Conceptual image depicting cybersecurity breach with stolen meta and Google ad accounts, emphasizing data protection and digital security.

A stolen Meta Business Manager account with a $5,000 monthly budget can be emptied in hours. Both Meta and Google run on pre-loaded credit or card-on-file billing, so campaigns keep spending until they hit a budget cap or someone intervenes — and if nobody is watching the account overnight or across a weekend, the cap is the only brake. (Source: Helpnetsecurity)

The account itself is the asset.

Key Insight: That cash drain is the part most businesses notice first, and according to Mimecast it is the least valuable part to the attacker.

"Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account. This is what makes the older, higher-history account worth a 2 to 4 times premium in the underground market," Mimecast explained.

Your years of clean spending history are what the buyer is paying for. An account with verification status, an established daily spending limit, and no policy strikes can push scam creative through review systems that would reject a freshly registered advertiser, which is why this asset class trades on age rather than balance.

Pricing reflects that. Zscaler reports stolen Meta Business Manager accounts selling from roughly $15 to $340, with some Google Ads accounts tied to high-risk sectors listed at $200 to $270 on Telegram. The market around them has hardened into ordinary commerce — tiered pricing, escrow services, and money-back warranties on stolen accounts.

Why recovery takes longer than the theft

Shutting off fraudulent spend is usually a same-day fix: you notice unfamiliar campaigns and cancel the linked payment method. Getting the account back is a different problem entirely.

Attackers who gain access typically add their own admin users and downgrade the legitimate owner to a limited role. Platform permission structures don't always allow a newly added admin to reverse that, so the person who built the account can no longer remove the person who stole it.

Reclaiming ownership and rebuilding standing with the platform's review systems can take months. During that window your account may sit in appeal queues while campaigns stay paused or, worse, keep running under someone else's control.

There is also no financial backstop comparable to the one you have on a corporate card. As Mimecast's researchers put it, unlike card fraud with its chargeback and zero-liability protections, the platforms offer no equivalent, and have a structural financial incentive not to act quickly.

The incentive problem behind slow response

Every impression served from a compromised account earns the platform revenue, regardless of who is paying. A 2026 class-action complaint from the Consumer Federation of America cites Meta's own estimates putting scam advertising at 15 billion impressions a day, worth an annualized $7 billion in revenue, and alleges Meta prioritized that revenue over user safety.

Enforcement exists — Meta sued scam advertisers in February 2026 and worked with law enforcement on Southeast Asian criminal networks the following month — but an account under review can keep serving ads while the review proceeds. Malwarebytes documented one advertiser that remained active after 30 reports.

The downstream cost lands on you rather than the platform. Scam creative served from your verified business page reaches the audiences you built, your pixel and conversion data get polluted by fraudulent traffic, and paused campaigns mean lost pipeline for however long the appeal takes.

Mimecast's Threat Research Team logged 6.4 million detections of Meta Business Manager and Google Ads account theft across four years, with roughly 1.86 million in the second half of 2025 alone — the highest volume of any period in the dataset.

DuckTail, NodeStealer, PXA Stealer, and VietCredCare: Malware Families Targeting Ad Platforms

DuckTail, NodeStealer, VietCredCare, and PXA Stealer are the four Vietnam-linked malware families Mimecast associates with the bulk of Meta Business Manager and Google Ads account theft it has tracked. Across four years, its Threat Research Team logged 6.4 million detections tied to these campaigns, with roughly 1.86 million landing in the second half of 2025 alone — the highest volume of any period in the dataset.

They are not the only cluster. Mimecast also traces separate operations to Brazil and Portugal and to China and Hong Kong, which matters operationally: this is not one crew with one toolkit, but several independent supply chains all converging on the same two ad platforms.

The PXA Stealer case shows how durable that structure is. The ring was dismantled in March 2026 with 14 people prosecuted, and detection volume dropped for a period before starting to recover. That pattern repeats across the full four-year trend line — takedowns and arrests produce a dip, then activity returns to equal or higher levels.

The more useful detail for defenders is how these campaigns reach an inbox in the first place. Rather than standing up purpose-built malicious domains, the operators route delivery through legitimate, high-reputation sending platforms that email security tooling is configured to trust:

  • Salesforce infrastructure accounted for about one in three detections in Mimecast's telemetry.
  • Google Workspace mail-merge tools and SharePoint-hosted links together delivered roughly another quarter.

Mimecast's researchers were direct about why that distribution exists: "Salesforce and Google carry established sender reputations that bypass reputation-based filtering. Delivery through these platforms means the sending IP, domain, and authentication records (SPF, DKIM) all pass checks that would reject an unknown domain. The attacker's only task is to make the content convincing."

