Google Ads: incident recovery checklist
Printed from https://adfence.io/under-attack/google-ads
Guidance last reviewed 5 September 2026
AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google.
Under attack · Google ads
Google Ads account hacked? Start here.
Choose what was affected and follow the relevant steps to contain unauthorized activity, recover access, review the changes made to your account, and secure your advertising setup.
Before you go further
- AdFence is an independent advertising-security platform. It is not Google, is not affiliated with or endorsed by Google, and cannot access, restore or recover your account through this guide. Account access, cleanup, suspension, appeal and reimbursement decisions remain with Google.
- This guide cannot promise account recovery, the identification of whoever did this, the reversal of a suspension, a credit, or a refund. It sets out the order to work in and what to record.
- Never type a password, two-step verification code, recovery code, passkey, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.
Last reviewed . Official Google destinations and menu names on this page are reviewed every quarter.
Do these first, whichever Google Ads setup you use.
These three apply before the account-specific recovery paths below.
01
Contain unauthorized advertising activity
If legitimate access remains, pause what you cannot verify. Record IDs and timestamps as you go, but do not delay containment to collect perfect evidence. If you have lost access, do not spend time trying to force a pause. Ask a trusted administrator who still has access to contain the activity, then go to the recovery path that matches your situation.
- Unfamiliar campaigns
- Campaigns pointing at unknown destinations
- Other accounts under the same login that are spending
- Daily and shared budgets
- Automated rules
- Scripts and other automation
- Campaign and account IDs, recorded before anything is removed
02
Secure the Google Account and the device
A Google Ads login is a Google Account login. If someone else may still be signed in, change the password now, preferably from a device you trust, and then remove harmful software and unfamiliar extensions.
- Google Account password
- Recovery email address
- Recovery phone number
- Signed-in devices
- Recent security events
- Two-step verification
- Passkeys
- Third-party account connections
03
Preserve the essential evidence
Use Google Ads change history while you still have access. It is one evidence source, not a complete forensic record: it currently covers up to two years, includes changes made by rules, the API and Google Ads Editor, and not everything it lists can be undone.
- Who or what Google attributes each change to
- When each change was made
- Campaigns affected
- Budget and bidding changes
- Ads and assets created
- Targeting changes
- Conversion changes
- Unknown managers and users
- Billing changes
- Relevant emails from Google
- Support case numbers
Which part of your Google Ads setup was compromised?
Select one or more. A compromised Google Account can reach an individual Ads account, a Manager Account, several client accounts and a payments profile at the same time, so the paths below open in the order they should be worked through.
No recovery paths selected yet.
Your selection is saved only in this browser, on this device. It is never sent to AdFence.
Recovery paths
Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.
Not sure yet is a valid answer. Every recovery path can be opened below, and the final checklist covers the whole setup.
Path 1Google Account login compromised
The sign-in identity behind Google Ads, Gmail and every other connected Google product.
Step 1. If someone else may still be signed in, change the password now
Google’s guidance is to change the password immediately when another person may still have access, preferably from a device you trust. Removing harmful software matters too, but it is not a reason to leave a live session open while you scan.
If the device you normally use may be infected, change the password from a different trusted device, then clean the original before signing in from it again.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Google’s step-by-step guidance once you are back in: password, recovery details, security events, devices, and the harmful software and browser extensions that may have taken the password in the first place.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Step 2. If you cannot sign in at all, use Google Account recovery
Google’s recovery flow is the route when someone else may be using the account or the legitimate owner can no longer sign in. Answer from a device and a location you have used before where possible.
Google states that it does not work with account or password recovery services, and that sign-in recovery cannot be completed by calling Google. Anyone offering paid recovery or an internal Google contact is a second attack, not a solution.
- Google Account recovery (opens in a new tab)
Google’s own recovery flow for a Google Account you can no longer sign in to. Answer from a device and location you have used before where possible, because Google weighs that when deciding.
