Skip to main content

Under attack · Google ads

Google Ads account hacked? Start here.

Choose what was affected and follow the relevant steps to contain unauthorized activity, recover access, review the changes made to your account, and secure your advertising setup.

Before you go further

  • AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google.
  • This guide cannot promise account recovery, the identification of whoever did this, the reversal of a suspension, a credit, or a refund. It sets out the order to work in and what to record.
  • Never type a password, two-step verification code, recovery code, passkey, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.

Last reviewed . Official Google destinations and menu names on this page are reviewed every quarter.

Do these first, whichever Google Ads setup you use.

These three apply before the account-specific recovery paths below.

  1. 01

    Contain unauthorized advertising activity

    If legitimate access remains, pause what you cannot verify. Record IDs and timestamps as you go, but do not delay containment to collect perfect evidence. If you have lost access, do not spend time trying to force a pause. Ask a trusted administrator who still has access to contain the activity, then go to the recovery path that matches your situation.

    • Unfamiliar campaigns
    • Campaigns pointing at unknown destinations
    • Other accounts under the same login that are spending
    • Daily and shared budgets
    • Automated rules
    • Scripts and other automation
    • Campaign and account IDs, recorded before anything is removed
  2. 02

    Secure the Google Account and the device

    A Google Ads login is a Google Account login. If someone else may still be signed in, change the password now, preferably from a device you trust, and then remove harmful software and unfamiliar extensions.

    • Google Account password
    • Recovery email address
    • Recovery phone number
    • Signed-in devices
    • Recent security events
    • Two-step verification
    • Passkeys
    • Third-party account connections
  3. 03

    Preserve the essential evidence

    Use Google Ads change history while you still have access. It is one evidence source, not a complete forensic record: it currently covers up to two years, includes changes made by rules, the API and Google Ads Editor, and not everything it lists can be undone.

    • Who or what Google attributes each change to
    • When each change was made
    • Campaigns affected
    • Budget and bidding changes
    • Ads and assets created
    • Targeting changes
    • Conversion changes
    • Unknown managers and users
    • Billing changes
    • Relevant emails from Google
    • Support case numbers

Which part of your Google Ads setup was compromised?

Select one or more. A compromised Google Account can reach an individual Ads account, a Manager Account, several client accounts and a payments profile at the same time, so the paths below open in the order they should be worked through.

Select everything that happened.

No recovery paths selected yet.

Your selection is saved only in this browser, on this device. It is never sent to AdFence.

Recovery paths

Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.

Not sure yet is a valid answer. Every recovery path can be opened below, and the final checklist covers the whole setup.

Go to the final checklist

Path 1

Google Account login compromised

The sign-in identity behind Google Ads, Gmail and every other connected Google product.
  1. Step 1. If someone else may still be signed in, change the password now

    Google’s guidance is to change the password immediately when another person may still have access, preferably from a device you trust. Removing harmful software matters too, but it is not a reason to leave a live session open while you scan.

    If the device you normally use may be infected, change the password from a different trusted device, then clean the original before signing in from it again.

  2. Step 2. If you cannot sign in at all, use Google Account recovery

    Google’s recovery flow is the route when someone else may be using the account or the legitimate owner can no longer sign in. Answer from a device and a location you have used before where possible.

    Google states that it does not work with account or password recovery services, and that sign-in recovery cannot be completed by calling Google. Anyone offering paid recovery or an internal Google contact is a second attack, not a solution.

  3. Step 3. Work out whether this is a personal account or a Google Workspace account

    The two have different recovery routes, and using the consumer flow on a work account wastes the hours that matter.

    • Personal Google Account: use Google’s standard recovery and hacked-account guidance
    • Google Workspace user: contact your organisation’s Workspace administrator immediately
    • Sole or unreachable Super Admin: use Google’s administrator recovery route instead
    • Reseller customer: your reseller may need to act

    Workspace self-recovery depends on the configured recovery details and the organisation’s policy, and support-assisted recovery may require domain verification. It is not offered in every case.

  4. Step 4. Clean every device used to reach Google Ads

    • Browser extensions
    • Recently downloaded software
    • Remote-access tools
    • Unfamiliar applications
    • Malware and antivirus results
    • Browser profiles
    • Stored passwords

    A device that is still compromised can capture the new password as soon as you set it, so clean it before you sign in from it again.

