Google Ads: incident recovery checklist
Printed from https://adfence.io/under-attack/google-ads
Guidance last reviewed 5 September 2026
AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google.
Under attack · Google ads
Google Ads account hacked? Start here.
Choose what was affected and follow the relevant steps to contain unauthorized activity, recover access, review the changes made to your account, and secure your advertising setup.
Google’s reporting form is login-gated, so it needs a working Google Account session. If you cannot sign in, begin Google Account recovery and ask another legitimate administrator with access to report the suspected compromise in parallel.
Is unauthorized spend still active?
If you still have legitimate access, pause the campaigns you cannot verify and check whether other accounts under the same login or Manager Account are also spending. If another trusted administrator still has access, ask them to contain the activity now.
Record campaign IDs, timestamps and account IDs where that is practical, but do not delay containment to build a perfect evidence file. If you have already lost access, go straight to the recovery path that matches your situation.
Before you go further
- AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google.
- This guide cannot promise account recovery, the identification of whoever did this, the reversal of a suspension, a credit, or a refund. It sets out the order to work in and what to record.
- Never type a password, two-step verification code, recovery code, passkey, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.
- Do not publish Customer IDs, invoices, case numbers or security screenshots in a public forum or social post while an incident is open. Send them only through Google’s own signed-in routes.
- Which Google routes you are offered depends on whether you can still sign in, your access level, whether the account is personal or a Google Workspace account, your region, your payment setting and your eligibility. Work through the routes below in order rather than expecting a particular form or reply to appear.
- Google Account, Google Ads, Google Workspace, the payments centre and Merchant Center are separate support systems. Securing one does not establish that the others are clean, and this advertising guide does not attempt to cover full Workspace or Merchant Center recovery.
- Everything on this page is readable without an account, a signup or an email address.
Last reviewed . Official Google destinations and menu names on this page are reviewed every quarter.
Do these first, whichever Google Ads setup you use.
These four apply before the account-specific recovery paths below.
01
Report the account as compromised
Use Google’s compromised-account route as soon as you can reach it. The form is login-gated, so recover the Google Account first if you cannot sign in. Have the identifiers ready before you start.
- Google Ads Customer ID
- Manager Customer ID, where one applies
- Email addresses that may be compromised
- The first suspicious timestamp
- Unknown users
- Unknown Manager Accounts
- Unauthorized campaigns
- Budget increases
- Automated rules and scripts
- Your current IP address
- The unauthorized amount
02
Contain unauthorized advertising activity
If legitimate access remains, pause what you cannot verify. Record IDs and timestamps as you go, but do not delay containment to collect perfect evidence.
- Unfamiliar campaigns
- Campaigns pointing at unknown destinations
- Other accounts under the same login that are spending
- Daily and shared budgets
- Automated rules
- Scripts and other automation
- Campaign and account IDs, recorded before anything is removed
03
Secure the Google Account and the device
A Google Ads login is a Google Account login. If someone else may still be signed in, change the password now, preferably from a device you trust, and then remove harmful software and unfamiliar extensions.
- Google Account password
- Recovery email address
- Recovery phone number
- Signed-in devices
- Recent security events
- Two-step verification
- Passkeys
- Third-party account connections
04
Preserve the essential evidence
Use Google Ads change history while you still have access. It is one evidence source, not a complete forensic record: it currently covers up to two years, includes changes made by rules, the API and Google Ads Editor, and not everything it lists can be undone.
- Who or what Google attributes each change to
- When each change was made
- Campaigns affected
- Budget and bidding changes
- Ads and assets created
- Targeting changes
- Conversion changes
- Unknown managers and users
- Billing changes
- Relevant emails from Google
- Support case numbers
Six different layers, and only one of them is the login.
Google uses separate account, access and billing systems, alongside a resulting suspension or enforcement state. Which system was reached and whether enforcement followed determine the recovery route, so name each affected layer before you pick a path.
Google Account
The email-based identity used to sign in. A compromise here can also expose Gmail, YouTube, Drive, Analytics, Merchant Center and other connected Google services, and it is recovered through Google Account recovery rather than through Google Ads.
Individual Google Ads account
Where campaigns, budgets, targeting, ads, conversions and billing are managed. It is identified by a 10-digit Customer ID, and one Google Account can reach several of them.
Google Ads Manager Account (MCC)
The hierarchy layer that can manage several individual accounts and other Manager Accounts. A compromise here may reach multiple client or brand accounts at once, and authority over each client depends on the manager-level role and on administrative ownership.
Payments profile and billing setup
The legally responsible payer, payment methods, tax data, billing contacts and permissions. One profile may serve several Ads accounts and other Google products, though reuse and edit rights vary by payment setting, account type, country and permission.
Suspension and enforcement state
A temporary security suspension, policy suspension or billing suspension is an enforcement state, not proof of which layer was compromised. Containment and recovery may need to run alongside a separate appeal, advertiser verification or payment-verification process.
Connected products and tools
Analytics, Merchant Center, YouTube, Business Profile, Search Console, Firebase, Google Ads Editor, scripts, automated rules, API integrations and third-party platforms. Each remains its own security domain with its own recovery process.
Securing one layer does not establish that the others are clean. A recovered Google Account can still be reachable through an unauthorized Manager Account link, a script, an API integration or a payments profile shared with another product.
Which part of your Google Ads setup was compromised?
Select one or more. A compromised Google Account can reach an individual Ads account, a Manager Account, several client accounts and a payments profile at the same time, so the paths below open in the order they should be worked through.
No recovery paths selected yet.
Your selection is saved only in this browser, on this device. It is never sent to AdFence.
Recovery paths
Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.
Not sure yet is a valid answer. Every recovery path can be opened below, and the full post-recovery audit lists what to check across the whole setup.
Go to the full post-recovery audit
Path 1Google Account login compromised
The sign-in identity behind Google Ads, Gmail and every other connected Google product.
