Skip to main content

Under attack · Google ads

Google Ads account hacked? Start here.

Choose what was affected and follow the relevant steps to contain unauthorized activity, recover access, review the changes made to your account, and secure your advertising setup.

Google’s reporting form is login-gated, so it needs a working Google Account session. If you cannot sign in, begin Google Account recovery and ask another legitimate administrator with access to report the suspected compromise in parallel.

Is unauthorized spend still active?

If you still have legitimate access, pause the campaigns you cannot verify and check whether other accounts under the same login or Manager Account are also spending. If another trusted administrator still has access, ask them to contain the activity now.

Record campaign IDs, timestamps and account IDs where that is practical, but do not delay containment to build a perfect evidence file. If you have already lost access, go straight to the recovery path that matches your situation.

Before you go further

  • AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google.
  • This guide cannot promise account recovery, the identification of whoever did this, the reversal of a suspension, a credit, or a refund. It sets out the order to work in and what to record.
  • Never type a password, two-step verification code, recovery code, passkey, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.
  • Do not publish Customer IDs, invoices, case numbers or security screenshots in a public forum or social post while an incident is open. Send them only through Google’s own signed-in routes.
  • Which Google routes you are offered depends on whether you can still sign in, your access level, whether the account is personal or a Google Workspace account, your region, your payment setting and your eligibility. Work through the routes below in order rather than expecting a particular form or reply to appear.
  • Google Account, Google Ads, Google Workspace, the payments centre and Merchant Center are separate support systems. Securing one does not establish that the others are clean, and this advertising guide does not attempt to cover full Workspace or Merchant Center recovery.
  • Everything on this page is readable without an account, a signup or an email address.

Last reviewed . Official Google destinations and menu names on this page are reviewed every quarter.

Do these first, whichever Google Ads setup you use.

These four apply before the account-specific recovery paths below.

  1. 01

    Report the account as compromised

    Use Google’s compromised-account route as soon as you can reach it. The form is login-gated, so recover the Google Account first if you cannot sign in. Have the identifiers ready before you start.

    • Google Ads Customer ID
    • Manager Customer ID, where one applies
    • Email addresses that may be compromised
    • The first suspicious timestamp
    • Unknown users
    • Unknown Manager Accounts
    • Unauthorized campaigns
    • Budget increases
    • Automated rules and scripts
    • Your current IP address
    • The unauthorized amount
  2. 02

    Contain unauthorized advertising activity

    If legitimate access remains, pause what you cannot verify. Record IDs and timestamps as you go, but do not delay containment to collect perfect evidence.

    • Unfamiliar campaigns
    • Campaigns pointing at unknown destinations
    • Other accounts under the same login that are spending
    • Daily and shared budgets
    • Automated rules
    • Scripts and other automation
    • Campaign and account IDs, recorded before anything is removed
  3. 03

    Secure the Google Account and the device

    A Google Ads login is a Google Account login. If someone else may still be signed in, change the password now, preferably from a device you trust, and then remove harmful software and unfamiliar extensions.

    • Google Account password
    • Recovery email address
    • Recovery phone number
    • Signed-in devices
    • Recent security events
    • Two-step verification
    • Passkeys
    • Third-party account connections
  4. 04

    Preserve the essential evidence

    Use Google Ads change history while you still have access. It is one evidence source, not a complete forensic record: it currently covers up to two years, includes changes made by rules, the API and Google Ads Editor, and not everything it lists can be undone.

    • Who or what Google attributes each change to
    • When each change was made
    • Campaigns affected
    • Budget and bidding changes
    • Ads and assets created
    • Targeting changes
    • Conversion changes
    • Unknown managers and users
    • Billing changes
    • Relevant emails from Google
    • Support case numbers

Six different layers, and only one of them is the login.

Google uses separate account, access and billing systems, alongside a resulting suspension or enforcement state. Which system was reached and whether enforcement followed determine the recovery route, so name each affected layer before you pick a path.

  1. Google Account

    The email-based identity used to sign in. A compromise here can also expose Gmail, YouTube, Drive, Analytics, Merchant Center and other connected Google services, and it is recovered through Google Account recovery rather than through Google Ads.

  2. Individual Google Ads account

    Where campaigns, budgets, targeting, ads, conversions and billing are managed. It is identified by a 10-digit Customer ID, and one Google Account can reach several of them.

  3. Google Ads Manager Account (MCC)

    The hierarchy layer that can manage several individual accounts and other Manager Accounts. A compromise here may reach multiple client or brand accounts at once, and authority over each client depends on the manager-level role and on administrative ownership.

  4. Payments profile and billing setup

    The legally responsible payer, payment methods, tax data, billing contacts and permissions. One profile may serve several Ads accounts and other Google products, though reuse and edit rights vary by payment setting, account type, country and permission.

  5. Suspension and enforcement state

    A temporary security suspension, policy suspension or billing suspension is an enforcement state, not proof of which layer was compromised. Containment and recovery may need to run alongside a separate appeal, advertiser verification or payment-verification process.