- Google Account Help: account recovery scams (opens in a new tab)
Google states that it does not work with account or password recovery services and that sign-in recovery cannot be completed by calling Google. Treat anyone offering paid recovery, an internal contact or a phone number as a second attack.
- Google Ads Help: avoid scams and impersonation (opens in a new tab)
How Google describes people impersonating Google Ads support. Useful while an incident is live, because a compromise is often followed by someone offering to fix it.
- Google Account recovery (opens in a new tab)
Step 3. Work out whether this is a personal account or a Google Workspace account
The two have different recovery routes, and using the consumer flow on a work account wastes the hours that matter.
- Personal Google Account: use Google’s standard recovery and hacked-account guidance
- Google Workspace user: contact your organisation’s Workspace administrator immediately
- Sole or unreachable Super Admin: use Google’s administrator recovery route instead
- Reseller customer: your reseller may need to act
Workspace self-recovery depends on the configured recovery details and the organisation’s policy, and support-assisted recovery may require domain verification. It is not offered in every case.
- Google Workspace Admin Help: recover an administrator account (opens in a new tab)
For a work or school account. Another Super Admin can restore access where one exists; self-recovery depends on the configured recovery details and organisation policy.
- Google Workspace: administrator recovery request (opens in a new tab)
The support-assisted route for a sole or unreachable Workspace administrator. It may require domain verification, reseller customers may need their reseller, and this option is not offered in every case.
Step 4. Clean every device used to reach Google Ads
- Browser extensions
- Recently downloaded software
- Remote-access tools
- Unfamiliar applications
- Malware and antivirus results
- Browser profiles
- Stored passwords
A device that is still compromised can capture the new password as soon as you set it, so clean it before you sign in from it again.
Step 5. Run Security Checkup and reset the recovery details
- Recent security events
- Signed-in devices
- Recovery phone number
- Recovery email address
- Two-step verification
- Passkeys
- Additional protections
Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor. Plan for that rather than assuming an instant reset.
- Google Security Checkup (opens in a new tab)
Recent security events, signed-in devices, recovery phone and email, two-step verification and third-party access, in one signed-in review.
- Google Ads Help: two-step verification for Google Ads (opens in a new tab)
How two-step verification applies to Google Ads sign-in. Changes to recovery information can take up to seven days to take effect, and contacting support may still require access to the configured second factor.
Step 6. Review the applications and services with account access
Remove anything unfamiliar, anything no longer needed, anything added around the time of the compromise, and anything holding more access than it requires.
- Google Account Help: apps and services with account access (opens in a new tab)
Where to review Sign in with Google connections and third-party applications holding access to Google Account data, and how to remove them.
- Google Account Help: apps and services with account access (opens in a new tab)
Step 7. Continue to the Google Ads audit
Securing the Google Account does not establish that the advertising setup is clean. An unauthorized user, Manager Account link, script or API integration can still hold access after the password changes.
Path 2Individual Google Ads account compromised
You can still sign in, but the Ads account holds activity you did not create.
Step 1. Use Google’s report if you need Google to act
If you need Google to secure or restore access, review unauthorized activity, or take another platform-side action, submit its compromised-account report with the Customer ID and timeline.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads: report a compromised account (opens in a new tab)
Step 2. Review change history across the suspected period
Set the date range to cover the whole suspected window, and record who or what Google attributes each change to.
- User additions
- Campaign creation
- Budget and shared-budget changes
- Bid changes
- Ad and asset creation
- Final URL changes
- Audience and location changes
- Conversion changes
- Automated activity
- Campaign pauses and activations
Change history currently covers up to two years and can include changes made through automated rules, the Google Ads API and Google Ads Editor. Some entries can be undone and some cannot, so treat it as one evidence source rather than the whole record.