When this path applies
- The password no longer works
- The recovery email or phone number changed
- Two-step verification methods changed
- An unknown device is signed in
- Google reported suspicious activity
- The account can no longer reach Google Ads
- Gmail and Google Ads were lost together
Step 1. If someone else may still be signed in, change the password now
Google’s guidance is to change the password immediately when another person may still have access, preferably from a device you trust. Removing harmful software matters too, but it is not a reason to leave a live session open while you scan.
If the device you normally use may be infected, change the password from a different trusted device, then clean the original before signing in from it again.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Google’s step-by-step guidance once you are back in: password, recovery details, security events, devices, and the harmful software and browser extensions that may have taken the password in the first place.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Step 2. If you cannot sign in at all, use Google Account recovery
Google’s recovery flow is the route when someone else may be using the account or the legitimate owner can no longer sign in. Answer from a device and a location you have used before where possible.
Google states that it does not work with account or password recovery services, and that sign-in recovery cannot be completed by calling Google. Anyone offering paid recovery or an internal Google contact is a second attack, not a solution.
- Google Account recovery (opens in a new tab)
Google’s own recovery flow for a Google Account you can no longer sign in to. Answer from a device and location you have used before where possible, because Google weighs that when deciding.
- Google Account Help: account recovery scams (opens in a new tab)
Google states that it does not work with account or password recovery services and that sign-in recovery cannot be completed by calling Google. Treat anyone offering paid recovery, an internal contact or a phone number as a second attack.
- Google Ads Help: avoid scams and impersonation (opens in a new tab)
How Google describes people impersonating Google Ads support. Useful while an incident is live, because a compromise is often followed by someone offering to fix it.
- Google Account recovery (opens in a new tab)
Step 3. Work out whether this is a personal account or a Google Workspace account
The two have different recovery routes, and using the consumer flow on a work account wastes the hours that matter.
- Personal Google Account: use Google’s standard recovery and hacked-account guidance
- Google Workspace user: contact your organisation’s Workspace administrator immediately
- Sole or unreachable Super Admin: use Google’s administrator recovery route instead
- Reseller customer: your reseller may need to act
Workspace self-recovery depends on the configured recovery details and the organisation’s policy, and support-assisted recovery may require domain verification. It is not offered in every case.
- Google Workspace Admin Help: recover an administrator account (opens in a new tab)
For a work or school account. Another Super Admin can restore access where one exists; self-recovery depends on the configured recovery details and organisation policy.
- Google Workspace: administrator recovery request (opens in a new tab)
The support-assisted route for a sole or unreachable Workspace administrator. It may require domain verification, reseller customers may need their reseller, and this option is not offered in every case.
Step 4. Clean every device used to reach Google Ads
- Browser extensions
- Recently downloaded software
- Remote-access tools
- Unfamiliar applications
- Malware and antivirus results
- Browser profiles
- Stored passwords
A device that is still compromised can capture the new password as soon as you set it, so clean it before you sign in from it again.
Step 5. Run Security Checkup and reset the recovery details
- Recent security events
- Signed-in devices
- Recovery phone number
- Recovery email address
- Two-step verification
- Passkeys
- Additional protections
Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor. Plan for that rather than assuming an instant reset.
- Google Security Checkup (opens in a new tab)
Recent security events, signed-in devices, recovery phone and email, two-step verification and third-party access, in one signed-in review.
- Google Ads Help: two-step verification for Google Ads (opens in a new tab)
How two-step verification applies to Google Ads sign-in. Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor.
Step 6. Review the applications and services with account access
Remove anything unfamiliar, anything no longer needed, anything added around the time of the compromise, and anything holding more access than it requires.
- Google Account Help: apps and services with account access (opens in a new tab)
Where to review Sign in with Google connections and third-party applications holding access to Google Account data, and how to remove them.
- Google Account Help: apps and services with account access (opens in a new tab)
Step 7. Continue to the Google Ads audit
Securing the Google Account does not establish that the advertising setup is clean. An unauthorized user, Manager Account link, script or API integration can still hold access after the password changes.
Path 2Individual Google Ads account compromised
You can still sign in, but the Ads account holds activity you did not create.
When this path applies
- Unknown campaigns or unauthorized spend
- New users you do not recognise
- An unfamiliar Manager Account is linked
- Budgets increased
- Unknown automated rules or scripts
- Final URLs or tracking templates changed
- Targeting or conversions changed
- Billing information changed
- Unexpected advertiser verification prompts
Step 1. Report the compromise rather than only correcting the account
Submit Google’s compromised-account report with the Customer ID and the timeline. Manually undoing changes does not create the case Google’s cleanup process runs from.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads: report a compromised account (opens in a new tab)
Step 2. Review change history across the suspected period
Set the date range to cover the whole suspected window, and record who or what Google attributes each change to.
- User additions
- Campaign creation
- Budget and shared-budget changes
- Bid changes
- Ad and asset creation
- Final URL changes
- Audience and location changes
- Conversion changes
- Automated activity
- Campaign pauses and activations
Change history currently covers up to two years and can include changes made through automated rules, the Google Ads API and Google Ads Editor. Some entries can be undone and some cannot, so treat it as one evidence source rather than the whole record.
- Google Ads Help: account history and change history (opens in a new tab)
Google’s article on reviewing account history. Change history currently covers up to two years and can include changes made directly, by automated rules, through the Google Ads API and through Google Ads Editor. Some changes can be undone and some cannot, so treat it as one evidence source rather than a complete forensic record.
Step 3. Review every user in Access and security
- Admin users
- Standard users
- Read-only users
- Billing users
- Email-only users
- Pending invitations
- Authentication method
- Last login information, where it is shown
Admin access can manage users, manager links, product links, and the authentication-method and last-login information. Billing and Standard roles are narrower but still material. Record identifying details before removing anyone, where that is practical.
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
- Google Ads Help: account access levels (opens in a new tab)
What Admin, Standard, Read-only, Billing and Email-only access each allow, including who can see authentication method and last-login information.
Step 4. Review every linked Manager Account separately
Removing one unknown user does not remove access held through a Manager Account. These are two different routes in.