  5. Step 5. Run Security Checkup and reset the recovery details

    • Recent security events
    • Signed-in devices
    • Recovery phone number
    • Recovery email address
    • Two-step verification
    • Passkeys
    • Additional protections

    Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor. Plan for that rather than assuming an instant reset.

  6. Step 6. Review the applications and services with account access

    Remove anything unfamiliar, anything no longer needed, anything added around the time of the compromise, and anything holding more access than it requires.

  7. Step 7. Continue to the Google Ads audit

    Securing the Google Account does not establish that the advertising setup is clean. An unauthorized user, Manager Account link, script or API integration can still hold access after the password changes.

My Google Account is secure. Check Google Ads next.

Path 2

Individual Google Ads account compromised

You can still sign in, but the Ads account holds activity you did not create.
  1. Step 1. Use Google’s report if you need Google to act

    If you need Google to secure or restore access, review unauthorized activity, or take another platform-side action, submit its compromised-account report with the Customer ID and timeline.

  2. Step 2. Review change history across the suspected period

    Set the date range to cover the whole suspected window, and record who or what Google attributes each change to.

    • User additions
    • Campaign creation
    • Budget and shared-budget changes
    • Bid changes
    • Ad and asset creation
    • Final URL changes
    • Audience and location changes
    • Conversion changes
    • Automated activity
    • Campaign pauses and activations

    Change history currently covers up to two years and can include changes made through automated rules, the Google Ads API and Google Ads Editor. Some entries can be undone and some cannot, so treat it as one evidence source rather than the whole record.

    • Google Ads Help: account history and change history (opens in a new tab)

      Google’s article on reviewing account history. Change history currently covers up to two years and can include changes made directly, by automated rules, through the Google Ads API and through Google Ads Editor. Some changes can be undone and some cannot, so treat it as one evidence source rather than a complete forensic record.

  3. Step 3. Review every user in Access and security

    • Admin users
    • Standard users
    • Read-only users
    • Billing users
    • Email-only users
    • Pending invitations
    • Authentication method
    • Last login information, where it is shown

    Admin access can manage users, manager links, product links, and the authentication-method and last-login information. Billing and Standard roles are narrower but still material. Record identifying details before removing anyone, where that is practical.

  4. Step 5. Audit every campaign, including paused and removed ones

    • Search, Shopping and Display campaigns
    • Performance Max and Demand Gen
    • Video and App campaigns
    • Shared budgets and experiments
    • Daily budgets and bid strategies
    • Locations, languages and audiences
    • Keywords and search themes
    • Ads, assets and account-level assets
    • Final URLs and tracking templates
    • Schedules, devices and conversion goals
    • Product feeds

    Pause what you cannot verify rather than deleting it first. Record IDs, settings, destinations and spend before removing anything, where containment allows.

  5. Step 6. Review the automation, not only the people

    An unauthorized change may have been made by a person, a Manager Account, a script, a rule, an application or an API integration.

    • Automated rules
    • Scripts
    • Auto-applied recommendations
    • Google Ads Editor activity
    • API-based tools
    • Third-party campaign platforms
    • Feed-management tools
    • Call-tracking integrations
  6. Step 7. Review conversions and tracking

    A compromised account can be pointed at a different event while the visible campaign still looks normal.

    • Conversion actions and goals
    • The Google tag
    • Imported Analytics conversions
    • Enhanced conversions
    • Offline conversion imports
    • Call conversions
    • Attribution settings
    • Conversion values
    • Primary and secondary status
  7. Step 8. Review the account billing and the payments profile separately

    • Payment methods
    • Payments profile
    • Payments profile users
    • Billing contacts
    • Billing country and tax information
    • Invoices and transactions
    • Account balance
    • Monthly invoicing and billing transfers
    • Unknown payment methods

    A payments profile may be shared across several Ads accounts and other Google products, so a profile-level change can reach further than this account. Google Ads Admin and Billing users can edit specified profile and payment details, but Google Ads users cannot add or remove payments profile users directly.

  8. Step 9. Review advertiser verification and certification status

    • Advertiser name and business details
    • Verification status
    • Identity documentation
    • Business operations verification
    • Unexpected certification requirements
    • New regulated-category status

    Campaigns created by an unauthorized user can change verification details or trigger certification requirements you never asked for.

  9. Step 10. Review the connected products

    If a connected product was separately compromised, use that product’s own recovery process rather than trying to fix it from Google Ads.

