New administrator added
Unfamiliar access appeared at 02:12
Always-on protection for your ad accounts
AdFence monitors your Meta, Google, and TikTok ad accounts and alerts you to suspicious changes, wasted spend, and delivery problems.
Landing page is down. Ads are still running.
8 active ads affected
$1,840 spent since page became unreachable
Unknown admin added to your Business Manager
Admin access · First seen 8 minutes ago
Meta delivery issue affecting 3 of your accounts
Performance dropped across all 3 accounts
Official platform status: No incident reported yet
Unexpected spend spike detected
$120 spent in the last 32 minutes
Daily budget changed: $500 → $5,000
Ad spend leaks
Hacks, mistakes, and outages leave different warning signs.
A broken page, expired SSL, or unfamiliar domain sends paid clicks to the wrong place.
An extra zero or a deliberate edit pushes a budget beyond the account's usual pattern.
Copied settings or a takeover can send spend to a country you do not sell to.
An expired card, spend limit, or account restriction stops campaigns your team expects to be running.
A Meta, Google, or Shopify incident can look like a campaign problem.
An unknown admin, partner, or connected app gains access that a password reset may not remove.
A site update removes the pixel or purchase events stop while campaigns keep spending.
Attackers can create an ad account under your Business Manager and spend through your credit line or business payment method.
Incident flows/Preview
Unfamiliar access appeared at 02:12
northstar.com → offer-deals.co
+1,376% against the recent pattern
AdFence connects the access, destination, and spend changes into one incident, then alerts the team.
An authorized user chooses an available response in the ad platform.
Signals, alert, and decision remain in activity history.
How it works
01Step
Connect Meta, Google, or TikTok through OAuth and choose your accounts; monitoring is read-only by default.
02Step
AdFence builds a baseline from recent account history: spend, domains, targeting, campaigns, and tracking.
03Step
Every 15 minutes, AdFence checks for unusual changes, broken signals, access risks, and spend problems.
04Step
Review alerts, mark safe changes, trigger Kill Switch when needed, and keep the evidence.
Incident wall
Third-party reports, with a link to every original source.
The Daily Telegraph reported that Cleonie Swim discovered unfamiliar ads after a Meta account hack, with an unexpected bill of $12,382.
Reuters reported Shopify admin and point-of-sale disruption on Cyber Monday; some merchants also encountered checkout-related issues.
The Times of India reported unauthorized Google ads over two days for Old School Rituals, with expenditure of ₹12.7 crore, around 850 times its usual daily budget.
Monica W. reported admins changed to read-only, hundreds of unauthorized Google accounts, and an invoice above $300,000 while recovery continued weeks later.
These are third-party reports, not AdFence customer testimonials.
Access watch
Track access changes and new accounts, including those outside your monitoring.
See users across Meta, Google, and TikTok; get alerts when someone is added, removed, or promoted.
Track partner access requests, additions, and expanded permissions.
Spot unfamiliar Meta apps that can remain connected after a password change.
Find new ad accounts under your Business Manager, including ones you did not create.
Meta BM #481 -Acme Corp
scan · 02:31
New · Account Radar
"Northwind Retail: Ad Account #4"
appeared under your BM · $840 spent in 12h
Removed
access revoked 2h ago
Spend protection
Watch campaign and targeting changes, destination health, product availability, tracking, billing, and account status on Meta, Google, or TikTok.
Destination health
AdFence checks live-ad destinations for broken links, expired SSL, and pages or stores unreachable in a country you advertise in.
Down for
2h 12m
Unreachable from Germany · Ads still active
Checks whole products linked in ads by reading the destinations those ads point to, and alerts when unavailable, including no purchasable variants. An individual sold-out variant stays out of scope while others remain purchasable. No store integration, alert only.
A product sells out while its ads keep running.
Flag unexpected campaigns, budget jumps, structural changes, and targeting or country shifts against the account's normal pattern, learned from recent account history. A market added to targeting can send spend somewhere you do not sell to.
A daily budget jumps while targeting expands.
Check live-ad domains against your trusted list, flag unfamiliar destinations, and read the pages behind them for broken links or expired SSL. Notice when a pixel disappears, stops firing, or an unfamiliar pixel appears while campaigns keep spending.
An ad points to a domain outside your trusted list.
Tell relevant Meta, Google, and Shopify incidents, including problems the platform has not yet acknowledged, apart from a failed card, exhausted balance, or spend limit. Catch limits, disabled accounts, or bans on Meta, Google, or TikTok.
A failed card stops active campaigns overnight.
Kill Switch
AdFence alerts you first; if nobody responds within your configured window, Kill Switch can take only the actions you approved in advance.
Pause active campaigns, set spending limits, or lower budgets using the actions you approved.
Reversible By Admin
Choose a response window; an unanswered critical incident can trigger your preapproved action when it expires.
2h Response Window → Auto Action
Choose in advance which actions AdFence may take if you do not respond.
Stop affected accounts while healthy accounts keep running.
Coverage
One account compromised → we pause just that account. Access-level breach → we pause ads across the whole BM. The response matches the threat: your healthy accounts keep running.
Choose a Business Manager and action, then follow execution status in real time.
Open the Kill Switch link in a critical alert email to dispatch a response.
Execute preapproved actions when an alert meets your severity threshold and remains unanswered past your window.
Evidence packs
Evidence Packs combine minute-level timelines, spend impact, and signed records for support cases, refund requests, and client reporting.
AdFence Evidence Pack
EP-2026-0047 · Jun 4, 02:31 AM
A PDF summary of the timeline, impact, and incident details for support, clients, or legal review.
Timestamps are captured at detection by scans running every 15 minutes.
Add your own statement to record what your team knew.
Generate in your dashboard for an account compromise or platform spend issue.
Alerts that reach you
Route alerts with incident context and each member's delivery preferences.
Hold routine alerts. Critical incidents still break through.
Bundle low-priority alerts into one clean daily summary.
Choose which alerts reach each person and where.
Suppress repeats so one does not become ten alerts.
Act without leaving the alert
Review and respond in place. Take action or mark a legitimate change safe from Slack, Telegram, or email.
AdFence Alerts
Telegram · just now
CRITICAL · Spend spike detected
Northwind Retail
Spent in last 30 min $3,420
For agencies
Separate each client's accounts, alerts, and team access in one dashboard.
Separate accounts, alerts, settings, team access, and notifications for each client.
Account Radar spots new client ad accounts that could otherwise sit outside monitoring.
Reassign accounts without reconnecting platforms or rebuilding your setup.
See where departing teammates or freelancers still have access and remove their permissions.
Flag wrong links, wrong countries, and extra zeros in budgets.
Send critical alerts and scheduled reports to trusted contacts without giving them workspace access.
Security
Monitoring never edits your ad accounts; actions such as Kill Switch require separate opt-in permission.
Certifications & reviews
Two-factor authentication is required for sensitive actions, with fresh verification before a critical change.
1 of 6Keep account changes, security actions, and team activity logged for review.
2 of 6Access tokens are encrypted at rest with AES-256-GCM and never sent to your browser.
3 of 6Sensitive actions require fresh identity verification, not just an open session.
4 of 6Review every active device and recent session activity, then sign out other sessions as needed.
5 of 6AdFence cannot create ads, change budgets, or modify platform access unless you explicitly grant write access.
6 of 6All systems operational· 99.97% uptime last 90 days
Always on
Every 15 min
Scan cadence
24 / 7
Monitoring coverage