- Manager Account name
- Manager Customer ID
- Administrative ownership status
- When and why the relationship exists
- Whether the agency or partner is still legitimate
- Any pending link request
A linked manager is not automatically an administrative owner. Unlinking an unauthorized manager requires the permission your own role actually carries, so check what you hold before assuming you can.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
Step 5. Audit every campaign, including paused and removed ones
- Search, Shopping and Display campaigns
- Performance Max and Demand Gen
- Video and App campaigns
- Shared budgets and experiments
- Daily budgets and bid strategies
- Locations, languages and audiences
- Keywords and search themes
- Ads, assets and account-level assets
- Final URLs and tracking templates
- Schedules, devices and conversion goals
- Product feeds
Pause what you cannot verify rather than deleting it first. Record IDs, settings, destinations and spend before removing anything, where containment allows.
Step 6. Review the automation, not only the people
An unauthorized change may have been made by a person, a Manager Account, a script, a rule, an application or an API integration.
- Automated rules
- Scripts
- Auto-applied recommendations
- Google Ads Editor activity
- API-based tools
- Third-party campaign platforms
- Feed-management tools
- Call-tracking integrations
Step 7. Review conversions and tracking
A compromised account can be pointed at a different event while the visible campaign still looks normal.
- Conversion actions and goals
- The Google tag
- Imported Analytics conversions
- Enhanced conversions
- Offline conversion imports
- Call conversions
- Attribution settings
- Conversion values
- Primary and secondary status
Step 8. Review the account billing and the payments profile separately
- Payment methods
- Payments profile
- Payments profile users
- Billing contacts
- Billing country and tax information
- Invoices and transactions
- Account balance
- Monthly invoicing and billing transfers
- Unknown payment methods
A payments profile may be shared across several Ads accounts and other Google products, so a profile-level change can reach further than this account. Google Ads Admin and Billing users can edit specified profile and payment details, but Google Ads users cannot add or remove payments profile users directly.
- Google Ads Help: payments profiles (opens in a new tab)
What a payments profile holds and how one profile can serve several Ads accounts and other Google products, so a profile-level change can reach further than the account you are looking at.
- Google payments centre: payments profile users (opens in a new tab)
Who can be a payments profile user and how those permissions change. Google Ads users cannot add or remove payments profile users directly; that requires the appropriate payments contact or a same-domain user contacting support.
Step 9. Review advertiser verification and certification status
- Advertiser name and business details
- Verification status
- Identity documentation
- Business operations verification
- Unexpected certification requirements
- New regulated-category status
Campaigns created by an unauthorized user can change verification details or trigger certification requirements you never asked for.
Step 10. Review the connected products
If a connected product was separately compromised, use that product’s own recovery process rather than trying to fix it from Google Ads.
- Google Analytics
- Merchant Center
- YouTube
- Business Profile
- Search Console
- Firebase and app platforms
- Customer Match sources
- Third-party products
- Merchant Center Help: compromised account (opens in a new tab)
Merchant Center is a separate security domain with its own process. If the Merchant Center account itself was taken over, use this rather than treating it as a Google Ads issue.
This account is contained. Check the Manager Account level next.
Path 3Google Ads Manager Account compromised
The hierarchy layer above the accounts, where one compromise can reach many clients.
When this path applies
- Several client accounts are affected
- Unknown users appear in the Manager Account
- An unfamiliar sub-manager appears
- Client accounts were linked or unlinked
- Legitimate agency users were removed or downgraded
- New client accounts were created
- Unauthorized campaigns appear across several accounts
- Payments profiles or billing setups changed
Step 1. Identify the highest affected manager level
Work out whether the compromise reached one client account, the direct Manager Account, a parent manager, a sub-manager, or several levels at once.
This matters because Google’s cleanup approval is level-sensitive: for a manager-level compromise, approval is limited to eligible administrators at that manager level.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads Help: compromised account guidance (opens in a new tab)
Step 2. Record the whole hierarchy, not only the accounts that alerted
- Manager Account name and Customer ID
- Parent Manager Account
- Sub-managers
- Linked client accounts
- Administrative ownership status
- Legitimate administrators
- Unknown administrators
- Accounts showing unauthorized activity
Step 3. Review every user with access to the Manager Account
- Admin
- Standard
- Read-only
- Email-only
- Pending invitations
- Authentication methods
- Last login information
- Former employees
- Former agencies
- Shared or generic email addresses
Manager administrators can invite and remove users, change access levels and manage links, but authority over a client account also depends on whether that manager is the client’s administrative owner. A manager Admin without ownership has limited client-administration powers.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
Step 4. Review manager and sub-manager links in both directions
- Parent Manager Account
- Sub-manager accounts
- External managers
- Newly linked accounts
- Pending link requests
- Accounts unexpectedly removed
- Ownership changes
An individual Ads account can be managed through several manager relationships at once, so reviewing direct users alone is not enough.
Step 5. Contain the client accounts where legitimate access remains
- Pause unauthorized campaigns
- Notify the affected client administrators
- Ask clients to secure their own Google Accounts
- Record unauthorized users and manager links
- Review each client’s billing
- Confirm which legitimate campaigns are still running
Keep a separate record per client: Customer ID, unauthorized activity, amount affected, first suspicious time, containment time and current access status. One client incident is not the whole manager incident, and the reverse is also true.
Step 6. Review accounts created during the compromise window
- Accounts the legitimate team did not create
- Accounts using unfamiliar billing
- Accounts with unusually high budgets
- Accounts targeting unrelated businesses
- Accounts linked to unknown websites
Google’s current process says that, where it confirms a compromise, it may unlink unauthorized Manager Accounts and set spending limits to zero on unauthorized new sub-accounts. That is a description of what Google may do, not a guarantee that it has happened.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
Step 7. Review the payments relationships with care
- Linked payments profiles
- Who holds link-management permission
- Billing transfers
- Consolidated billing
- Payments profile ownership
- Invoicing relationships
- Pending linking requests
Google describes manager-to-payments-profile linking as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for every dependent Ads account and stop them serving until new setups are created, so do not unlink as a containment reflex.
