Skip to main content

Use case: Ad account security

Spot the warning signs of an ad account takeover.

An unfamiliar administrator appears, or an unplanned campaign starts spending. AdFence records changes in connected ad accounts, with previous and current values, so your team can check what happened.

Any of these can be legitimate. Each recorded change is a warning, not proof of a hack, and the decision stays with your team.

Access event

02:14
Administrator added
[email protected]
Team confirms
No one sent the invite

Followed, 41 minutes later, by

Campaign change

02:55
Destination domain
store.example.comchanged to deals-example.xyz
Daily budget
$200changed to $2,000

Sample. Names, times, and figures are invented.

Example

One takeover, four connected changes.

A compromised login can expose business assets and allow unauthorized campaign changes. This sample links an access change to new spending and a changed destination.

Sample scenario. Names and figures are invented.

  1. Access point

    An unfamiliar administrator appears

    Personal profile, user, partner, or app access can expose the account.

    • Business users

      4changed to 5

    • New user

      New[email protected]

      Administrator; the team confirms nobody sent the invite.

  2. Business assets

    Shared assets become accessible

    Partner permissions widen and an unfamiliar app reaches the pixel and pages.

    • Partner access

      Viewchanged to Manage

    • Connected app

      NewUnfamiliar app

  3. Campaign changes

    A campaign nobody planned starts spending

    The attacker changes campaigns, budgets, countries, and destinations.

    • New campaign

      NewFlash Sale 24h

    • Daily budget

      $200changed to $2,000

    • Countries

      USchanged to US, BR, PH

    • Destination domain

      store.example.comchanged to deals-example.xyz

  4. Consequences

    The money and the account are both at stake

    Spend runs against the new settings, and the ads can put the account under platform review.

    • Recorded spend since the first change

      New$1,840

    • Account standing

      Activechanged to At risk of review

Access can come through a personal profile, a user, a partner, or a connected app. AdFence sees the account changes that follow, not the login that caused them.

AdFence does not detect malware, stolen passwords, or hijacked sessions. It records what changed in the connected account, and when, so your team can decide whether the change was authorized.

Impact

Which changes deserve a closer look?

One change may be routine. Access, budget, and destination changes recorded close together deserve a closer look.

  • People and access

    Someone gained or lost account access.

    • Administrator added or promoted
    • Partner added or permissions expanded
    • Unfamiliar app connected
    • Expected administrator removed
  • Campaigns and budgets

    Campaign activity or spending changed.

    • Campaign launched that nobody planned
    • Paused campaign resumed
    • Budget moved outside the usual range
    • Spend running against the new settings
  • Where the ads go

    The audience or destination changed.

    • New countries targeted
    • New destination domain
    • Tracking or pixel configuration changed
    • Ads that can breach platform policy

Review and response

What AdFence shows and what you decide.

AdFence shows the changes to investigate. Your team decides how to respond.

What AdFence shows

  • The account, asset, and change involved
  • Previous and current values where the platform exposes them
  • Related changes recorded in the same window
  • An alert to the channels your team chose

What stays with your team

  • Whether the change was authorized
  • Who to contact, and which access to revoke
  • Whether to pause covered campaigns, by manual confirmation or through an automation your team explicitly configured and pre-approved
  • Platform recovery stays with Meta, Google, or TikTok

How AdFence behaves

  • Product availability checks start after connection. Other supported checks start after connection and run every 15 minutes.
  • Read-only by default. Monitoring never edits an ad account on its own.
  • Coverage varies by platform, permissions, integrations, configuration, and plan.
  • Product availability is alert only. Other automatic actions run only when they are explicitly configured and pre-approved.
  • No guarantee of prevention, recovery, refund, or reinstatement.

Keep the record

Keep the record while the incident is fresh.

AdFence keeps a timeline with previous and current values and related spend. An Evidence Pack brings those records together.

How to use the record

  • Platform support enquiries
  • Payment disputes
  • Client updates
  • Internal reviews

The record covers activity recorded after the account was connected. An Evidence Pack documents the incident. It does not guarantee a refund or a favorable decision from a platform, bank, or payment provider.

Incident timeline

Sample scenario. Names and figures are invented.

  1. 02:14Administrator added[email protected]
  2. 02:21Partner access expandedView to Manage
  3. 02:40Campaign launchedFlash Sale 24h
  4. 02:41Daily budget changed$200 to $2,000
  5. 02:55Countries changedUS to US, BR, PH
  6. 03:00Alert sentEmail, Slack

If it is happening right now

Already compromised? Start with the guide for your platform.

These guides link to each platform’s recovery process. You do not need AdFence to follow them.

Questions, answered

What teams ask before connecting.

Can AdFence prevent every ad account takeover?

No. AdFence alerts your team to supported changes in connected accounts. Monitoring cannot guarantee that an account will never be compromised.

Does AdFence detect malware, stolen passwords, or hijacked sessions?

No. Those live on devices and platform logins that AdFence never sees. It records the account changes that can follow them, such as a new administrator, a widened partner permission, or a campaign nobody planned.

Is a new administrator proof that the account was hacked?

No. It is a warning. Teams add people all the time. The record shows who was added and when, so someone who knows the account can confirm whether it was expected.

Will AdFence pause campaigns when it sees these changes?

Not on its own. Monitoring is read-only by default. Pausing covered campaigns requires separate setup and either an authorized user’s confirmation or an automation your team explicitly configured and pre-approved.

Can AdFence recover a compromised account?

No. Recovery and reinstatement decisions stay with Meta, Google, or TikTok. The emergency guides on this site walk through each platform's own recovery routes.

Start protecting

Know what changed in your ad accounts, and when.

  • 7-day free trial
  • Read-only by default
  • Cancel anytime