  6. Connected products and tools

    Analytics, Merchant Center, YouTube, Business Profile, Search Console, Firebase, Google Ads Editor, scripts, automated rules, API integrations and third-party platforms. Each remains its own security domain with its own recovery process.

Securing one layer does not establish that the others are clean. A recovered Google Account can still be reachable through an unauthorized Manager Account link, a script, an API integration or a payments profile shared with another product.

Which part of your Google Ads setup was compromised?

Select one or more. A compromised Google Account can reach an individual Ads account, a Manager Account, several client accounts and a payments profile at the same time, so the paths below open in the order they should be worked through.

Select everything that happened.

No recovery paths selected yet.

Your selection is saved only in this browser, on this device. It is never sent to AdFence.

Recovery paths

Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.

Not sure yet is a valid answer. Every recovery path can be opened below, and the full post-recovery audit lists what to check across the whole setup.

Go to the full post-recovery audit

Path 1

Google Account login compromised

The sign-in identity behind Google Ads, Gmail and every other connected Google product.

When this path applies

  • The password no longer works
  • The recovery email or phone number changed
  • Two-step verification methods changed
  • An unknown device is signed in
  • Google reported suspicious activity
  • The account can no longer reach Google Ads
  • Gmail and Google Ads were lost together
  1. Step 1. If someone else may still be signed in, change the password now

    Google’s guidance is to change the password immediately when another person may still have access, preferably from a device you trust. Removing harmful software matters too, but it is not a reason to leave a live session open while you scan.

    If the device you normally use may be infected, change the password from a different trusted device, then clean the original before signing in from it again.

  2. Step 2. If you cannot sign in at all, use Google Account recovery

    Google’s recovery flow is the route when someone else may be using the account or the legitimate owner can no longer sign in. Answer from a device and a location you have used before where possible.

    Google states that it does not work with account or password recovery services, and that sign-in recovery cannot be completed by calling Google. Anyone offering paid recovery or an internal Google contact is a second attack, not a solution.

  3. Step 3. Work out whether this is a personal account or a Google Workspace account

    The two have different recovery routes, and using the consumer flow on a work account wastes the hours that matter.

    • Personal Google Account: use Google’s standard recovery and hacked-account guidance
    • Google Workspace user: contact your organisation’s Workspace administrator immediately
    • Sole or unreachable Super Admin: use Google’s administrator recovery route instead
    • Reseller customer: your reseller may need to act

    Workspace self-recovery depends on the configured recovery details and the organisation’s policy, and support-assisted recovery may require domain verification. It is not offered in every case.

  4. Step 4. Clean every device used to reach Google Ads

    • Browser extensions
    • Recently downloaded software
    • Remote-access tools
    • Unfamiliar applications
    • Malware and antivirus results
    • Browser profiles
    • Stored passwords

    A device that is still compromised can capture the new password as soon as you set it, so clean it before you sign in from it again.

  5. Step 5. Run Security Checkup and reset the recovery details

    • Recent security events
    • Signed-in devices
    • Recovery phone number
    • Recovery email address
    • Two-step verification
    • Passkeys
    • Additional protections

    Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor. Plan for that rather than assuming an instant reset.

  6. Step 6. Review the applications and services with account access

    Remove anything unfamiliar, anything no longer needed, anything added around the time of the compromise, and anything holding more access than it requires.

  7. Step 7. Continue to the Google Ads audit

    Securing the Google Account does not establish that the advertising setup is clean. An unauthorized user, Manager Account link, script or API integration can still hold access after the password changes.

My Google Account is secure. Check Google Ads next.

Path 2

Individual Google Ads account compromised

You can still sign in, but the Ads account holds activity you did not create.

When this path applies

  • Unknown campaigns or unauthorized spend
  • New users you do not recognise
  • An unfamiliar Manager Account is linked
  • Budgets increased
  • Unknown automated rules or scripts
  • Final URLs or tracking templates changed
  • Targeting or conversions changed
  • Billing information changed
  • Unexpected advertiser verification prompts
  1. Step 1. Report the compromise rather than only correcting the account

    Submit Google’s compromised-account report with the Customer ID and the timeline. Manually undoing changes does not create the case Google’s cleanup process runs from.

  2. Step 2. Review change history across the suspected period

    Set the date range to cover the whole suspected window, and record who or what Google attributes each change to.

    • User additions
    • Campaign creation
    • Budget and shared-budget changes
    • Bid changes
    • Ad and asset creation
    • Final URL changes
    • Audience and location changes
    • Conversion changes
    • Automated activity
    • Campaign pauses and activations

    Change history currently covers up to two years and can include changes made through automated rules, the Google Ads API and Google Ads Editor. Some entries can be undone and some cannot, so treat it as one evidence source rather than the whole record.