Read that as a control failure rather than a filter bug. If your mail gateway decisions rest heavily on sender reputation and authentication results, a phishing message carrying valid SPF and DKIM from Salesforce or Google Workspace arrives with the same signals as your own vendor correspondence. Detection engineering has to shift from "who sent this" to "what does this ask the recipient to do."

From there the chain runs through phishing templates and credential-harvesting pages aimed at the people who hold administrative rights on the ad account — marketing staff, agency contacts, and contractors, not necessarily the users your identity monitoring watches most closely. Once access is established, operators add their own admin users and downgrade the legitimate owner to a limited role, which is where a credential-theft incident becomes an ownership dispute with the platform.

Mapped to MITRE ATT&CK, the observable behavior in these campaigns lines up with:

  • T1566 – Phishing, delivered via trusted third-party sending infrastructure.
  • T1078 – Valid Accounts, using harvested advertiser credentials against the platform directly.
  • T1098 – Account Manipulation, covering the added admin users and role downgrades.

The commodity nature of the ecosystem — tiered pricing, escrow, money-back warranties on stolen accounts — means the malware operator and the eventual account buyer are frequently different parties. A single credential-harvesting hit on one marketing manager can therefore surface as unfamiliar ad activity weeks later, under an operator who never touched your network.

How Attackers Monetize Compromised Ad Accounts

Access to these accounts rarely starts at the ad platform itself. Mimecast traced how the phishing that precedes compromise actually reaches inboxes, and found attackers have largely abandoned purpose-built malicious infrastructure in favor of sending platforms your email gateway is configured to trust.

About one in three detections in these campaigns arrived through Salesforce infrastructure. Another quarter came through Google Workspace mail-merge tools and SharePoint-hosted links. Because the sending IP, domain, SPF, and DKIM records all belong to a legitimate high-reputation service, reputation-based filtering passes the message. As Mimecast put it, the attacker's only remaining task is making the content convincing.

Once credentials or session data land, the first meaningful action is permission manipulation rather than spending. Attackers add their own admin users to the Business Manager or Ads account and downgrade the legitimate owner to a limited role — a straightforward case of account manipulation (MITRE ATT&CK T1098) layered on valid account abuse (T1078).

That ordering matters operationally. Platform permission structures do not always allow a newly added admin to reverse the change, so the person who built the account can be left without the authority to evict the intruder. Recovering ownership then runs through the platform's review and appeal systems, which Mimecast says can take months.

Spending happens against the card or pre-loaded credit already attached to the account, which is why the fastest available brake is cancelling the linked payment method rather than fixing permissions. The billing relationship is what attackers monetize, and it survives the owner losing administrative control.

Ads keep serving while complaints are processed. Malwarebytes documented one advertiser that remained active after 30 reports, and an account under review can continue delivering impressions for the duration of that review. For the business named on the account, that means unfamiliar campaigns run under your brand while the ticket sits in a queue.

The resale side has the structure of a functioning market. Pricing is tiered on age, spending history, verification status, and daily spending limits, and sellers offer escrow services and money-back warranties on the accounts they move.

  • Meta Business Manager accounts: Zscaler reports listings from roughly $15 to $340, depending on account attributes.
  • Google Ads accounts for high-risk sectors: listed at $200 to $270 on Telegram.
  • Sales channels: Telegram-based storefronts with warranties and escrow, which lowers the buyer's risk of paying for a dead account.

Buyers are not necessarily the operators who stole the account. The escrow-and-warranty layer separates intrusion from monetization, so a credential thief can sell to someone who wants an established advertising identity for scam campaigns and never touch the campaign side at all. That resale chain is why shutting down fraudulent spend does not end the exposure — the account can change hands again after the original theft is contained.

Platform economics reinforce the cycle. Every impression served earns revenue whether the spender is the legitimate advertiser or an attacker, and a 2026 class-action complaint from the Consumer Federation of America cites Meta's own estimates placing scam advertising at 15 billion impressions a day, worth an annualized $7 billion. The complaint alleges Meta prioritized that revenue over user safety.

Mimecast also notes the absence of a financial backstop: unlike card fraud, where chargeback and zero-liability protections apply, the ad platforms offer no equivalent and, in the researchers' assessment, carry a structural financial incentive not to act quickly. The loss sits with the advertiser, both in spend and in the time the account stays out of reach.

Immediate Actions for Marketing and Finance Teams

Start with the user list, not the campaigns. Open Business Settings > People in Meta Business Manager and the Tools & Settings > Access and security page in Google Ads, and compare every admin, employee, and partner entry against a list of people who should be there. Attackers who take an ad account add their own admin and demote the real owner to a limited role, and platform permission structures don't always let you undo that once you've lost admin rights.