- Google Ads Help: link a Manager Account to a payments profile (opens in a new tab)
Google describes this as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for dependent Ads accounts and stop them serving until new setups are created.
- Google Ads Help: payments profiles (opens in a new tab)
What a payments profile holds and how one profile can serve several Ads accounts and other Google products, so a profile-level change can reach further than the account you are looking at.
Step 8. Report the full manager-level scope in one case
- Manager Customer ID
- The highest affected Manager Account
- Every affected client Customer ID
- Unknown Manager Account IDs
- Unknown users
- Unauthorized campaigns
- Accounts where access was removed or downgraded
- Billing impact per account
- One timeline across the whole hierarchy
Submitting unrelated explanations account by account, without naming the shared manager incident, makes the pattern harder for Google to see.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
The hierarchy is mapped. Check unknown accounts and charges next.
Path 4Unknown Google Ads account or unauthorized charges
An invoice, a card charge or an Ads account you never knowingly created.
When this path applies
- A Google Ads invoice arrived for an account you do not recognise
- A card was charged by Google Ads unexpectedly
- An Ads account appeared under your Google Account without permission
- You have never knowingly used Google Ads
- A new account was created during a Google Account compromise
- Your payment method was used in an unfamiliar Ads account
Step 1. Do not assume the charge identifies the cause
Investigate the Google Account and the payment method together, because the charge is a symptom of several possible causes.
- A compromised Google Account
- A new Ads account created under an existing identity
- An existing Ads account nobody remembers
- A compromised payment card
- An unauthorized user or Manager Account
- A payment method reused in another account
Step 2. Gather the charge details before you contact anyone
- Amount and currency
- Date
- Card or bank account used
- Transaction reference
- Billing descriptor
- Invoice number
- Customer ID, if it is shown
- The email address that received the notification
- Screenshots of the charge
- Any Google Ads billing email
Step 3. Sign in with the notified email and review every account it reaches
Record any account that was not created by you, has an unfamiliar Customer ID, contains unknown campaigns, uses an unfamiliar website, carries billing activity, or was created around the suspicious date.
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
- Google Ads Help: manage account access (opens in a new tab)
Step 4. Secure the Google Account even if you believe only the card was used
Complete the Google Account recovery and security steps. A card is one route in; the identity that can create an Ads account is another.
- Password
- Signed-in devices
- Recent security events
- Recovery methods
- Two-step verification
- Applications with account access
- Google Security Checkup (opens in a new tab)
Recent security events, signed-in devices, recovery phone and email, two-step verification and third-party access, in one signed-in review.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Google’s step-by-step guidance once you are back in: password, recovery details, security events, devices, and the harmful software and browser extensions that may have taken the password in the first place.
Step 5. Use the Google route that matches what you are looking at
- A known Ads account that was compromised: finish Google’s compromise process
- A charge you cannot identify at all: use the unidentified-charge troubleshooter
- An Ads account you do not recognise on the statement: read Google’s unrecognised-charge guidance first
The troubleshooter’s questions and any temporary notices inside it change, so read what it shows you today rather than a summary written months ago.
- Google Ads Help: troubleshoot an unidentified charge (opens in a new tab)
Google’s current destination for a Google Ads charge you cannot identify. The questions and any temporary notices inside it change, so read what it shows you today rather than a summary of it.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
Google describes contacting the card issuer as an often-recommended first step here, alongside cancelling or replacing the compromised card. The issuer makes the chargeback decision, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
Step 6. Talk to the card issuer, knowing what a dispute does
Google describes contacting the issuer as an often-recommended first step for a charge from an account you do not recognise, alongside cancelling or replacing the compromised card. A Google investigation and a bank dispute are separate processes with different evidence.
The financial institution makes the chargeback decision. A chargeback raised against a legitimate Ads balance can suspend the Ads account or leave an overdue balance if Google contests it, so establish which situation you are in before disputing.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
Google describes contacting the card issuer as an often-recommended first step here, alongside cancelling or replacing the compromised card. The issuer makes the chargeback decision, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
The charge route is chosen. Check whether the account was suspended.
Path 5Google Ads account suspended after unauthorized activity
Enforcement and compromise are two different findings, and the order of work matters.
When this path applies
- A temporary security suspension appeared
- A policy suspension appeared
- Circumventing Systems enforcement
- Unacceptable Business Practices enforcement
- Phishing or malicious-software enforcement
- Suspicious payment enforcement
- Advertiser verification failed
- Unexpected certification requirements appeared
Step 1. Identify which kind of suspension you are looking at
Google may temporarily suspend an account while it secures it after suspected unauthorized activity. Unauthorized campaigns, destinations, ads or keywords can separately trigger a policy suspension. These are different findings with different routes.
Unauthorized activity is not proof that it caused the suspension. Read the notice inside your own account rather than assuming which one applies.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
What each suspension type means and which appeal route applies. Google may require advertiser or payment verification first, generally expects separate appeals for separate suspended accounts, and says excessive appeals may not be processed.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
Step 2. Complete the compromise recovery before you appeal
- Secure the Google Account
- Remove unauthorized access
- Review Manager Account links
- Complete Google’s compromise process
- Review the account activity change log
- Remove or remediate unauthorized campaigns and destinations
- Confirm billing and advertiser verification
An appeal is not a containment step. Appealing while an unauthorized user still holds access leaves them there.
