TL;DR: Attackers are targeting Google Ad Manager accounts to run malvertising, ad fraud, account resale, and extortion schemes, while also using hijacked accounts to reach broader SSO-linked services and monetise existing ad spend, according to Push Security. The security gap is not just phishing resistance, but browser-level identity protection for high-value commercial accounts.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “How cyber criminals power malvertising scams with stolen accounts”.
Key questions
Q: What breaks when a Google Ad Manager account is phished?
A: The account stops being a bounded marketing tool and becomes a reusable access token for fraud, malvertising and broader SaaS compromise.
Q: Why do compromised advertising accounts create such a large blast radius?
A: They carry trust, spend authority and relationships that normal fraud controls may not scrutinise closely.
Q: How can security teams detect ad account abuse before budgets are exhausted?
A: Look for new campaigns, unfamiliar destination URLs, abrupt spend spikes, account recovery changes and campaign edits that do not fit normal marketing activity.
Practitioner guidance
- Audit high-value advertising identities Map every Google Ad Manager, Google Ads and MCC account to the business systems and SaaS services it can reach, including any SSO-linked applications.
- Harden browser-side session protection Prioritise controls that detect AITM phishing, session theft and malicious login flows inside the browser rather than relying only on email filtering.
- Separate campaign authority from account recovery Remove excessive recovery paths, shared access and informal delegation from marketing accounts so a stolen session cannot be turned into persistent control.
Bottom line: Google Ad Manager takeovers are no longer just an advertising problem because the same account can be used for malvertising, ad fraud, resale and extortion.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Google Ad Manager abuse is an identity security problem hiding inside a revenue workflow. The account is valuable because it combines authentication, billing authority, and downstream application reach. Once compromised, it becomes both a fraud instrument and a pivot point into broader SaaS access. Practitioners should treat commercial advertising identities as protected access paths, not just campaign admin consoles.
A few things that frame the scale:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
A question worth separating out:
Q: How should organisations govern marketing accounts that also reach SSO-linked apps?
A: Treat them as business-critical identities with explicit ownership, review and recovery controls, not as casual team logins. Restrict shared access, document downstream application reach, and remove unnecessary login reuse across SaaS tools. If the same identity opens multiple doors, governance has to cover every door it can open.
👉 Read our full editorial: Google Ad Manager account takeovers are powering malvertising scams