    • Google Ads Help: account history and change history (opens in a new tab)

      Google’s article on reviewing account history. Change history currently covers up to two years and can include changes made directly, by automated rules, through the Google Ads API and through Google Ads Editor. Some changes can be undone and some cannot, so treat it as one evidence source rather than a complete forensic record.

  3. Step 3. Review every user in Access and security

    • Admin users
    • Standard users
    • Read-only users
    • Billing users
    • Email-only users
    • Pending invitations
    • Authentication method
    • Last login information, where it is shown

    Admin access can manage users, manager links, product links, and the authentication-method and last-login information. Billing and Standard roles are narrower but still material. Record identifying details before removing anyone, where that is practical.

  4. Step 5. Audit every campaign, including paused and removed ones

    • Search, Shopping and Display campaigns
    • Performance Max and Demand Gen
    • Video and App campaigns
    • Shared budgets and experiments
    • Daily budgets and bid strategies
    • Locations, languages and audiences
    • Keywords and search themes
    • Ads, assets and account-level assets
    • Final URLs and tracking templates
    • Schedules, devices and conversion goals
    • Product feeds

    Pause what you cannot verify rather than deleting it first. Record IDs, settings, destinations and spend before removing anything, where containment allows.

  5. Step 6. Review the automation, not only the people

    An unauthorized change may have been made by a person, a Manager Account, a script, a rule, an application or an API integration.

    • Automated rules
    • Scripts
    • Auto-applied recommendations
    • Google Ads Editor activity
    • API-based tools
    • Third-party campaign platforms
    • Feed-management tools
    • Call-tracking integrations
  6. Step 7. Review conversions and tracking

    A compromised account can be pointed at a different event while the visible campaign still looks normal.

    • Conversion actions and goals
    • The Google tag
    • Imported Analytics conversions
    • Enhanced conversions
    • Offline conversion imports
    • Call conversions
    • Attribution settings
    • Conversion values
    • Primary and secondary status
  7. Step 8. Review the account billing and the payments profile separately

    • Payment methods
    • Payments profile
    • Payments profile users
    • Billing contacts
    • Billing country and tax information
    • Invoices and transactions
    • Account balance
    • Monthly invoicing and billing transfers
    • Unknown payment methods

    A payments profile may be shared across several Ads accounts and other Google products, so a profile-level change can reach further than this account. Google Ads Admin and Billing users can edit specified profile and payment details, but Google Ads users cannot add or remove payments profile users directly.

  8. Step 9. Review advertiser verification and certification status

    • Advertiser name and business details
    • Verification status
    • Identity documentation
    • Business operations verification
    • Unexpected certification requirements
    • New regulated-category status

    Campaigns created by an unauthorized user can change verification details or trigger certification requirements you never asked for.

  9. Step 10. Review the connected products

    If a connected product was separately compromised, use that product’s own recovery process rather than trying to fix it from Google Ads.

    • Google Analytics
    • Merchant Center
    • YouTube
    • Business Profile
    • Search Console
    • Firebase and app platforms
    • Customer Match sources
    • Third-party products

This account is contained. Check the Manager Account level next.

Path 3

Google Ads Manager Account compromised

The hierarchy layer above the accounts, where one compromise can reach many clients.

When this path applies

  • Several client accounts are affected
  • Unknown users appear in the Manager Account
  • An unfamiliar sub-manager appears
  • Client accounts were linked or unlinked
  • Legitimate agency users were removed or downgraded
  • New client accounts were created
  • Unauthorized campaigns appear across several accounts
  • Payments profiles or billing setups changed
  1. Step 1. Identify the highest affected manager level

    Work out whether the compromise reached one client account, the direct Manager Account, a parent manager, a sub-manager, or several levels at once.

    This matters because Google’s cleanup approval is level-sensitive: for a manager-level compromise, approval is limited to eligible administrators at that manager level.

  2. Step 2. Record the whole hierarchy, not only the accounts that alerted

    • Manager Account name and Customer ID
    • Parent Manager Account
    • Sub-managers
    • Linked client accounts
    • Administrative ownership status
    • Legitimate administrators
    • Unknown administrators
    • Accounts showing unauthorized activity
  3. Step 3. Review every user with access to the Manager Account

    • Admin
    • Standard
    • Read-only
    • Email-only
    • Pending invitations
    • Authentication methods
    • Last login information
    • Former employees
    • Former agencies
    • Shared or generic email addresses

    Manager administrators can invite and remove users, change access levels and manage links, but authority over a client account also depends on whether that manager is the client’s administrative owner. A manager Admin without ownership has limited client-administration powers.

  4. Step 5. Contain the client accounts where legitimate access remains

    • Pause unauthorized campaigns
    • Notify the affected client administrators
    • Ask clients to secure their own Google Accounts
    • Record unauthorized users and manager links
    • Review each client’s billing
    • Confirm which legitimate campaigns are still running

    Keep a separate record per client: Customer ID, unauthorized activity, amount affected, first suspicious time, containment time and current access status. One client incident is not the whole manager incident, and the reverse is also true.

