TL;DR:
- Attackers are hijacking Google Ads accounts and running up huge spend in hours — sometimes tens of thousands of pounds before anyone notices
- The phishing emails look almost identical to genuine Google Ads notifications
- Two-factor authentication isn’t enough on its own; the attacks now use session token theft to bypass it
- From 15 July 2026, Google requires passkeys for sensitive Google Ads actions — set yours up now
You’d notice if someone broke into your premises and spent thousands of pounds from your till. You might not notice for days if someone broke into your Google Ads account and spent thousands on their own campaign activity. That’s the gap attackers have been exploiting with increasing sophistication throughout 2025 and into 2026.
The core attack is not technically complex, but it’s well-executed and the losses can be serious. Here’s what’s happening and what you can do about it.
How the Attack Works
Most Google Ads account hijackings start with a phishing email. The email looks like a legitimate Google Ads notification — correct branding, familiar layout, the right kind of urgent language about account policy issues, billing problems, or security alerts.
The email contains a link that leads to a fake Google login page. The page is often hosted on a legitimate-looking domain (sometimes even using Google Sites or other trusted infrastructure) and looks essentially identical to the real Google sign-in. You enter your username and password. The attackers capture both and also intercept your 2FA code in real time, using it before it expires.
Once in, they have your session token — the authentication credential your browser uses to stay logged in without re-entering your password. With that token, they don’t need your password or your 2FA codes for future access. They can operate from their own devices while you’re logged in on yours.
What happens next tends to be fast. Attackers typically create new ad campaigns, add new billing methods, or change existing campaigns to redirect traffic. In documented cases, entire account budgets have been drained in hours. Recovery typically involves extended conversations with Google Support, and depending on the circumstances, you may or may not be reimbursed.
If you’re using a Google Ads Manager Account (MCC) — which many small businesses do, especially if they work with an agency — the stakes are higher. Access to an MCC gives an attacker visibility and control across every client account linked to it.
Why 2FA Isn’t Enough on Its Own
This is the part that trips people up. You have two-factor authentication enabled. Surely that’s enough?
The problem is that session token theft sidesteps it entirely. Once the attacker has your session token — which they can steal in real time during the phishing interaction — they’re authenticated. Your 2FA protected the login; it doesn’t protect the ongoing session.
This is why the industry has been shifting toward passkeys, which are device-bound cryptographic credentials that can’t be phished in the same way. Passkeys use a challenge-response mechanism that requires the specific device the passkey is stored on. Even if an attacker can see your screen in real time, they can’t complete the challenge without your physical device.
What Google Is Changing in July 2026
Google has announced that from 15 July 2026, passkeys will be required to complete certain sensitive actions in Google Ads. The specific actions include:
- Adding new users to an account
- Changing billing information
- Updating account links
- Changing user access levels
This is a direct response to the pattern of account hijackings. These are exactly the actions attackers take after gaining access — adding their own billing methods, inviting their own users, removing legitimate users.
If you run Google Ads, you should set up a passkey now rather than waiting for the deadline. The process takes a few minutes and is done through your Google Account security settings. Your phone or computer’s biometric unlock (fingerprint, Face ID) serves as the passkey authenticator.
Practical Steps to Protect Your Account
Beyond the passkey setup, there are a few things worth doing:
Audit who has access to your account. Go into your Google Ads settings and review the users list. Anyone who shouldn’t be there, remove them. This takes two minutes and costs nothing. If you work with an agency, check that access levels are appropriate — most agencies don’t need admin access; manager access is usually sufficient.
Review your billing methods. Make sure the only payment methods on file are ones you recognise. Remove any that look unfamiliar. Set budget alerts so you’re notified if spend spikes unexpectedly.
Be sceptical of Google Ads emails. Genuine Google emails will never ask you to log in urgently via a link in the email itself. If you receive something that looks like a Google Ads notification and feels urgent, navigate directly to ads.google.com manually rather than clicking the link.
Enable spend alerts. Within Google Ads, you can set up alerts for unusual spend activity. It won’t prevent a hijacking but it can minimise the financial impact by alerting you quickly.
Report financial losses to Action Fraud. If you do suffer a loss through an ad account hijacking, report it to Action Fraud (actionfraud.police.uk) and to Google Support. Some losses are recoverable; documentation helps the claim process.
For Businesses Using Agencies
If a marketing agency manages your Google Ads on your behalf, this guidance applies to your account too, even if you never log in yourself. Make sure your agency has:
- Set up passkeys on the accounts they use to access your campaigns
- Reviewed their own MCC security practices
- Confirmed they have spend alerts configured
It’s a reasonable question to ask and any reputable agency should be able to answer it clearly. The agency’s security posture directly affects yours when they have manager access to your account.
The honest truth is that Google Ads account security hasn’t received as much attention as email security in most small businesses’ security thinking. Given how much money flows through these accounts, that’s worth correcting.