Step 3. Record exactly what the suspension notice says
- The policy named
- The date issued
- The account affected
- Campaigns or destinations involved
- Whether the account is read-only
- Whether an appeal option is offered
- Whether additional verification is required
Step 4. Remove or pause the unauthorized policy-violating content
- Unauthorized ads
- Unknown final URLs
- Cloaked or redirected destinations
- Policy-violating keywords
- Unfamiliar campaigns
- Unknown business identities
- Unauthorized payment methods
- Misleading assets
- Incorrect advertiser verification details
Step 5. Submit one appeal that explains the compromise and the remediation
- That the account experienced unauthorized access
- When the compromise began
- Which activity was unauthorized
- Which security issues were fixed
- Which users and managers were removed
- Which campaigns and destinations were removed
- Which verification details were corrected
- Which supporting evidence is available
An appeal is not guaranteed to restore an account. Google may require advertiser or payment-method verification first, certain selected advertisers must complete advertiser verification before appealing, separate suspended accounts generally need separate appeals, and Google says excessive appeals may not be processed. Do not file competing appeals for the same account.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
What each suspension type means and which appeal route applies. Google may require advertiser or payment verification first, generally expects separate appeals for separate suspended accounts, and says excessive appeals may not be processed.
Step 6. Keep the compromise case and the policy appeal consistent
The timeline, campaign IDs, affected users and remediation details should match across the compromised-account report, the account activity change log, the policy appeal, any reimbursement request and your own incident record.
The appeal is in. Check whether Admin access is still yours.
Path 6Admin access removed or downgraded
Legitimate administrators were removed, downgraded, or replaced by someone unknown.
When this path applies
- Legitimate Admin users were removed
- Admins were changed to Standard or Read-only
- Only an unknown user remains as Admin
- The account appears under an unfamiliar Manager Account
- An agency lost access to client accounts
- No active administrator remains
Step 1. Ask another legitimate Admin or administrative owner first
Where one still exists, they can restore access faster than any support route.
- Current users and access levels
- Linked Manager Accounts
- Pending invitations
- Recent change history
- Whether the affected user was removed or downgraded
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
Step 2. Check direct access and manager access separately
A user can lose direct account access while a legitimate Manager Account still holds it. The reverse also happens: direct Admin access remains while an unauthorized manager controls parts of the account. Inspect both routes.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
- Google Ads Help: Manager Account access levels (opens in a new tab)
Step 3. Report an unauthorized access change as a compromise
If the change was not authorised, use the compromised-account process rather than treating it as an ordinary invitation problem.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
- Google Ads: report a compromised account (opens in a new tab)
Step 4. Use Google’s account access request route where it applies
When the original administrator has left or no active Admin can grant access, Google offers an access-request route and may ask for proof of account ownership before changing permissions.
Google validates ownership and decides whether permissions change. Submitting documents does not oblige Google to grant access, and this route is not a substitute for reporting the security incident.
- Google Ads Help: request access to an account (opens in a new tab)
Google’s guidance for regaining access when the original administrator has left or no active Admin can grant it. Google validates ownership and decides whether permissions change.
- Google Ads: account access request (opens in a new tab)
The request route itself. Be ready to prove ownership. Treat it as an access-recovery route, not as a substitute for reporting a security incident.
- Google Ads Help: request access to an account (opens in a new tab)
Step 5. Gather the ownership evidence before you ask
- Customer ID
- Manager Customer ID
- Historic invoices
- Billing details
- Business registration
- Domain ownership
- Advertiser verification information
- Previous Admin email addresses
- Previous support cases
- Campaign and payment history
Step 6. Coordinate the correct administrator level for the cleanup
For a confirmed manager-level compromise, Google may require an administrator at that manager level to review and approve the cleanup. Do not approve a cleanup decision until the full hierarchy and the listed changes have been reviewed.
- Google Ads Help: account activity change logs (opens in a new tab)
The log Google may email to eligible prior administrators after it secures a compromised account, and the cleanup decision attached to it. The log can also list cleanup actions that failed and still need manual remediation.
- Google Ads Help: account activity change logs (opens in a new tab)
Access is being restored. Read what happens after you report it.
Google may secure the account before it restores normal access.
If Google confirms unauthorized activity, its current process can change the account before you get it back. Knowing what it may do stops a secured account looking like a second attack.
What Google’s current process says it may do
- Temporarily suspend the affected account while it is secured
- Pause campaigns created or modified by the unauthorized user
- Restrict the compromised users
- Revoke unauthorized user or Manager Account invitations
- Restore or re-invite legitimate users who were removed
- Unlink unauthorized Manager Accounts
- Set spending limits to zero on unauthorized new sub-accounts
Google says untouched legitimate campaigns may keep running while unauthorized ones are paused, depending on the security event. None of this is automatic or guaranteed, and the account activity change log can list cleanup actions that failed and still need manual remediation.
The account activity change log
- It is sent by email after Google secures the account, if Google sends one at all
- Only users who held an Admin role before Google’s confirmed compromise date may be eligible
- The originally compromised user is excluded from the notification in the documented workflows
- For a manager-level compromise, eligibility is limited to administrators at that manager level
- Google does not disclose which administrators received the email
- Structural-change cases may stay suspended until an eligible Admin consents and the cleanup succeeds
Clean up this account
Use this when every listed modification was unauthorized.
Restore this account as is
Use this when the activity Google flagged was in fact legitimate.
Additional investigation is needed
Use this when some of the activity is legitimate and the rest needs further review.
One administrator, one submission, no undo.
Only one eligible administrator can submit the cleanup decision, and Google states that a submitted decision cannot be changed or reverted. Read the complete change log, and agree the answer with the people who know which campaigns were real, before anyone confirms it.
- Google Ads Help: account activity change logs (opens in a new tab)
The log Google may email to eligible prior administrators after it secures a compromised account, and the cleanup decision attached to it. The log can also list cleanup actions that failed and still need manual remediation.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
Did Google send the account activity change log?
This is Google’s post-investigation log, not the change history you can open yourself. What you should do next depends on whether it has arrived.
All three answers are shown. Choose one to narrow this to your situation.
This answer is not saved, and it does not change which recovery paths are open. All three answers are shown until you pick one.
The log arrived
Read the whole log before anyone answers it. The decision is submitted once, by one eligible administrator, and Google states it cannot be changed afterwards.