- Google Ads Help: account history and change history (opens in a new tab)
Google’s article on reviewing account history. Change history currently covers up to two years and can include changes made directly, by automated rules, through the Google Ads API and through Google Ads Editor. Some changes can be undone and some cannot, so treat it as one evidence source rather than a complete forensic record.
Step 3. Review every user in Access and security
- Admin users
- Standard users
- Read-only users
- Billing users
- Email-only users
- Pending invitations
- Authentication method
- Last login information, where it is shown
Admin access can manage users, manager links, product links, and the authentication-method and last-login information. Billing and Standard roles are narrower but still material. Record identifying details before removing anyone, where that is practical.
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
- Google Ads Help: account access levels (opens in a new tab)
What Admin, Standard, Read-only, Billing and Email-only access each allow, including who can see authentication method and last-login information.
Step 4. Review every linked Manager Account separately
Removing one unknown user does not remove access held through a Manager Account. These are two different routes in.
- Manager Account name
- Manager Customer ID
- Administrative ownership status
- When and why the relationship exists
- Whether the agency or partner is still legitimate
- Any pending link request
A linked manager is not automatically an administrative owner. Unlinking an unauthorized manager requires the permission your own role actually carries, so check what you hold before assuming you can.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
Step 5. Audit every campaign, including paused and removed ones
- Search, Shopping and Display campaigns
- Performance Max and Demand Gen
- Video and App campaigns
- Shared budgets and experiments
- Daily budgets and bid strategies
- Locations, languages and audiences
- Keywords and search themes
- Ads, assets and account-level assets
- Final URLs and tracking templates
- Schedules, devices and conversion goals
- Product feeds
Pause what you cannot verify rather than deleting it first. Record IDs, settings, destinations and spend before removing anything, where containment allows.
Step 6. Review the automation, not only the people
An unauthorized change may have been made by a person, a Manager Account, a script, a rule, an application or an API integration.
- Automated rules
- Scripts
- Auto-applied recommendations
- Google Ads Editor activity
- API-based tools
- Third-party campaign platforms
- Feed-management tools
- Call-tracking integrations
Step 7. Review conversions and tracking
A compromised account can be pointed at a different event while the visible campaign still looks normal.
- Conversion actions and goals
- The Google tag
- Imported Analytics conversions
- Enhanced conversions
- Offline conversion imports
- Call conversions
- Attribution settings
- Conversion values
- Primary and secondary status
Step 8. Review the account billing and the payments profile separately
- Payment methods
- Payments profile
- Payments profile users
- Billing contacts
- Billing country and tax information
- Invoices and transactions
- Account balance
- Monthly invoicing and billing transfers
- Unknown payment methods
A payments profile may be shared across several Ads accounts and other Google products, so a profile-level change can reach further than this account. Google Ads Admin and Billing users can edit specified profile and payment details, but Google Ads users cannot add or remove payments profile users directly.
- Google Ads Help: payments profiles (opens in a new tab)
What a payments profile holds and how one profile can serve several Ads accounts and other Google products, so a profile-level change can reach further than the account you are looking at.
- Google payments centre: payments profile users (opens in a new tab)
Who can be a payments profile user and how those permissions change. Google Ads users cannot add or remove payments profile users directly; that requires the appropriate payments contact or a same-domain user contacting support.
Step 9. Review advertiser verification and certification status
- Advertiser name and business details
- Verification status
- Identity documentation
- Business operations verification
- Unexpected certification requirements
- New regulated-category status
Campaigns created by an unauthorized user can change verification details or trigger certification requirements you never asked for.
Step 10. Review the connected products
If a connected product was separately compromised, use that product’s own recovery process rather than trying to fix it from Google Ads.
- Google Analytics
- Merchant Center
- YouTube
- Business Profile
- Search Console
- Firebase and app platforms
- Customer Match sources
- Third-party products
- Merchant Center Help: compromised account (opens in a new tab)
Merchant Center is a separate security domain with its own process. If the Merchant Center account itself was taken over, use this rather than treating it as a Google Ads issue.