    • Google Analytics
    • Merchant Center
    • YouTube
    • Business Profile
    • Search Console
    • Firebase and app platforms
    • Customer Match sources
    • Third-party products

This account is contained. Check the Manager Account level next.

Path 3

Google Ads Manager Account compromised

The hierarchy layer above the accounts, where one compromise can reach many clients.
  1. Step 1. Identify the highest affected manager level

    Work out whether the compromise reached one client account, the direct Manager Account, a parent manager, a sub-manager, or several levels at once.

    This matters because Google’s cleanup approval is level-sensitive: for a manager-level compromise, approval is limited to eligible administrators at that manager level.

  2. Step 2. Record the whole hierarchy, not only the accounts that alerted

    • Manager Account name and Customer ID
    • Parent Manager Account
    • Sub-managers
    • Linked client accounts
    • Administrative ownership status
    • Legitimate administrators
    • Unknown administrators
    • Accounts showing unauthorized activity
  3. Step 3. Review every user with access to the Manager Account

    • Admin
    • Standard
    • Read-only
    • Email-only
    • Pending invitations
    • Authentication methods
    • Last login information
    • Former employees
    • Former agencies
    • Shared or generic email addresses

    Manager administrators can invite and remove users, change access levels and manage links, but authority over a client account also depends on whether that manager is the client’s administrative owner. A manager Admin without ownership has limited client-administration powers.

  4. Step 5. Contain the client accounts where legitimate access remains

    • Pause unauthorized campaigns
    • Notify the affected client administrators
    • Ask clients to secure their own Google Accounts
    • Record unauthorized users and manager links
    • Review each client’s billing
    • Confirm which legitimate campaigns are still running

    Keep a separate record per client: Customer ID, unauthorized activity, amount affected, first suspicious time, containment time and current access status. One client incident is not the whole manager incident, and the reverse is also true.

  5. Step 6. Review accounts created during the compromise window

    • Accounts the legitimate team did not create
    • Accounts using unfamiliar billing
    • Accounts with unusually high budgets
    • Accounts targeting unrelated businesses
    • Accounts linked to unknown websites

    Google’s current process says that, where it confirms a compromise, it may unlink unauthorized Manager Accounts and set spending limits to zero on unauthorized new sub-accounts. That is a description of what Google may do, not a guarantee that it has happened.

  6. Step 7. Review the payments relationships with care

    • Linked payments profiles
    • Who holds link-management permission
    • Billing transfers
    • Consolidated billing
    • Payments profile ownership
    • Invoicing relationships
    • Pending linking requests

    Google describes manager-to-payments-profile linking as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for every dependent Ads account and stop them serving until new setups are created, so do not unlink as a containment reflex.

  7. Step 8. If Google needs to act, report the full manager-level scope

    If you need Google to recover access, review unauthorized spend, or investigate the hierarchy, include the shared manager incident and every affected account in one case.

    • Manager Customer ID
    • The highest affected Manager Account
    • Every affected client Customer ID
    • Unknown Manager Account IDs
    • Unknown users
    • Unauthorized campaigns
    • Accounts where access was removed or downgraded
    • Billing impact per account
    • One timeline across the whole hierarchy

    Submitting unrelated explanations account by account, without naming the shared manager incident, makes the pattern harder for Google to see.

The hierarchy is mapped. Check unknown accounts and charges next.

Path 4

Unknown Google Ads account or unauthorized charges

An invoice, a card charge or an Ads account you never knowingly created.
  1. Step 1. Do not assume the charge identifies the cause

    Investigate the Google Account and the payment method together, because the charge is a symptom of several possible causes.

    • A compromised Google Account
    • A new Ads account created under an existing identity
    • An existing Ads account nobody remembers
    • A compromised payment card
    • An unauthorized user or Manager Account
    • A payment method reused in another account
  2. Step 2. Gather the charge details before you contact anyone

    • Amount and currency
    • Date
    • Card or bank account used
    • Transaction reference
    • Billing descriptor
    • Invoice number
    • Customer ID, if it is shown
    • The email address that received the notification
    • Screenshots of the charge
    • Any Google Ads billing email
  3. Step 3. Sign in with the notified email and review every account it reaches

    Record any account that was not created by you, has an unfamiliar Customer ID, contains unknown campaigns, uses an unfamiliar website, carries billing activity, or was created around the suspicious date.