  5. Step 6. Review accounts created during the compromise window

    • Accounts the legitimate team did not create
    • Accounts using unfamiliar billing
    • Accounts with unusually high budgets
    • Accounts targeting unrelated businesses
    • Accounts linked to unknown websites

    Google’s current process says that, where it confirms a compromise, it may unlink unauthorized Manager Accounts and set spending limits to zero on unauthorized new sub-accounts. That is a description of what Google may do, not a guarantee that it has happened.

  6. Step 7. Review the payments relationships with care

    • Linked payments profiles
    • Who holds link-management permission
    • Billing transfers
    • Consolidated billing
    • Payments profile ownership
    • Invoicing relationships
    • Pending linking requests

    Google describes manager-to-payments-profile linking as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for every dependent Ads account and stop them serving until new setups are created, so do not unlink as a containment reflex.

  7. Step 8. Report the full manager-level scope in one case

    • Manager Customer ID
    • The highest affected Manager Account
    • Every affected client Customer ID
    • Unknown Manager Account IDs
    • Unknown users
    • Unauthorized campaigns
    • Accounts where access was removed or downgraded
    • Billing impact per account
    • One timeline across the whole hierarchy

    Submitting unrelated explanations account by account, without naming the shared manager incident, makes the pattern harder for Google to see.

The hierarchy is mapped. Check unknown accounts and charges next.

Path 4

Unknown Google Ads account or unauthorized charges

An invoice, a card charge or an Ads account you never knowingly created.

When this path applies

  • A Google Ads invoice arrived for an account you do not recognise
  • A card was charged by Google Ads unexpectedly
  • An Ads account appeared under your Google Account without permission
  • You have never knowingly used Google Ads
  • A new account was created during a Google Account compromise
  • Your payment method was used in an unfamiliar Ads account
  1. Step 1. Do not assume the charge identifies the cause

    Investigate the Google Account and the payment method together, because the charge is a symptom of several possible causes.

    • A compromised Google Account
    • A new Ads account created under an existing identity
    • An existing Ads account nobody remembers
    • A compromised payment card
    • An unauthorized user or Manager Account
    • A payment method reused in another account
  2. Step 2. Gather the charge details before you contact anyone

    • Amount and currency
    • Date
    • Card or bank account used
    • Transaction reference
    • Billing descriptor
    • Invoice number
    • Customer ID, if it is shown
    • The email address that received the notification
    • Screenshots of the charge
    • Any Google Ads billing email
  3. Step 3. Sign in with the notified email and review every account it reaches

    Record any account that was not created by you, has an unfamiliar Customer ID, contains unknown campaigns, uses an unfamiliar website, carries billing activity, or was created around the suspicious date.

  4. Step 4. Secure the Google Account even if you believe only the card was used

    Complete the Google Account recovery and security steps. A card is one route in; the identity that can create an Ads account is another.

    • Password
    • Signed-in devices
    • Recent security events
    • Recovery methods
    • Two-step verification
    • Applications with account access
  5. Step 5. Use the Google route that matches what you are looking at

    • A known Ads account that was compromised: finish Google’s compromise process
    • A charge you cannot identify at all: use the unidentified-charge troubleshooter
    • An Ads account you do not recognise on the statement: read Google’s unrecognised-charge guidance first

    The troubleshooter’s questions and any temporary notices inside it change, so read what it shows you today rather than a summary written months ago.

  6. Step 6. Talk to the card issuer, knowing what a dispute does

    Google describes contacting the issuer as an often-recommended first step for a charge from an account you do not recognise, alongside cancelling or replacing the compromised card. A Google investigation and a bank dispute are separate processes with different evidence.

    The financial institution makes the chargeback decision. A chargeback raised against a legitimate Ads balance can suspend the Ads account or leave an overdue balance if Google contests it, so establish which situation you are in before disputing.

The charge route is chosen. Check whether the account was suspended.

Path 5

Google Ads account suspended after unauthorized activity

Enforcement and compromise are two different findings, and the order of work matters.

When this path applies

  • A temporary security suspension appeared
  • A policy suspension appeared
  • Circumventing Systems enforcement
  • Unacceptable Business Practices enforcement
  • Phishing or malicious-software enforcement
  • Suspicious payment enforcement
  • Advertiser verification failed
  • Unexpected certification requirements appeared
  1. Step 1. Identify which kind of suspension you are looking at

    Google may temporarily suspend an account while it secures it after suspected unauthorized activity. Unauthorized campaigns, destinations, ads or keywords can separately trigger a policy suspension. These are different findings with different routes.

    Unauthorized activity is not proof that it caused the suspension. Read the notice inside your own account rather than assuming which one applies.