This account is contained. Check the Manager Account level next.
Path 3Google Ads Manager Account compromised
The hierarchy layer above the accounts, where one compromise can reach many clients.
Step 1. Identify the highest affected manager level
Work out whether the compromise reached one client account, the direct Manager Account, a parent manager, a sub-manager, or several levels at once.
This matters because Google’s cleanup approval is level-sensitive: for a manager-level compromise, approval is limited to eligible administrators at that manager level.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads Help: compromised account guidance (opens in a new tab)
Step 2. Record the whole hierarchy, not only the accounts that alerted
- Manager Account name and Customer ID
- Parent Manager Account
- Sub-managers
- Linked client accounts
- Administrative ownership status
- Legitimate administrators
- Unknown administrators
- Accounts showing unauthorized activity
Step 3. Review every user with access to the Manager Account
- Admin
- Standard
- Read-only
- Email-only
- Pending invitations
- Authentication methods
- Last login information
- Former employees
- Former agencies
- Shared or generic email addresses
Manager administrators can invite and remove users, change access levels and manage links, but authority over a client account also depends on whether that manager is the client’s administrative owner. A manager Admin without ownership has limited client-administration powers.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
Step 4. Review manager and sub-manager links in both directions
- Parent Manager Account
- Sub-manager accounts
- External managers
- Newly linked accounts
- Pending link requests
- Accounts unexpectedly removed
- Ownership changes
An individual Ads account can be managed through several manager relationships at once, so reviewing direct users alone is not enough.
Step 5. Contain the client accounts where legitimate access remains
- Pause unauthorized campaigns
- Notify the affected client administrators
- Ask clients to secure their own Google Accounts
- Record unauthorized users and manager links
- Review each client’s billing
- Confirm which legitimate campaigns are still running
Keep a separate record per client: Customer ID, unauthorized activity, amount affected, first suspicious time, containment time and current access status. One client incident is not the whole manager incident, and the reverse is also true.
Step 6. Review accounts created during the compromise window
- Accounts the legitimate team did not create
- Accounts using unfamiliar billing
- Accounts with unusually high budgets
- Accounts targeting unrelated businesses
- Accounts linked to unknown websites
Google’s current process says that, where it confirms a compromise, it may unlink unauthorized Manager Accounts and set spending limits to zero on unauthorized new sub-accounts. That is a description of what Google may do, not a guarantee that it has happened.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
Step 7. Review the payments relationships with care
- Linked payments profiles
- Who holds link-management permission
- Billing transfers
- Consolidated billing
- Payments profile ownership
- Invoicing relationships
- Pending linking requests
Google describes manager-to-payments-profile linking as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for every dependent Ads account and stop them serving until new setups are created, so do not unlink as a containment reflex.
- Google Ads Help: link a Manager Account to a payments profile (opens in a new tab)
Google describes this as a gradual rollout for eligible automatic or manual payment accounts, requiring Admin access to both. Unlinking can deactivate billing setups for dependent Ads accounts and stop them serving until new setups are created.
- Google Ads Help: payments profiles (opens in a new tab)
What a payments profile holds and how one profile can serve several Ads accounts and other Google products, so a profile-level change can reach further than the account you are looking at.
Step 8. If Google needs to act, report the full manager-level scope
If you need Google to recover access, review unauthorized spend, or investigate the hierarchy, include the shared manager incident and every affected account in one case.
- Manager Customer ID
- The highest affected Manager Account
- Every affected client Customer ID
- Unknown Manager Account IDs
- Unknown users
- Unauthorized campaigns
- Accounts where access was removed or downgraded
- Billing impact per account
- One timeline across the whole hierarchy
Submitting unrelated explanations account by account, without naming the shared manager incident, makes the pattern harder for Google to see.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
The hierarchy is mapped. Check unknown accounts and charges next.