  4. Step 4. Secure the Google Account even if you believe only the card was used

    Complete the Google Account recovery and security steps. A card is one route in; the identity that can create an Ads account is another.

    • Password
    • Signed-in devices
    • Recent security events
    • Recovery methods
    • Two-step verification
    • Applications with account access
  5. Step 5. Use the Google route that matches what you are looking at

    • A known Ads account that was compromised: finish Google’s compromise process
    • A charge you cannot identify at all: use the unidentified-charge troubleshooter
    • An Ads account you do not recognise on the statement: read Google’s unrecognised-charge guidance first

    The troubleshooter’s questions and any temporary notices inside it change, so read what it shows you today rather than a summary written months ago.

  6. Step 6. Talk to the card issuer, knowing what a dispute does

    Google describes contacting the issuer as an often-recommended first step for a charge from an account you do not recognise, alongside cancelling or replacing the compromised card. A Google investigation and a bank dispute are separate processes with different evidence.

    The financial institution makes the chargeback decision. A chargeback raised against a legitimate Ads balance can suspend the Ads account or leave an overdue balance if Google contests it, so establish which situation you are in before disputing.

The charge route is chosen. Check whether the account was suspended.

Path 5

Google Ads account suspended after unauthorized activity

Enforcement and compromise are two different findings, and the order of work matters.
  1. Step 1. Identify which kind of suspension you are looking at

    Google may temporarily suspend an account while it secures it after suspected unauthorized activity. Unauthorized campaigns, destinations, ads or keywords can separately trigger a policy suspension. These are different findings with different routes.

    Unauthorized activity is not proof that it caused the suspension. Read the notice inside your own account rather than assuming which one applies.

  2. Step 2. Complete compromise recovery before deciding whether to appeal

    • Secure the Google Account
    • Remove unauthorized access
    • Review Manager Account links
    • Complete Google’s compromise process
    • Review the account activity change log
    • Remove or remediate unauthorized campaigns and destinations
    • Confirm billing and advertiser verification

    An appeal, if needed, is not a containment step. Appealing while an unauthorized user still holds access leaves them there.

  3. Step 3. Record exactly what the suspension notice says

    • The policy named
    • The date issued
    • The account affected
    • Campaigns or destinations involved
    • Whether the account is read-only
    • Whether an appeal option is offered
    • Whether additional verification is required
  4. Step 4. Remove or pause the unauthorized policy-violating content

    • Unauthorized ads
    • Unknown final URLs
    • Cloaked or redirected destinations
    • Policy-violating keywords
    • Unfamiliar campaigns
    • Unknown business identities
    • Unauthorized payment methods
    • Misleading assets
    • Incorrect advertiser verification details
  5. Step 5. If you need Google to review the suspension, submit one appeal

    Use the appeal route only when the suspension notice offers it and you need Google to review the enforcement decision. Explain both the compromise and the remediation.

    • That the account experienced unauthorized access
    • When the compromise began
    • Which activity was unauthorized
    • Which security issues were fixed
    • Which users and managers were removed
    • Which campaigns and destinations were removed
    • Which verification details were corrected
    • Which supporting evidence is available

    An appeal is not guaranteed to restore an account. Google may require advertiser or payment-method verification first, certain selected advertisers must complete advertiser verification before appealing, separate suspended accounts generally need separate appeals, and Google says excessive appeals may not be processed. Do not file competing appeals for the same account.

  6. Step 6. Keep the compromise case and the policy appeal consistent

    The timeline, campaign IDs, affected users and remediation details should match across the compromised-account report, the account activity change log, the policy appeal, any reimbursement request and your own incident record.

The suspension route is clear. Check whether Admin access is still yours.

Path 6

Admin access removed or downgraded

Legitimate administrators were removed, downgraded, or replaced by someone unknown.
  1. Step 1. Ask another legitimate Admin or administrative owner first

    Where one still exists, they can restore access faster than any support route.

    • Current users and access levels
    • Linked Manager Accounts
    • Pending invitations
    • Recent change history
    • Whether the affected user was removed or downgraded
  2. Step 2. Check direct access and manager access separately

    A user can lose direct account access while a legitimate Manager Account still holds it. The reverse also happens: direct Admin access remains while an unauthorized manager controls parts of the account. Inspect both routes.

  3. Step 3. If you need Google to restore access, report the change as a compromise

    If the change was not authorised and you need Google to restore access or investigate it, use the compromised-account process rather than treating it as an ordinary invitation problem.