- Confirm the recipient held an Admin role before Google’s confirmed compromise date
- For a manager-level compromise, confirm they are an Admin at that manager level
- Update the Google Account password and re-authenticate before acting on the log
- Read every listed modification, including the ones that look routine
- Check the log for cleanup actions that failed and still need manual remediation
- Agree the answer with the people who know which campaigns were legitimate
- Then have one administrator submit the single decision
Google does not disclose which administrators received the email, so absence of a copy in your own inbox does not mean nobody got one. Ask the other prior Admins before assuming it was not sent.
Nothing has arrived yet
The change history you can open inside Google Ads is not the same artefact. The account activity change log is the post-investigation record Google may email after it secures the account, and it may never be sent.
- Keep containment and the audit going; none of it depends on the log
- Keep the compromised-account case open and answer anything Google asks
- Monitor the inboxes of every administrator who held Admin before the compromise
- Check spam, filters, forwarding rules and shared mailboxes, which a compromise often touches
- Keep using change history as your own evidence source in the meantime
Google publishes no general timing for this, so do not plan around a date. Nothing on this page can tell you when or whether a log will arrive.
You are not sure
Work out who would have been eligible to receive it, then check with them directly rather than waiting.
- List everyone who held an Admin role before the suspected compromise date
- Identify the level Google would treat as affected: the individual account or a manager level
- For a manager-level incident, ask the administrators at that manager level
- Exclude the originally compromised user, who is not notified in the documented workflows
- Check each eligible administrator’s inbox, spam folder and any shared mailbox
- Ask through the open support case whether a log was issued
Establishing who is eligible is worth doing now. If a log does arrive, only one of those people can answer it, and only once.
Regaining access does not mean the incident is over.
Once access is restored, inspect the whole Google Ads setup before normal advertising resumes.
Google Accounts and devices
- Google Account passwords
- Recovery phone numbers
- Recovery email addresses
- Two-step verification
- Passkeys
- Recent security events
- Signed-in devices
- Third-party connections
- Browser extensions
- Malware scans
Users and access
- Admin users
- Standard users
- Read-only users
- Billing users
- Email-only users
- Pending invitations
- Authentication methods
- Last login information
- Former employees
- Former agencies
Manager Account hierarchy
- Parent managers
- Sub-managers
- Client accounts
- Administrative ownership
- Unknown Manager Accounts
- Pending manager requests
- Accounts added or removed
- New sub-accounts
Campaigns
- New campaigns
- Reactivated campaigns
- Budgets and shared budgets
- Bid strategies
- Locations and languages
- Audiences
- Keywords and search themes
- Ads and assets
- Final URLs
- Tracking templates
- Campaign schedules
- Conversion goals
Automation
- Automated rules
- Scripts
- API integrations
- Google Ads Editor
- Auto-applied recommendations
- Feed tools
- Third-party campaign platforms
- Data imports
Tracking and conversions
- Conversion actions
- The Google tag
- Analytics imports
- Enhanced conversions
- Offline conversion imports
- Attribution settings
- Conversion values
- Primary and secondary goals
Billing and payments
- Payment methods
- Transactions
- Invoices
- Account balance
- Payments profile
- Payments profile users
- Billing contacts
- Billing transfers
- Monthly invoicing
- Credit lines
- Tax details
Connected products
- Google Analytics
- Merchant Center
- YouTube
- Business Profile
- Search Console
- Firebase
- Ecommerce integrations
- Product feeds
- Customer data sources
Verification and certification
- Advertiser verification
- Business name
- Business information
- Identity documents
- Business operations
- Unexpected certification requirements
- Unexpected regulated-category status
Do not fully resume advertising until access, campaigns, automation, destinations, tracking, billing and verification have all been reviewed.
Close every route back into the account.
Google Account
- Use a unique password, not shared with any other service
- Turn on two-step verification
- Add passkeys where they are offered
- Review recovery email and phone
- Review signed-in devices
- Remove unknown linked applications
- Complete Security Checkup
- Never share one login between people
Google Ads users
- Give each person individual access
- Remove inactive users
- Limit Admin access
- Use Standard access where it is sufficient
- Use Read-only for reporting-only users
- Review authentication methods
- Review last login information
- Use business email addresses
Manager Account
- Review every Manager Account link
- Remove inactive agencies
- Review sub-managers
- Limit administrative ownership
- Confirm who owns each client account
- Review access after every staffing or agency change
Billing
- Limit payments-profile access
- Review billing users
- Review shared payments profiles
- Review Manager Account payment links
- Confirm billing contacts
- Remove outdated finance access
- Review invoices and adjustments regularly
Google’s own controls, with the conditions attached
Allowed email domains
Restricts which email domains may be invited in future. It does not remove users who already have access, and a Manager Account mandate reaches only the sub-accounts that manager administratively owns.
- Google Ads Help: allowed email domains (opens in a new tab)
Restricts which email domains may be invited in future. It does not remove users who already have access.
- Google Ads Help: Manager Account security mandates (opens in a new tab)
How a Manager Account can require security settings below it. A mandate reaches only the sub-accounts that manager administratively owns.
Multi-party approval
Google currently applies this only to accounts with more than three administrators, and read-only roles and API users are exempt. Eligible account or linked-manager Admins can approve, requests expire after 20 days, and Google Support cannot override an internal approver who does not respond.
- Google Ads Help: multi-party approval (opens in a new tab)
Google currently applies this only to accounts with more than three administrators; read-only roles and API users are exempt. Requests expire after 20 days, and Google Support cannot override an internal approver who does not respond.
Confirm it is you, and passkeys
Google may challenge Standard or Admin invitations, unusual budget or bulk changes, new destination domains, and campaigns for previously unused apps. It is independent of two-step verification and is not triggered for every action. Any advertiser can set up a passkey, and Google may require one for some sensitive actions.
- Google Ads Help: confirm it is you (opens in a new tab)
Google may challenge Standard or Admin invitations, unusual budget or bulk changes, new destination domains, and campaigns for previously unused apps. It is independent of two-step verification and is not triggered for every action.
- Google Ads Help: passkeys (opens in a new tab)
Any advertiser can set up a passkey, and Google may require one for some sensitive actions. Do not assume every account is prompted the same way.