  2. Step 2. Complete the compromise recovery before you appeal

    • Secure the Google Account
    • Remove unauthorized access
    • Review Manager Account links
    • Complete Google’s compromise process
    • Review the account activity change log
    • Remove or remediate unauthorized campaigns and destinations
    • Confirm billing and advertiser verification

    An appeal is not a containment step. Appealing while an unauthorized user still holds access leaves them there.

  3. Step 3. Record exactly what the suspension notice says

    • The policy named
    • The date issued
    • The account affected
    • Campaigns or destinations involved
    • Whether the account is read-only
    • Whether an appeal option is offered
    • Whether additional verification is required
  4. Step 4. Remove or pause the unauthorized policy-violating content

    • Unauthorized ads
    • Unknown final URLs
    • Cloaked or redirected destinations
    • Policy-violating keywords
    • Unfamiliar campaigns
    • Unknown business identities
    • Unauthorized payment methods
    • Misleading assets
    • Incorrect advertiser verification details
  5. Step 5. Submit one appeal that explains the compromise and the remediation

    • That the account experienced unauthorized access
    • When the compromise began
    • Which activity was unauthorized
    • Which security issues were fixed
    • Which users and managers were removed
    • Which campaigns and destinations were removed
    • Which verification details were corrected
    • Which supporting evidence is available

    An appeal is not guaranteed to restore an account. Google may require advertiser or payment-method verification first, certain selected advertisers must complete advertiser verification before appealing, separate suspended accounts generally need separate appeals, and Google says excessive appeals may not be processed. Do not file competing appeals for the same account.

  6. Step 6. Keep the compromise case and the policy appeal consistent

    The timeline, campaign IDs, affected users and remediation details should match across the compromised-account report, the account activity change log, the policy appeal, any reimbursement request and your own incident record.

The appeal is in. Check whether Admin access is still yours.

Path 6

Admin access removed or downgraded

Legitimate administrators were removed, downgraded, or replaced by someone unknown.

When this path applies

  • Legitimate Admin users were removed
  • Admins were changed to Standard or Read-only
  • Only an unknown user remains as Admin
  • The account appears under an unfamiliar Manager Account
  • An agency lost access to client accounts
  • No active administrator remains
  1. Step 1. Ask another legitimate Admin or administrative owner first

    Where one still exists, they can restore access faster than any support route.

    • Current users and access levels
    • Linked Manager Accounts
    • Pending invitations
    • Recent change history
    • Whether the affected user was removed or downgraded
  2. Step 2. Check direct access and manager access separately

    A user can lose direct account access while a legitimate Manager Account still holds it. The reverse also happens: direct Admin access remains while an unauthorized manager controls parts of the account. Inspect both routes.

  3. Step 3. Report an unauthorized access change as a compromise

    If the change was not authorised, use the compromised-account process rather than treating it as an ordinary invitation problem.

  4. Step 4. Use Google’s account access request route where it applies

    When the original administrator has left or no active Admin can grant access, Google offers an access-request route and may ask for proof of account ownership before changing permissions.

    Google validates ownership and decides whether permissions change. Submitting documents does not oblige Google to grant access, and this route is not a substitute for reporting the security incident.

  5. Step 5. Gather the ownership evidence before you ask

    • Customer ID
    • Manager Customer ID
    • Historic invoices
    • Billing details
    • Business registration
    • Domain ownership
    • Advertiser verification information
    • Previous Admin email addresses
    • Previous support cases
    • Campaign and payment history
  6. Step 6. Coordinate the correct administrator level for the cleanup

    For a confirmed manager-level compromise, Google may require an administrator at that manager level to review and approve the cleanup. Do not approve a cleanup decision until the full hierarchy and the listed changes have been reviewed.

Access is being restored. Read what happens after you report it.

Google may secure the account before it restores normal access.

If Google confirms unauthorized activity, its current process can change the account before you get it back. Knowing what it may do stops a secured account looking like a second attack.

What Google’s current process says it may do

  • Temporarily suspend the affected account while it is secured
  • Pause campaigns created or modified by the unauthorized user
  • Restrict the compromised users
  • Revoke unauthorized user or Manager Account invitations
  • Restore or re-invite legitimate users who were removed
  • Unlink unauthorized Manager Accounts
  • Set spending limits to zero on unauthorized new sub-accounts

Google says untouched legitimate campaigns may keep running while unauthorized ones are paused, depending on the security event. None of this is automatic or guaranteed, and the account activity change log can list cleanup actions that failed and still need manual remediation.

The account activity change log

  • It is sent by email after Google secures the account, if Google sends one at all
  • Only users who held an Admin role before Google’s confirmed compromise date may be eligible
  • The originally compromised user is excluded from the notification in the documented workflows
  • For a manager-level compromise, eligibility is limited to administrators at that manager level
  • Google does not disclose which administrators received the email
  • Structural-change cases may stay suspended until an eligible Admin consents and the cleanup succeeds

Clean up this account

Use this when every listed modification was unauthorized.

Restore this account as is

Use this when the activity Google flagged was in fact legitimate.