Path 4Unknown Google Ads account or unauthorized charges
An invoice, a card charge or an Ads account you never knowingly created.
Step 1. Do not assume the charge identifies the cause
Investigate the Google Account and the payment method together, because the charge is a symptom of several possible causes.
- A compromised Google Account
- A new Ads account created under an existing identity
- An existing Ads account nobody remembers
- A compromised payment card
- An unauthorized user or Manager Account
- A payment method reused in another account
Step 2. Gather the charge details before you contact anyone
- Amount and currency
- Date
- Card or bank account used
- Transaction reference
- Billing descriptor
- Invoice number
- Customer ID, if it is shown
- The email address that received the notification
- Screenshots of the charge
- Any Google Ads billing email
Step 3. Sign in with the notified email and review every account it reaches
Record any account that was not created by you, has an unfamiliar Customer ID, contains unknown campaigns, uses an unfamiliar website, carries billing activity, or was created around the suspicious date.
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
- Google Ads Help: manage account access (opens in a new tab)
Step 4. Secure the Google Account even if you believe only the card was used
Complete the Google Account recovery and security steps. A card is one route in; the identity that can create an Ads account is another.
- Password
- Signed-in devices
- Recent security events
- Recovery methods
- Two-step verification
- Applications with account access
- Google Security Checkup (opens in a new tab)
Recent security events, signed-in devices, recovery phone and email, two-step verification and third-party access, in one signed-in review.
- Google Account Help: secure a hacked or compromised account (opens in a new tab)
Google’s step-by-step guidance once you are back in: password, recovery details, security events, devices, and the harmful software and browser extensions that may have taken the password in the first place.
Step 5. Use the Google route that matches what you are looking at
- A known Ads account that was compromised: finish Google’s compromise process
- A charge you cannot identify at all: use the unidentified-charge troubleshooter
- An Ads account you do not recognise on the statement: read Google’s unrecognised-charge guidance first
The troubleshooter’s questions and any temporary notices inside it change, so read what it shows you today rather than a summary written months ago.
- Google Ads Help: troubleshoot an unidentified charge (opens in a new tab)
Google’s current destination for a Google Ads charge you cannot identify. The questions and any temporary notices inside it change, so read what it shows you today rather than a summary of it.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
Google describes contacting the card issuer as an often-recommended first step here, alongside cancelling or replacing the compromised card. The issuer makes the chargeback decision, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
Step 6. Talk to the card issuer, knowing what a dispute does
Google describes contacting the issuer as an often-recommended first step for a charge from an account you do not recognise, alongside cancelling or replacing the compromised card. A Google investigation and a bank dispute are separate processes with different evidence.
The financial institution makes the chargeback decision. A chargeback raised against a legitimate Ads balance can suspend the Ads account or leave an overdue balance if Google contests it, so establish which situation you are in before disputing.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
Google describes contacting the card issuer as an often-recommended first step here, alongside cancelling or replacing the compromised card. The issuer makes the chargeback decision, and a chargeback raised against a legitimate Ads balance can suspend the account or leave an overdue balance.
- Google Ads Help: a charge from an account you do not recognise (opens in a new tab)
The charge route is chosen. Check whether the account was suspended.
Path 5Google Ads account suspended after unauthorized activity
Enforcement and compromise are two different findings, and the order of work matters.
Step 1. Identify which kind of suspension you are looking at
Google may temporarily suspend an account while it secures it after suspected unauthorized activity. Unauthorized campaigns, destinations, ads or keywords can separately trigger a policy suspension. These are different findings with different routes.
Unauthorized activity is not proof that it caused the suspension. Read the notice inside your own account rather than assuming which one applies.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
What each suspension type means and which appeal route applies. Google may require advertiser or payment verification first, generally expects separate appeals for separate suspended accounts, and says excessive appeals may not be processed.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
Step 2. Complete compromise recovery before deciding whether to appeal
- Secure the Google Account
- Remove unauthorized access
- Review Manager Account links
- Complete Google’s compromise process
- Review the account activity change log
- Remove or remediate unauthorized campaigns and destinations
- Confirm billing and advertiser verification
An appeal, if needed, is not a containment step. Appealing while an unauthorized user still holds access leaves them there.