  4. Step 4. Use Google’s account access request route where it applies

    When the original administrator has left or no active Admin can grant access, Google offers an access-request route and may ask for proof of account ownership before changing permissions.

    Google validates ownership and decides whether permissions change. Submitting documents does not oblige Google to grant access, and this route is not a substitute for reporting the security incident.

  5. Step 5. Gather the ownership evidence before you ask

    • Customer ID
    • Manager Customer ID
    • Historic invoices
    • Billing details
    • Business registration
    • Domain ownership
    • Advertiser verification information
    • Previous Admin email addresses
    • Previous support cases
    • Campaign and payment history
  6. Step 6. Coordinate the correct administrator level for the cleanup

    For a confirmed manager-level compromise, Google may require an administrator at that manager level to review and approve the cleanup. Do not approve a cleanup decision until the full hierarchy and the listed changes have been reviewed.

Access is being restored. Read what happens after you report it.

Google may secure the account before it restores normal access.

If Google confirms unauthorized activity, its current process can change the account before you get it back. Knowing what it may do stops a secured account looking like a second attack.

One administrator, one submission, no undo.

Only one eligible administrator can submit the cleanup decision, and Google states that a submitted decision cannot be changed or reverted. Read the complete change log, and agree the answer with the people who know which campaigns were real, before anyone confirms it.

Did Google send the account activity change log?

This is Google’s post-investigation log, not the change history you can open yourself. What you should do next depends on whether it has arrived.

Account activity change log

All three answers are shown. Choose one to narrow this to your situation.

This answer is not saved, and it does not change which recovery paths are open. All three answers are shown until you pick one.

The log arrived

Read the whole log before anyone answers it. The decision is submitted once, by one eligible administrator, and Google states it cannot be changed afterwards.

  • Confirm the recipient held an Admin role before Google’s confirmed compromise date
  • For a manager-level compromise, confirm they are an Admin at that manager level
  • Update the Google Account password and re-authenticate before acting on the log
  • Read every listed modification, including the ones that look routine
  • Check the log for cleanup actions that failed and still need manual remediation
  • Agree the answer with the people who know which campaigns were legitimate
  • Then have one administrator submit the single decision

Google does not disclose which administrators received the email, so absence of a copy in your own inbox does not mean nobody got one. Ask the other prior Admins before assuming it was not sent.

Nothing has arrived yet

The change history you can open inside Google Ads is not the same artefact. The account activity change log is the post-investigation record Google may email after it secures the account, and it may never be sent.

  • Keep containment and the audit going; none of it depends on the log
  • Keep the compromised-account case open and answer anything Google asks
  • Monitor the inboxes of every administrator who held Admin before the compromise
  • Check spam, filters, forwarding rules and shared mailboxes, which a compromise often touches
  • Keep using change history as your own evidence source in the meantime

Google publishes no general timing for this, so do not plan around a date. Nothing on this page can tell you when or whether a log will arrive.

You are not sure

Work out who would have been eligible to receive it, then check with them directly rather than waiting.

  • List everyone who held an Admin role before the suspected compromise date
  • Identify the level Google would treat as affected: the individual account or a manager level
  • For a manager-level incident, ask the administrators at that manager level
  • Exclude the originally compromised user, who is not notified in the documented workflows
  • Check each eligible administrator’s inbox, spam folder and any shared mailbox
  • Ask through the open support case whether a log was issued

Establishing who is eligible is worth doing now. If a log does arrive, only one of those people can answer it, and only once.

Need Google to act? Prepare one short case.

Only create a Google case when you need help recovering access, a platform-side cleanup or appeal, or a review of unauthorized spend or reimbursement. If none applies, skip this section.

Which Google routes you are offered depends on whether you can still sign in, your access level, whether the account is personal or a Google Workspace account, your region, your payment setting and your eligibility. Work through the routes below in order rather than expecting a particular form or reply to appear.

Do not publish Customer IDs, invoices, case numbers or security screenshots in a public forum or social post while an incident is open. Send them only through Google’s own signed-in routes.