Google Ads Security Agent
Google describes behavioural monitoring, unusual-user and domain detection, login-activity monitoring and access-level suggestions. Review the security insights if your account shows them; they are suggestions rather than an automatic block or remediation.
- Google Ads Help: Google Ads Security Agent (opens in a new tab)
Google describes behavioural monitoring, unusual-user and domain detection, login-activity monitoring and access-level suggestions. Review the security insights if your account shows them; they are suggestions, not an automatic block or remediation.
Two-step verification
Required before a reimbursement request under Google’s current process, and worth keeping enabled regardless. Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor.
- Google Ads Help: two-step verification for Google Ads (opens in a new tab)
How two-step verification applies to Google Ads sign-in. Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor.
Keep Google’s own controls switched on. They are the layer that decides who can reach the account; nothing on this page replaces them.
A note on Google’s changing menu names
Google updates Google Ads regularly, so the exact labels on your screen may not match a guide written a few months ago. Where a menu name here does not exist in your interface, look for the nearest equivalent under Admin, Access and security, Billing, or the account history views rather than assuming the setting was removed.
Every official destination on this page
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
- Google Account recovery (opens in a new tab)
Google’s own recovery flow for a Google Account you can no longer sign in to. Answer from a device and location you have used before where possible, because Google weighs that when deciding.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Google’s step-by-step guidance once you are back in: password, recovery details, security events, devices, and the harmful software and browser extensions that may have taken the password in the first place.
- Google Security Checkup (opens in a new tab)
Recent security events, signed-in devices, recovery phone and email, two-step verification and third-party access, in one signed-in review.
- Google Account Help: account recovery scams (opens in a new tab)
Google states that it does not work with account or password recovery services and that sign-in recovery cannot be completed by calling Google. Treat anyone offering paid recovery, an internal contact or a phone number as a second attack.
- Google Ads Help: avoid scams and impersonation (opens in a new tab)
How Google describes people impersonating Google Ads support. Useful while an incident is live, because a compromise is often followed by someone offering to fix it.
- Google Ads Help: account history and change history (opens in a new tab)
Google’s article on reviewing account history. Change history currently covers up to two years and can include changes made directly, by automated rules, through the Google Ads API and through Google Ads Editor. Some changes can be undone and some cannot, so treat it as one evidence source rather than a complete forensic record.
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
- Google Ads Help: account access levels (opens in a new tab)
What Admin, Standard, Read-only, Billing and Email-only access each allow, including who can see authentication method and last-login information.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
- Google Ads Help: request access to an account (opens in a new tab)
Google’s guidance for regaining access when the original administrator has left or no active Admin can grant it. Google validates ownership and decides whether permissions change.
- Google Ads: account access request (opens in a new tab)
The request route itself. Be ready to prove ownership. Treat it as an access-recovery route, not as a substitute for reporting a security incident.
- Google Ads Help: account activity change logs (opens in a new tab)
The log Google may email to eligible prior administrators after it secures a compromised account, and the cleanup decision attached to it. The log can also list cleanup actions that failed and still need manual remediation.
- Google Ads Help: payments profiles (opens in a new tab)
What a payments profile holds and how one profile can serve several Ads accounts and other Google products, so a profile-level change can reach further than the account you are looking at.
- Google payments centre: payments profile users (opens in a new tab)
Who can be a payments profile user and how those permissions change. Google Ads users cannot add or remove payments profile users directly; that requires the appropriate payments contact or a same-domain user contacting support.
- Google Ads Help: link a Manager Account to a payments profile (opens in a new tab)
Google describes this as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for dependent Ads accounts and stop them serving until new setups are created.
- Google Ads Help: troubleshoot an unidentified charge (opens in a new tab)
Google’s current destination for a Google Ads charge you cannot identify. The questions and any temporary notices inside it change, so read what it shows you today rather than a summary of it.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
Google describes contacting the card issuer as an often-recommended first step here, alongside cancelling or replacing the compromised card. The issuer makes the chargeback decision, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
What each suspension type means and which appeal route applies. Google may require advertiser or payment verification first, generally expects separate appeals for separate suspended accounts, and says excessive appeals may not be processed.
- Google Ads Help: two-step verification for Google Ads (opens in a new tab)
How two-step verification applies to Google Ads sign-in. Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor.
- Google Ads Help: passkeys (opens in a new tab)
Any advertiser can set up a passkey, and Google may require one for some sensitive actions. Do not assume every account is prompted the same way.
- Google Ads Help: confirm it is you (opens in a new tab)
Google may challenge Standard or Admin invitations, unusual budget or bulk changes, new destination domains, and campaigns for previously unused apps. It is independent of two-step verification and is not triggered for every action.
- Google Ads Help: allowed email domains (opens in a new tab)
Restricts which email domains may be invited in future. It does not remove users who already have access.
- Google Ads Help: multi-party approval (opens in a new tab)
Google currently applies this only to accounts with more than three administrators; read-only roles and API users are exempt. Requests expire after 20 days, and Google Support cannot override an internal approver who does not respond.
- Google Ads Help: Manager Account security mandates (opens in a new tab)
How a Manager Account can require security settings below it. A mandate reaches only the sub-accounts that manager administratively owns.
- Google Ads Help: Google Ads Security Agent (opens in a new tab)
Google describes behavioural monitoring, unusual-user and domain detection, login-activity monitoring and access-level suggestions. Review the security insights if your account shows them; they are suggestions, not an automatic block or remediation.
- Google Account Help: apps and services with account access (opens in a new tab)
Where to review Sign in with Google connections and third-party applications holding access to Google Account data, and how to remove them.
- Google Workspace Admin Help: recover an administrator account (opens in a new tab)
For a work or school account. Another Super Admin can restore access where one exists; self-recovery depends on the configured recovery details and organisation policy.
- Google Workspace: administrator recovery request (opens in a new tab)
The support-assisted route for a sole or unreachable Workspace administrator. It may require domain verification, reseller customers may need their reseller, and this option is not offered in every case.