Step 3. Record exactly what the suspension notice says
- The policy named
- The date issued
- The account affected
- Campaigns or destinations involved
- Whether the account is read-only
- Whether an appeal option is offered
- Whether additional verification is required
Step 4. Remove or pause the unauthorized policy-violating content
- Unauthorized ads
- Unknown final URLs
- Cloaked or redirected destinations
- Policy-violating keywords
- Unfamiliar campaigns
- Unknown business identities
- Unauthorized payment methods
- Misleading assets
- Incorrect advertiser verification details
Step 5. If you need Google to review the suspension, submit one appeal
Use the appeal route only when the suspension notice offers it and you need Google to review the enforcement decision. Explain both the compromise and the remediation.
- That the account experienced unauthorized access
- When the compromise began
- Which activity was unauthorized
- Which security issues were fixed
- Which users and managers were removed
- Which campaigns and destinations were removed
- Which verification details were corrected
- Which supporting evidence is available
An appeal is not guaranteed to restore an account. Google may require advertiser or payment-method verification first, certain selected advertisers must complete advertiser verification before appealing, separate suspended accounts generally need separate appeals, and Google says excessive appeals may not be processed. Do not file competing appeals for the same account.
- Google Ads Help: suspended accounts and appeals (opens in a new tab)
What each suspension type means and which appeal route applies. Google may require advertiser or payment verification first, generally expects separate appeals for separate suspended accounts, and says excessive appeals may not be processed.
Step 6. Keep the compromise case and the policy appeal consistent
The timeline, campaign IDs, affected users and remediation details should match across the compromised-account report, the account activity change log, the policy appeal, any reimbursement request and your own incident record.
The suspension route is clear. Check whether Admin access is still yours.
Path 6Admin access removed or downgraded
Legitimate administrators were removed, downgraded, or replaced by someone unknown.
Step 1. Ask another legitimate Admin or administrative owner first
Where one still exists, they can restore access faster than any support route.
- Current users and access levels
- Linked Manager Accounts
- Pending invitations
- Recent change history
- Whether the affected user was removed or downgraded
- Google Ads Help: manage account access (opens in a new tab)
Where users, invitations and access levels are managed inside an individual Google Ads account, and what each role can do there.
Step 2. Check direct access and manager access separately
A user can lose direct account access while a legitimate Manager Account still holds it. The reverse also happens: direct Admin access remains while an unauthorized manager controls parts of the account. Inspect both routes.
- Google Ads Help: Manager Account access levels (opens in a new tab)
How authority over a client account depends on both the manager-level role and whether that Manager Account is the client’s administrative owner. A linked manager is not automatically an owner.
- Google Ads Help: Manager Account access levels (opens in a new tab)
Step 3. If you need Google to restore access, report the change as a compromise
If the change was not authorised and you need Google to restore access or investigate it, use the compromised-account process rather than treating it as an ordinary invitation problem.
- Google Ads: report a compromised account (opens in a new tab)
Google’s reporting form for a suspected Google Ads compromise. It is login-gated, so you need a working Google Account session to reach it. If you cannot sign in, recover the Google Account first.
- Google Ads: report a compromised account (opens in a new tab)
Step 4. Use Google’s account access request route where it applies
When the original administrator has left or no active Admin can grant access, Google offers an access-request route and may ask for proof of account ownership before changing permissions.
Google validates ownership and decides whether permissions change. Submitting documents does not oblige Google to grant access, and this route is not a substitute for reporting the security incident.
- Google Ads Help: request access to an account (opens in a new tab)
Google’s guidance for regaining access when the original administrator has left or no active Admin can grant it. Google validates ownership and decides whether permissions change.