Include only the essentials

  • Google Ads Customer ID
  • Manager Customer ID
  • The compromised Google Account email
  • Unknown users, managers and affected campaign IDs
  • The first suspicious event and containment time
  • The unauthorized amount and the currency
  • Screenshots
  • Actions already taken

What you need the platform to do

  • What account or hierarchy was compromised
  • What activity or spend was unauthorized
  • When it started and what you already did
  • What recovery, cleanup, appeal or reimbursement you need

If Google determines that the account was compromised and unauthorized charges were billed, you may be eligible for reimbursement. Google’s current process requires recovery to be complete, the Ads account reactivated and two-step verification enabled before the request is submitted through Google Ads support. Google currently says billing investigations can take 10 to 15 business days, approved credits can appear as a Service Adjustment, and final adjustments may not be confirmed until the billing cycle ends.

Completing recovery, submitting evidence or finishing a cleanup does not guarantee reimbursement, a cash refund, a particular amount, or a decision within 10 to 15 business days. Eligibility and the outcome are decided by Google. A bank dispute is a separate process from Google’s investigation. The financial institution decides it, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance if Google contests it. Nothing on this page is legal or financial advice.

Before you consider the incident closed

Your own record of what you have done. Ticking a step records your note to yourself; it is not confirmation from Google that the step was accepted or that the incident is closed.

Open the final checklist

Your browser’s print dialog can also save it as a PDF.

0 of 32 steps recorded.

Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.

Questions people ask mid-incident

What should I do first if my Google Ads account is hacked?

Contain unauthorized advertising where you still can, secure the affected Google Account, and preserve the account and change-history details. Use Google’s compromised-account process only if you need access recovery, a platform-side action, an appeal, or review of unauthorized spend. If someone else may still be signed in, change the Google Account password immediately from a device you trust.

What is the difference between a Google Account and a Google Ads account?

The Google Account is the sign-in identity. The Google Ads account is the advertising account holding campaigns, settings and billing, identified by a 10-digit Customer ID. One Google Account can reach several Ads accounts.

What is a Google Ads Manager Account?

A Manager Account, previously called an MCC, is a higher-level account used to manage multiple client accounts and other Manager Accounts. A compromise at this level may affect several accounts at once, and authority over each client depends on the manager-level role and on administrative ownership.

Should I delete unauthorized campaigns?

Pause them first where you can. Record their IDs, settings, timestamps, destinations and spend before deleting anything. Do not delay urgent containment solely to preserve evidence.

What is Google’s account activity change log?

It is the log Google may email to eligible prior administrators after it confirms and secures a compromised account, showing what changed during the security event. It is not the change history you can open yourself. One eligible administrator may then submit a cleanup decision, and Google states that decision cannot be changed afterwards.

What if I was removed as an Admin?

Ask another legitimate Admin or administrative owner to restore access where possible. If no active administrator can help, use Google’s account access request route and report the compromise as well. Google validates ownership and decides whether permissions change.

Can Google reimburse unauthorized ad spend?

Google may approve reimbursement if it determines the account was compromised and unauthorized charges were billed. Recovery must be complete, the account reactivated and two-step verification enabled before the request. Google currently says billing investigations can take 10 to 15 business days, and approved credits can appear as a Service Adjustment. Approval, the amount and the timing are not guaranteed.

What if the account was suspended because of the attacker’s campaigns?

Complete the compromise recovery first, then remove or remediate the unauthorized policy-violating activity and read the notice for that suspension. If it offers an appeal and you need Google to review the decision, submit one through that route. Unauthorized activity is not proof that it caused the suspension, and an appeal is not guaranteed to restore the account.

Should I raise a chargeback with my bank?

It depends on what you are looking at. For a charge from an Ads account you do not recognise, Google describes contacting the card issuer as an often-recommended first step. For a charge against a legitimate Ads balance, a chargeback can suspend the account or leave an overdue balance if Google contests it. The issuer makes the final decision.

Can AdFence recover my Google Account or Ads account?

No. Google Account and Google Ads access restoration remain with Google. AdFence can monitor and document the Google Ads signals the integration supports after an account is connected.

Can I connect AdFence after the incident?

Yes, once legitimate access has been restored. Monitoring begins at connection and cannot recreate a history of what happened before it.

Does AdFence replace the Google Ads Security Agent?

No. Google’s native security features should stay enabled. AdFence is an additional monitoring layer across the supported advertising signals of several platforms, and what it can see differs by platform.

After recovery

Make the next incident easier to catch.

Monitoring is read-only by default and starts after connection. Coverage varies by platform, integration, permissions, configuration and plan. Where a response action is supported, it requires separate setup: an authorized user confirms manual actions, and automatic execution applies only to actions explicitly configured and pre-approved.