In the first hour, work through four things in order:

  • Remove unrecognized users and partner (business) connections while you still hold admin. Note anything you cannot remove — that's evidence you've already been downgraded, and it changes your case from a security cleanup to a platform recovery.
  • Check the billing section for changes: new cards, new payment profiles, and any edit to the billing contact email. A swapped notification address is how attackers keep spend receipts out of your inbox.
  • Pause all active campaigns and remove the card on file to stop spend against a budget cap rather than against your intervention.
  • File the compromise report with Meta or Google support the same hour, before the appeal queue backs up. Recovery of the account itself can take months, so the timestamp on your report matters.

Within 24 hours, deal with the credential that let them in. Force a password reset on every user who had access, then move that group off SMS and app codes to hardware security keys under Accounts Center > Password and security > Two-factor authentication in Meta and the equivalent 2-Step Verification setting on the Google account behind your Ads login. Session cookies stolen by an infostealer survive a password change, so revoke active sessions and remove unknown authorized devices as part of the same pass.

Then audit what else holds a token to the account. Review connected apps, API access, third-party reporting and automation tools, and any agency that authenticates through OAuth rather than a named user. Pull the last 30 days of spend and change history, flag campaigns and assets you don't recognize, and open disputes with your card issuer or payment processor for the unauthorized charges — platforms offer no chargeback equivalent, so your card network is the only recovery path for the money.

Because the entry point in these campaigns is a phished or stolen credential rather than a platform flaw, identity telemetry is where you catch it early. In environments Capstone manages, Adlumin monitors authentication behavior across managed environments and surfaces the impossible-travel logins, new-device approvals, and off-hours access that precede an ad account takeover, which gives your marketing team warning before the first unfamiliar campaign appears.

Over the next 30 days, treat the ad accounts like the financial assets they are:

  • Centralize access through SSO so ad platform logins live in your identity provider and die with the employee's account, not in a shared browser profile.
  • Apply IP allowlisting where the platform supports it, and require login approval from registered devices only.
  • Monitor browser extensions on the machines your marketers use — extension permissions are a quiet route to session tokens.
  • Run a weekly account health check covering users, partners, payment methods, and admin changes.

Set alerting thresholds your finance team owns: spend above 150% of the daily average, any new payment method added, and any campaign created outside business hours. Route those alerts to a shared mailbox with more than one recipient so a single compromised inbox cannot suppress them.

Detection Strategies for Security Operations Centers

The highest-value detection you can build here is a correlation rule, not a signature: an infostealer alert on a marketing user's endpoint followed within days by an administrative change in your ad accounts. Neither event alone will get triaged with urgency in most SOCs. Together they describe the full kill chain of these campaigns, from credential and cookie theft to account takeover.

Start by making the ad platforms a monitored log source. Marketing tools usually sit outside SIEM coverage, which is why takeover is typically discovered by a finance alert rather than security. Pull these into your pipeline:

  • Meta Business Manager security and admin activity logs — user additions, role changes, partner (business) connections, two-factor setting changes.
  • Google Ads change history and access logs — new users, linked manager accounts, API access grants, and modifications to daily spending limits.
  • Payment events — card-on-file changes, new billing profiles, and processor notifications for advertising charges outside normal cycles.
  • Identity provider sign-in logs for the Google and Meta identities used to administer campaigns, including OAuth grant events.
  • Browser telemetry from endpoints belonging to anyone with ad account admin rights.

On the endpoint side, the behavior worth alerting on is access to browser credential and session storage by processes that have no business reading it. DuckTail-class tooling steals session cookies rather than passwords, which means the attacker inherits an already-authenticated session and never triggers a password or MFA prompt. Your detection logic should treat any non-browser process opening browser profile directories, cookie stores, or local storage as a high-priority event, along with extension installations that were not pushed by policy and unexpected launches of browsers with remote-debugging or automation flags.

SentinelOne catches the process-level side of this in managed environments — credential-store access, injection into browser processes, and the persistence that follows — so the endpoint alert exists to correlate against before anyone notices unfamiliar campaigns. That correlation is the point: an EDR detection on a media buyer's laptop is a low-severity ticket in isolation, and a critical one when the same user's ad account gains an admin the following week.

Build the composite rule with three signals and weight it accordingly:

  • Infostealer or credential-access detection on a host tied to an ad-account admin.
  • Ad platform access or API activity from an ASN, country, or device fingerprint outside that user's baseline, especially where session activity overlaps with a legitimate session.
  • A budget, spending-limit, or payment-method change within a short window of either of the above.

Two of those three should page someone. All three is a confirmed takeover in progress, and your first containment step is revoking active sessions and OAuth tokens for the affected identity rather than only resetting the password — a stolen cookie survives a password change.