- Google Ads: account access request (opens in a new tab)
The request route itself. Be ready to prove ownership. Treat it as an access-recovery route, not as a substitute for reporting a security incident.
- Google Ads Help: request access to an account (opens in a new tab)
Step 5. Gather the ownership evidence before you ask
- Customer ID
- Manager Customer ID
- Historic invoices
- Billing details
- Business registration
- Domain ownership
- Advertiser verification information
- Previous Admin email addresses
- Previous support cases
- Campaign and payment history
Step 6. Coordinate the correct administrator level for the cleanup
For a confirmed manager-level compromise, Google may require an administrator at that manager level to review and approve the cleanup. Do not approve a cleanup decision until the full hierarchy and the listed changes have been reviewed.
- Google Ads Help: account activity change logs (opens in a new tab)
The log Google may email to eligible prior administrators after it secures a compromised account, and the cleanup decision attached to it. The log can also list cleanup actions that failed and still need manual remediation.
- Google Ads Help: account activity change logs (opens in a new tab)
Access is being restored. Read what happens after you report it.
Google may secure the account before it restores normal access.
If Google confirms unauthorized activity, its current process can change the account before you get it back. Knowing what it may do stops a secured account looking like a second attack.
One administrator, one submission, no undo.
Only one eligible administrator can submit the cleanup decision, and Google states that a submitted decision cannot be changed or reverted. Read the complete change log, and agree the answer with the people who know which campaigns were real, before anyone confirms it.
- Google Ads Help: account activity change logs (opens in a new tab)
The log Google may email to eligible prior administrators after it secures a compromised account, and the cleanup decision attached to it. The log can also list cleanup actions that failed and still need manual remediation.
- Google Ads Help: compromised account guidance (opens in a new tab)
Google’s maintained article on a compromised Google Ads account: what to report, what Google may do while it secures the account, and what happens afterwards. Read this before submitting anything.
Did Google send the account activity change log?
This is Google’s post-investigation log, not the change history you can open yourself. What you should do next depends on whether it has arrived.
All three answers are shown. Choose one to narrow this to your situation.
This answer is not saved, and it does not change which recovery paths are open. All three answers are shown until you pick one.
The log arrived
Read the whole log before anyone answers it. The decision is submitted once, by one eligible administrator, and Google states it cannot be changed afterwards.
- Confirm the recipient held an Admin role before Google’s confirmed compromise date
- For a manager-level compromise, confirm they are an Admin at that manager level
- Update the Google Account password and re-authenticate before acting on the log
- Read every listed modification, including the ones that look routine
- Check the log for cleanup actions that failed and still need manual remediation
- Agree the answer with the people who know which campaigns were legitimate
- Then have one administrator submit the single decision
Google does not disclose which administrators received the email, so absence of a copy in your own inbox does not mean nobody got one. Ask the other prior Admins before assuming it was not sent.
Nothing has arrived yet
The change history you can open inside Google Ads is not the same artefact. The account activity change log is the post-investigation record Google may email after it secures the account, and it may never be sent.
- Keep containment and the audit going; none of it depends on the log
- Keep the compromised-account case open and answer anything Google asks
- Monitor the inboxes of every administrator who held Admin before the compromise
- Check spam, filters, forwarding rules and shared mailboxes, which a compromise often touches
- Keep using change history as your own evidence source in the meantime
Google publishes no general timing for this, so do not plan around a date. Nothing on this page can tell you when or whether a log will arrive.
You are not sure
Work out who would have been eligible to receive it, then check with them directly rather than waiting.
- List everyone who held an Admin role before the suspected compromise date
- Identify the level Google would treat as affected: the individual account or a manager level
- For a manager-level incident, ask the administrators at that manager level
- Exclude the originally compromised user, who is not notified in the documented workflows
- Check each eligible administrator’s inbox, spam folder and any shared mailbox
- Ask through the open support case whether a log was issued
Establishing who is eligible is worth doing now. If a log does arrive, only one of those people can answer it, and only once.
