’s original technical summary.

What should I do first after suspected compromise?

From a known-clean device:

  1. use the platform’s official recovery flow;
  2. change affected credentials and secure the associated email or identity provider;
  3. revoke unfamiliar sessions, apps, users, partners, and service accounts;
  4. stop unauthorized campaigns using the platform controls available to you;
  5. preserve screenshots, IDs, timestamps, billing records, and activity logs; and
  6. report unauthorized activity and dispute charges through the platform and payment provider.

Reporting a charge is not a guarantee of reimbursement. For an active incident, use AdFence’s official Facebook ads recovery guide, Google Ads recovery guide, or TikTok Ads recovery guide. The cross-platform hacked-account overview helps teams prepare before an incident, while the longer Facebook recovery guide and Google Ads first-24-hours checklist provide additional platform-specific detail.

Bottom line

No single control covers every attack path. Use phishing-resistant sign-in, least privilege, deliberate session and app revocation, endpoint security, and account-level review. Treat monitoring as a detection aid, not as malware prevention or a guarantee that takeover, spend, restrictions, or loss will be stopped.

Keep reading

More practical notes for protecting your ad operations.