Additional investigation is needed

Use this when some of the activity is legitimate and the rest needs further review.

One administrator, one submission, no undo.

Only one eligible administrator can submit the cleanup decision, and Google states that a submitted decision cannot be changed or reverted. Read the complete change log, and agree the answer with the people who know which campaigns were real, before anyone confirms it.

Did Google send the account activity change log?

This is Google’s post-investigation log, not the change history you can open yourself. What you should do next depends on whether it has arrived.

Account activity change log

All three answers are shown. Choose one to narrow this to your situation.

This answer is not saved, and it does not change which recovery paths are open. All three answers are shown until you pick one.

The log arrived

Read the whole log before anyone answers it. The decision is submitted once, by one eligible administrator, and Google states it cannot be changed afterwards.

  • Confirm the recipient held an Admin role before Google’s confirmed compromise date
  • For a manager-level compromise, confirm they are an Admin at that manager level
  • Update the Google Account password and re-authenticate before acting on the log
  • Read every listed modification, including the ones that look routine
  • Check the log for cleanup actions that failed and still need manual remediation
  • Agree the answer with the people who know which campaigns were legitimate
  • Then have one administrator submit the single decision

Google does not disclose which administrators received the email, so absence of a copy in your own inbox does not mean nobody got one. Ask the other prior Admins before assuming it was not sent.

Nothing has arrived yet

The change history you can open inside Google Ads is not the same artefact. The account activity change log is the post-investigation record Google may email after it secures the account, and it may never be sent.

  • Keep containment and the audit going; none of it depends on the log
  • Keep the compromised-account case open and answer anything Google asks
  • Monitor the inboxes of every administrator who held Admin before the compromise
  • Check spam, filters, forwarding rules and shared mailboxes, which a compromise often touches
  • Keep using change history as your own evidence source in the meantime

Google publishes no general timing for this, so do not plan around a date. Nothing on this page can tell you when or whether a log will arrive.

You are not sure

Work out who would have been eligible to receive it, then check with them directly rather than waiting.

  • List everyone who held an Admin role before the suspected compromise date
  • Identify the level Google would treat as affected: the individual account or a manager level
  • For a manager-level incident, ask the administrators at that manager level
  • Exclude the originally compromised user, who is not notified in the documented workflows
  • Check each eligible administrator’s inbox, spam folder and any shared mailbox
  • Ask through the open support case whether a log was issued

Establishing who is eligible is worth doing now. If a log does arrive, only one of those people can answer it, and only once.

Regaining access does not mean the incident is over.

Once access is restored, inspect the whole Google Ads setup before normal advertising resumes.

Google Accounts and devices

  • Google Account passwords
  • Recovery phone numbers
  • Recovery email addresses
  • Two-step verification
  • Passkeys
  • Recent security events
  • Signed-in devices
  • Third-party connections
  • Browser extensions
  • Malware scans

Users and access

  • Admin users
  • Standard users
  • Read-only users
  • Billing users
  • Email-only users
  • Pending invitations
  • Authentication methods
  • Last login information
  • Former employees
  • Former agencies

Manager Account hierarchy

  • Parent managers
  • Sub-managers
  • Client accounts
  • Administrative ownership
  • Unknown Manager Accounts
  • Pending manager requests
  • Accounts added or removed
  • New sub-accounts

Campaigns

  • New campaigns
  • Reactivated campaigns
  • Budgets and shared budgets
  • Bid strategies
  • Locations and languages
  • Audiences
  • Keywords and search themes
  • Ads and assets
  • Final URLs
  • Tracking templates
  • Campaign schedules
  • Conversion goals

Automation

  • Automated rules
  • Scripts
  • API integrations
  • Google Ads Editor
  • Auto-applied recommendations
  • Feed tools
  • Third-party campaign platforms
  • Data imports

Tracking and conversions

  • Conversion actions
  • The Google tag
  • Analytics imports
  • Enhanced conversions
  • Offline conversion imports
  • Attribution settings
  • Conversion values
  • Primary and secondary goals

Billing and payments

  • Payment methods
  • Transactions
  • Invoices
  • Account balance
  • Payments profile
  • Payments profile users
  • Billing contacts
  • Billing transfers
  • Monthly invoicing
  • Credit lines
  • Tax details

Connected products

  • Google Analytics
  • Merchant Center
  • YouTube
  • Business Profile
  • Search Console
  • Firebase
  • Ecommerce integrations
  • Product feeds
  • Customer data sources

Verification and certification

  • Advertiser verification
  • Business name
  • Business information
  • Identity documents
  • Business operations
  • Unexpected certification requirements
  • Unexpected regulated-category status

Do not fully resume advertising until access, campaigns, automation, destinations, tracking, billing and verification have all been reviewed.

Give Google a clear incident record.

The report should make it obvious which access was unauthorized, what changed, when it happened, and what amount is being disputed.