Before you consider the incident closed
Your own record of what you have done. Ticking a step records your note to yourself; it is not confirmation from Google that the step was accepted or that the incident is closed.
Open the final checklist
Your browser’s print dialog can also save it as a PDF.
0 of 32 steps recorded.
Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.
Notes
Case and reference numbers, Customer IDs, amounts in dispute, who you spoke to, and what you are waiting on.
Questions people ask mid-incident
What should I do first if my Google Ads account is hacked?
Contain unauthorized advertising where you still can, secure the affected Google Account, and preserve the account and change-history details. Use Google’s compromised-account process only if you need access recovery, a platform-side action, an appeal, or review of unauthorized spend. If someone else may still be signed in, change the Google Account password immediately from a device you trust.
What is the difference between a Google Account and a Google Ads account?
The Google Account is the sign-in identity. The Google Ads account is the advertising account holding campaigns, settings and billing, identified by a 10-digit Customer ID. One Google Account can reach several Ads accounts.
What is a Google Ads Manager Account?
A Manager Account, previously called an MCC, is a higher-level account used to manage multiple client accounts and other Manager Accounts. A compromise at this level may affect several accounts at once, and authority over each client depends on the manager-level role and on administrative ownership.
Should I delete unauthorized campaigns?
Pause them first where you can. Record their IDs, settings, timestamps, destinations and spend before deleting anything. Do not delay urgent containment solely to preserve evidence.
What is Google’s account activity change log?
It is the log Google may email to eligible prior administrators after it confirms and secures a compromised account, showing what changed during the security event. It is not the change history you can open yourself. One eligible administrator may then submit a cleanup decision, and Google states that decision cannot be changed afterwards.
What if I was removed as an Admin?
Ask another legitimate Admin or administrative owner to restore access where possible. If no active administrator can help, use Google’s account access request route and report the compromise as well. Google validates ownership and decides whether permissions change.
Can Google reimburse unauthorized ad spend?
Google may approve reimbursement if it determines the account was compromised and unauthorized charges were billed. Recovery must be complete, the account reactivated and two-step verification enabled before the request. Google currently says billing investigations can take 10 to 15 business days, and approved credits can appear as a Service Adjustment. Approval, the amount and the timing are not guaranteed.
What if the account was suspended because of the attacker’s campaigns?
Complete the compromise recovery first, then remove or remediate the unauthorized policy-violating activity and read the notice for that suspension. If it offers an appeal and you need Google to review the decision, submit one through that route. Unauthorized activity is not proof that it caused the suspension, and an appeal is not guaranteed to restore the account.
Should I raise a chargeback with my bank?
It depends on what you are looking at. For a charge from an Ads account you do not recognise, Google describes contacting the card issuer as an often-recommended first step. For a charge against a legitimate Ads balance, a chargeback can suspend the account or leave an overdue balance if Google contests it. The issuer makes the final decision.
Can AdFence recover my Google Account or Ads account?
No. Google Account and Google Ads access restoration remain with Google. AdFence can monitor and document the Google Ads signals the integration supports after an account is connected.
Can I connect AdFence after the incident?
Yes, once legitimate access has been restored. Monitoring begins at connection and cannot recreate a history of what happened before it.
Does AdFence replace the Google Ads Security Agent?
No. Google’s native security features should stay enabled. AdFence is an additional monitoring layer across the supported advertising signals of several platforms, and what it can see differs by platform.
After recovery
Make the next incident easier to catch.
Monitoring is read-only by default and starts after connection. Coverage varies by platform, integration, permissions, configuration and plan. Where a response action is supported, it requires separate setup: an authorized user confirms manual actions, and automatic execution applies only to actions explicitly configured and pre-approved.