For false positives, baseline before you alert. Agencies, bid-management platforms, and reporting connectors legitimately hit these APIs constantly, so scope alerts to the OAuth application IDs and IP ranges you have approved, and treat requests from a new client ID as the anomaly rather than volume alone. Distinguish read patterns too: normal tooling pulls campaign metrics on a schedule, while takeover activity clusters around user management, billing, and creative uploads. Exclude your known agency source ranges explicitly and review that allowlist quarterly so a dormant partner integration doesn't become a permanent blind spot.

Preventing Ad Account Compromise: Technical and Organizational Controls

The most useful control you can add is separation: do the ad platform administration from a dedicated machine or a dedicated browser profile that does no general email or web browsing. The compromise chain in these campaigns runs through the browser profile of a marketing user, so removing that profile from the same machine that opens attachments removes most of the exposure in one step.

Endpoint prevention comes first because the malware families driving this activity are active now, not historical. Marketing and social media laptops are frequently treated as low-risk assets and end up with lighter endpoint coverage than finance or engineering machines.

  • Run endpoint detection in blocking mode, not alert-only, on every device that authenticates to Meta Business Manager or Google Ads.
  • Restrict browser extension installation to an allowlist using enterprise browser policy (ExtensionInstallAllowlist), since malicious or hijacked extensions read cookies and stored credentials directly.
  • Disable in-browser password saving and profile sync on those machines, so a single infostealer execution does not hand over the whole credential set.

On identity, understand why password-plus-app 2FA is not enough here. These infostealers take the authenticated session cookie out of the browser profile, and a replayed session presents as an already-logged-in user, so no second factor is ever requested. Your MFA policy is not bypassed so much as skipped.

Enforce FIDO2 hardware security keys on the Google and Meta identities that hold ad account admin rights. Hardware keys stop the phishing side of the chain outright, because credentials captured on a lookalike page cannot be replayed against the real login. Pair them with shortened session lifetimes and forced reauthentication for administrative changes, which is what actually limits stolen-cookie value.

Then add conditional access rules that flag or block sign-ins from new devices and unfamiliar geographies for those specific accounts. Ad platform administration is usually done by a handful of named people from predictable locations, which makes the baseline unusually tight and the anomalies unusually obvious.

At the platform layer, three settings do most of the work:

  • Turn on IP allowlisting where the platform supports it, restricting admin access to your office and VPN egress ranges.
  • Require a documented approval step for payment method changes and for any budget increase above a threshold you set, with finance notified independently of the marketing team.
  • Audit and revoke unused API tokens and third-party app connections. Reporting dashboards, bid management tools, and former agency integrations often keep API access long after the business relationship ends.

Set per-campaign spending caps and account-level daily limits deliberately rather than leaving them wide. Because these platforms bill against pre-loaded credit or a card on file, the cap is the practical ceiling on loss during the hours before anyone notices unfamiliar campaigns — a $500 daily limit and a $10,000 one produce very different overnight outcomes on the same compromise.

Organizationally, keep a written list of who holds admin rights on each ad and partner account, review it monthly, and remove access when people change roles rather than when they leave. Rotate the credentials behind these accounts quarterly; Passportal stores and rotates those shared marketing platform credentials across managed environments so rotation actually happens on schedule instead of after an incident.

Assign one named owner per ad account who is responsible for the admin list, the payment method, and the spending caps. Accounts shared informally across a marketing team are the ones where an added admin goes unnoticed for weeks.

The Critical Next Step

The economics explain why enforcement hasn't slowed this. Stolen Meta Business Manager accounts sell for roughly $15 to $340 according to Zscaler, with some Google Ads accounts serving high-risk sectors listed at $200 to $270 on Telegram — a resale market with tiered pricing, escrow, and money-back warranties on stolen inventory. Arrests and takedowns produce a dip in detections, then volume returns to equal or higher levels.

What that means for your business is that the loss you can reverse is the smaller one. Fraudulent spend usually stops within hours once someone cancels the linked payment method. Getting the account back is a different process entirely, and it can run for months while the account sits in platform appeal queues.

There is no chargeback equivalent here. Mimecast's researchers note that platforms offer no protection comparable to card zero-liability, and have a structural financial incentive not to act quickly — an account under review keeps serving ads while the review plays out. Malwarebytes documented one advertiser that stayed active after 30 reports.

The scale of that incentive is documented in a 2026 class-action complaint from the Consumer Federation of America, which cites Meta's own estimates of 15 billion scam ad impressions a day, worth an annualized $7 billion.

The takeaway for your organization is that an ad account is a liquid asset with a resale value independent of its balance, and the party best positioned to detect the theft is you, not the platform. Review the login and access history on your Meta and Google Ads accounts for sessions you cannot account for. Treat unfamiliar logins as compromise rather than as something to confirm later.

In This Article

Top hits