Information to collect

  • Google Ads Customer ID
  • Manager Customer ID
  • Payments profile ID
  • The compromised Google Account email
  • Unauthorized user emails
  • Unknown Manager Account IDs
  • Campaign IDs
  • Ad-group IDs
  • Ad and asset IDs
  • Automated rule names
  • Script information
  • The first suspicious timestamp
  • The containment timestamp
  • Budget changes
  • Destination changes
  • Targeting changes
  • The unauthorized amount and the currency
  • Transaction IDs
  • Invoice numbers
  • Your current IP address
  • Screenshots
  • Google security emails
  • Support case numbers
  • The cleanup decision, if one was submitted
  • Actions already taken

A timeline in this shape is enough

  1. 01:42Unknown Admin user added
  2. 01:49Unknown Manager Account linked
  3. 01:55New campaign created
  4. 02:02Daily budget increased
  5. 02:08Final URL changed
  6. 07:14Incident discovered
  7. 07:19Campaigns paused
  8. 07:31Unknown user removed
  9. 07:42Compromised-account report submitted

Then write it as one short statement

  1. 1.Which account or hierarchy was compromised
  2. 2.Which login credentials may have been affected
  3. 3.Which activity was unauthorized
  4. 4.Which Manager Accounts or users were unfamiliar
  5. 5.How much unauthorized spend occurred
  6. 6.When the incident began and ended
  7. 7.Which security actions were completed
  8. 8.Which cleanup or reimbursement is being requested

Reimbursement, as Google currently describes it

If Google determines that the account was compromised and unauthorized charges were billed, you may be eligible for reimbursement. Google’s current process requires recovery to be complete, the Ads account reactivated and two-step verification enabled before the request is submitted through Google Ads support. Google currently says billing investigations can take 10 to 15 business days, approved credits can appear as a Service Adjustment, and final adjustments may not be confirmed until the billing cycle ends.

Completing recovery, submitting evidence or finishing a cleanup does not guarantee reimbursement, a cash refund, a particular amount, or a decision within 10 to 15 business days. Eligibility and the outcome are decided by Google.

A bank dispute is a separate process from Google’s investigation. The financial institution decides it, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance if Google contests it. Nothing on this page is legal or financial advice.

Close every route back into the account.

Google Account

  • Use a unique password, not shared with any other service
  • Turn on two-step verification
  • Add passkeys where they are offered
  • Review recovery email and phone
  • Review signed-in devices
  • Remove unknown linked applications
  • Complete Security Checkup
  • Never share one login between people

Google Ads users

  • Give each person individual access
  • Remove inactive users
  • Limit Admin access
  • Use Standard access where it is sufficient
  • Use Read-only for reporting-only users
  • Review authentication methods
  • Review last login information
  • Use business email addresses

Manager Account

  • Review every Manager Account link
  • Remove inactive agencies
  • Review sub-managers
  • Limit administrative ownership
  • Confirm who owns each client account
  • Review access after every staffing or agency change

Billing

  • Limit payments-profile access
  • Review billing users
  • Review shared payments profiles
  • Review Manager Account payment links
  • Confirm billing contacts
  • Remove outdated finance access
  • Review invoices and adjustments regularly

Google’s own controls, with the conditions attached

Allowed email domains

Restricts which email domains may be invited in future. It does not remove users who already have access, and a Manager Account mandate reaches only the sub-accounts that manager administratively owns.

Multi-party approval

Google currently applies this only to accounts with more than three administrators, and read-only roles and API users are exempt. Eligible account or linked-manager Admins can approve, requests expire after 20 days, and Google Support cannot override an internal approver who does not respond.

  • Google Ads Help: multi-party approval (opens in a new tab)

    Google currently applies this only to accounts with more than three administrators; read-only roles and API users are exempt. Requests expire after 20 days, and Google Support cannot override an internal approver who does not respond.

Confirm it is you, and passkeys

Google may challenge Standard or Admin invitations, unusual budget or bulk changes, new destination domains, and campaigns for previously unused apps. It is independent of two-step verification and is not triggered for every action. Any advertiser can set up a passkey, and Google may require one for some sensitive actions.

Google Ads Security Agent

Google describes behavioural monitoring, unusual-user and domain detection, login-activity monitoring and access-level suggestions. Review the security insights if your account shows them; they are suggestions rather than an automatic block or remediation.

Two-step verification

Required before a reimbursement request under Google’s current process, and worth keeping enabled regardless. Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor.

Keep Google’s own controls switched on. They are the layer that decides who can reach the account; nothing on this page replaces them.

A note on Google’s changing menu names

Google updates Google Ads regularly, so the exact labels on your screen may not match a guide written a few months ago. Where a menu name here does not exist in your interface, look for the nearest equivalent under Admin, Access and security, Billing, or the account history views rather than assuming the setting was removed.

Every official destination on this page

Make the next incident easier to catch.

This part is about AdFence. It comes last on purpose: nothing here helps you recover the account you are trying to recover today.