- Merchant Center Help: compromised account (opens in a new tab)
Merchant Center is a separate security domain with its own process. If the Merchant Center account itself was taken over, use this rather than treating it as a Google Ads issue.
- Google Ads: get help (opens in a new tab)
Google’s support entry point, and where a reimbursement request is raised once recovery is complete. Which contact options appear depends on your sign-in state, account, region and eligibility.
Make the next incident easier to catch.
This part is about AdFence. It comes last on purpose: nothing here helps you recover the account you are trying to recover today.
If AdFence was already connected
- User access changes
- Manager or partner access changes
- Campaign changes
- Budget changes
- Targeting changes
- Domains and destinations
- Conversion and tracking changes
- Account status
- Billing signals
- Connection health
Availability depends on the Google integration, the permissions granted, your plan and your monitoring configuration, so treat the list above as the signals that may be supported for a Google Ads account rather than as a guarantee for yours. Monitoring is read-only by default, and AdFence connects by OAuth: it does not request or store platform passwords.
If AdFence was not connected
AdFence cannot reconstruct activity that occurred before the Google Ads account was connected. Once legitimate access has been restored, it can begin monitoring the Google Ads signals the integration supports, from that point forward.
An Evidence Pack organizes the activity AdFence recorded after connection into a documented timeline for support, disputes and internal review. It documents recorded activity only, and it does not prove fraud or guarantee a platform decision, a charge reversal or a reimbursement.
What it cannot do
- AdFence cannot restore Google access
- It cannot reverse a suspension
- It cannot identify the attacker
- It cannot determine reimbursement
- It does not replace Google’s own security controls
Monitoring is read-only by default. Where a response action is supported, it requires separate setup: an authorized user confirms manual actions, and automatic execution applies only to actions that were explicitly configured and pre-approved.
Keep two-step verification, passkeys, allowed email domains, multi-party approval, identity confirmation and the Google Ads Security Agent in place. Treat cross-platform monitoring as an additional layer over the supported advertising activity, not as a substitute for any of them.
Questions people ask mid-incident
- What should I do first if my Google Ads account is hacked?
- Report the account through Google’s compromised-account process, contain unauthorized advertising where you still can, secure the affected Google Account, and preserve the account and change-history details. If someone else may still be signed in, change the Google Account password immediately from a device you trust.
- What is the difference between a Google Account and a Google Ads account?
- The Google Account is the sign-in identity. The Google Ads account is the advertising account holding campaigns, settings and billing, identified by a 10-digit Customer ID. One Google Account can reach several Ads accounts.
- What is a Google Ads Manager Account?
- A Manager Account, previously called an MCC, is a higher-level account used to manage multiple client accounts and other Manager Accounts. A compromise at this level may affect several accounts at once, and authority over each client depends on the manager-level role and on administrative ownership.
- Should I delete unauthorized campaigns?
- Pause them first where you can. Record their IDs, settings, timestamps, destinations and spend before deleting anything. Do not delay urgent containment solely to preserve evidence.
- What is Google’s account activity change log?
- It is the log Google may email to eligible prior administrators after it confirms and secures a compromised account, showing what changed during the security event. It is not the change history you can open yourself. One eligible administrator may then submit a cleanup decision, and Google states that decision cannot be changed afterwards.
- What if I was removed as an Admin?
- Ask another legitimate Admin or administrative owner to restore access where possible. If no active administrator can help, use Google’s account access request route and report the compromise as well. Google validates ownership and decides whether permissions change.
- Can Google reimburse unauthorized ad spend?
- Google may approve reimbursement if it determines the account was compromised and unauthorized charges were billed. Recovery must be complete, the account reactivated and two-step verification enabled before the request. Google currently says billing investigations can take 10 to 15 business days, and approved credits can appear as a Service Adjustment. Approval, the amount and the timing are not guaranteed.
- What if the account was suspended because of the attacker’s campaigns?
- Complete the compromise recovery first, then remove or remediate the unauthorized policy-violating activity and submit the appeal route shown for that specific suspension. Unauthorized activity is not proof that it caused the suspension, and an appeal is not guaranteed to restore the account.
- Should I raise a chargeback with my bank?
- It depends on what you are looking at. For a charge from an Ads account you do not recognise, Google describes contacting the card issuer as an often-recommended first step. For a charge against a legitimate Ads balance, a chargeback can suspend the account or leave an overdue balance if Google contests it. The issuer makes the final decision.
- Can AdFence recover my Google Account or Ads account?
- No. Google Account and Google Ads access restoration remain with Google. AdFence can monitor and document the Google Ads signals the integration supports after an account is connected.
- Can I connect AdFence after the incident?
- Yes, once legitimate access has been restored. Monitoring begins at connection and cannot recreate a history of what happened before it.
- Does AdFence replace the Google Ads Security Agent?
- No. Google’s native security features should stay enabled. AdFence is an additional monitoring layer across the supported advertising signals of several platforms, and what it can see differs by platform.
Before you consider the incident closed
Your own record of what you have done. Ticking a step records your note to yourself; it is not confirmation from Google that the step was accepted or that the incident is closed.
Your browser’s print dialog can also save it as a PDF.
0 of 32 steps recorded.
Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.
Notes
Case and reference numbers, Customer IDs, amounts in dispute, who you spoke to, and what you are waiting on.
Back in control? Keep it that way.
AdFence monitors the supported Google Ads activity for the changes that turn compromised access into lost spend.
Related emergency guides
- Facebook and Meta Ads account hacked
The same emergency guide for a compromised Facebook profile, Meta ad account, Business portfolio or Page.
- TikTok Ads account hacked
The same emergency guide for a compromised TikTok for Business login, advertiser account or Business Center.
Related reading
- Ad account hacked: how monitoring helps
How AdFence detects and documents a compromise, rather than what to do during one.
- Security practices
How AdFence connects to advertising accounts and what it can and cannot do.
AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google. Your selection is saved only in this browser, on this device. It is never sent to AdFence.