If AdFence was already connected

  • User access changes
  • Manager or partner access changes
  • Campaign changes
  • Budget changes
  • Targeting changes
  • Domains and destinations
  • Conversion and tracking changes
  • Account status
  • Billing signals
  • Connection health

Availability depends on the Google integration, the permissions granted, your plan and your monitoring configuration, so treat the list above as the signals that may be supported for a Google Ads account rather than as a guarantee for yours. Monitoring is read-only by default, and AdFence connects by OAuth: it does not request or store platform passwords.

If AdFence was not connected

AdFence cannot reconstruct activity that occurred before the Google Ads account was connected. Once legitimate access has been restored, it can begin monitoring the Google Ads signals the integration supports, from that point forward.

An Evidence Pack organizes the activity AdFence recorded after connection into a documented timeline for support, disputes and internal review. It documents recorded activity only, and it does not prove fraud or guarantee a platform decision, a charge reversal or a reimbursement.

What it cannot do

  • AdFence cannot restore Google access
  • It cannot reverse a suspension
  • It cannot identify the attacker
  • It cannot determine reimbursement
  • It does not replace Google’s own security controls
Secure the account you recovered

Monitoring is read-only by default. Where a response action is supported, it requires separate setup: an authorized user confirms manual actions, and automatic execution applies only to actions that were explicitly configured and pre-approved.

Keep two-step verification, passkeys, allowed email domains, multi-party approval, identity confirmation and the Google Ads Security Agent in place. Treat cross-platform monitoring as an additional layer over the supported advertising activity, not as a substitute for any of them.

Questions people ask mid-incident

What should I do first if my Google Ads account is hacked?
Report the account through Google’s compromised-account process, contain unauthorized advertising where you still can, secure the affected Google Account, and preserve the account and change-history details. If someone else may still be signed in, change the Google Account password immediately from a device you trust.
What is the difference between a Google Account and a Google Ads account?
The Google Account is the sign-in identity. The Google Ads account is the advertising account holding campaigns, settings and billing, identified by a 10-digit Customer ID. One Google Account can reach several Ads accounts.
What is a Google Ads Manager Account?
A Manager Account, previously called an MCC, is a higher-level account used to manage multiple client accounts and other Manager Accounts. A compromise at this level may affect several accounts at once, and authority over each client depends on the manager-level role and on administrative ownership.
Should I delete unauthorized campaigns?
Pause them first where you can. Record their IDs, settings, timestamps, destinations and spend before deleting anything. Do not delay urgent containment solely to preserve evidence.
What is Google’s account activity change log?
It is the log Google may email to eligible prior administrators after it confirms and secures a compromised account, showing what changed during the security event. It is not the change history you can open yourself. One eligible administrator may then submit a cleanup decision, and Google states that decision cannot be changed afterwards.
What if I was removed as an Admin?
Ask another legitimate Admin or administrative owner to restore access where possible. If no active administrator can help, use Google’s account access request route and report the compromise as well. Google validates ownership and decides whether permissions change.
Can Google reimburse unauthorized ad spend?
Google may approve reimbursement if it determines the account was compromised and unauthorized charges were billed. Recovery must be complete, the account reactivated and two-step verification enabled before the request. Google currently says billing investigations can take 10 to 15 business days, and approved credits can appear as a Service Adjustment. Approval, the amount and the timing are not guaranteed.
What if the account was suspended because of the attacker’s campaigns?
Complete the compromise recovery first, then remove or remediate the unauthorized policy-violating activity and submit the appeal route shown for that specific suspension. Unauthorized activity is not proof that it caused the suspension, and an appeal is not guaranteed to restore the account.
Should I raise a chargeback with my bank?
It depends on what you are looking at. For a charge from an Ads account you do not recognise, Google describes contacting the card issuer as an often-recommended first step. For a charge against a legitimate Ads balance, a chargeback can suspend the account or leave an overdue balance if Google contests it. The issuer makes the final decision.
Can AdFence recover my Google Account or Ads account?
No. Google Account and Google Ads access restoration remain with Google. AdFence can monitor and document the Google Ads signals the integration supports after an account is connected.
Can I connect AdFence after the incident?
Yes, once legitimate access has been restored. Monitoring begins at connection and cannot recreate a history of what happened before it.
Does AdFence replace the Google Ads Security Agent?
No. Google’s native security features should stay enabled. AdFence is an additional monitoring layer across the supported advertising signals of several platforms, and what it can see differs by platform.

Before you consider the incident closed

Your own record of what you have done. Ticking a step records your note to yourself; it is not confirmation from Google that the step was accepted or that the incident is closed.

Your browser’s print dialog can also save it as a PDF.

0 of 32 steps recorded.

Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.

Back in control? Keep it that way.

AdFence monitors the supported Google Ads activity for the changes that turn compromised access into lost spend.

Related emergency guides

Related reading

AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google. Your selection is saved only in this browser, on this device. It is never sent to AdFence.