Cybercriminals Turn Ad Account Theft into a Lucrative Underground Economy
Cybercriminals have transformed the hijacking of Meta Business Manager and Google Ads accounts into a structured, commodity-driven market, complete with tiered pricing, escrow services, and money-back guarantees for stolen credentials. While drained ad budgets are often the most visible consequence, the real value for attackers lies in aged, high-spending accounts which bypass platform security checks and command premium prices in underground forums.
According to Mimecast, compromised accounts with established spending histories and verification statuses sell for 2–4 times more than newly created ones. Zscaler reports stolen Meta Business Manager accounts fetching $15–$340, while high-risk Google Ads accounts have been listed for $200–$270 on Telegram. Pricing depends on factors like account age, daily spending limits, and past ad performance.
A Rising Threat Despite Crackdowns
Mimecast’s four-year telemetry reveals 6.4 million detections of ad account theft, with 1.86 million recorded in the second half of 2025 a record high, despite recent enforcement actions. Takedowns, such as the March 2026 dismantling of the PXA Stealer ring (which led to 14 prosecutions), only caused temporary dips before activity rebounded.
The campaigns are linked to Vietnam-based malware families (DuckTail, NodeStealer, VietCredCare, PXA Stealer) as well as operations from Brazil, Portugal, China, and Hong Kong.
How Attackers Bypass Security Filters
Rather than relying on malicious infrastructure, cybercriminals exploit trusted platforms to evade detection. Mimecast found that:
- One-third of detections arrived via Salesforce infrastructure
- A quarter used Google Workspace mail-merge tools or SharePoint-hosted links
These services provide legitimate sender reputations, allowing phishing emails to bypass SPF, DKIM, and IP-based filters. Attackers only need to craft convincing content to trick victims.
The Long-Term Cost of Account Theft
While fraudulent ad spend can be halted within hours, recovering a hijacked account is far more difficult. Attackers often add their own admins and downgrade legitimate owners, leaving victims locked in appeal queues for months. Unlike credit card fraud, ad platforms lack zero-liability protections, and their revenue models incentivize delayed responses since compromised accounts continue generating ad impressions (and platform revenue) even under review.
A 2026 class-action lawsuit by the Consumer Federation of America alleges Meta’s scam advertising ecosystem generates 15 billion fraudulent impressions daily, worth an estimated $7 billion annually. While Meta has taken legal action against scam advertisers, critics argue platforms prioritize revenue over swift account recovery.
Until advertisers treat ad accounts with the same security rigor as other high-value assets and platforms improve recovery processes stolen accounts will remain a persistent threat in the cybercriminal economy.
Source: https://www.helpnetsecurity.com/2026/07/29/ad-account-theft-meta-google/
Google Ads cybersecurity rating report: https://www.rankiteo.com/company/google-ads-
"id": "GOO1785321058",
"linkid": "google-ads-",
"type": "Cyber Attack",
"date": "7/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Advertisers with high-spending '
'Meta Business Manager accounts',
'industry': 'Technology/Advertising',
'location': 'Global',
'name': 'Meta (Facebook)',
'size': 'Large',
'type': 'Social Media/Advertising Platform'},
{'customers_affected': 'Advertisers with high-risk '
'Google Ads accounts',
'industry': 'Technology/Advertising',
'location': 'Global',
'name': 'Google',
'size': 'Large',
'type': 'Technology/Advertising Platform'},
{'customers_affected': 'Users targeted via phishing '
'emails',
'industry': 'Technology',
'location': 'Global',
'name': 'Salesforce',
'size': 'Large',
'type': 'Cloud Software'},
{'customers_affected': 'Users targeted via phishing '
'links',
'industry': 'Technology',
'location': 'Global',
'name': 'Microsoft (SharePoint)',
'size': 'Large',
'type': 'Cloud Software'}],
'attack_vector': ['Phishing emails via trusted platforms (Salesforce, Google '
'Workspace, SharePoint)',
'Malware (DuckTail, NodeStealer, VietCredCare, PXA '
'Stealer)'],
'description': 'Cybercriminals have transformed the hijacking of Meta '
'Business Manager and Google Ads accounts into a structured, '
'commodity-driven market, complete with tiered pricing, escrow '
'services, and money-back guarantees for stolen credentials. '
'The real value lies in aged, high-spending accounts which '
'bypass platform security checks and command premium prices in '
'underground forums. Compromised accounts with established '
'spending histories sell for 2–4 times more than newly created '
'ones, with Meta Business Manager accounts fetching $15–$340 '
'and high-risk Google Ads accounts listed for $200–$270 on '
'Telegram. Despite enforcement actions, ad account theft '
'remains a persistent threat, with 6.4 million detections over '
'four years and 1.86 million in the second half of 2025 alone.',
'impact': {'brand_reputation_impact': ['Scam advertising ecosystem generating '
'15 billion fraudulent impressions '
'daily'],
'financial_loss': ['Drained ad budgets',
'Fraudulent ad spend generating $7 billion '
'annually (estimated)'],
'legal_liabilities': ['2026 class-action lawsuit by Consumer '
'Federation of America'],
'operational_impact': ['Delayed account recovery (months)',
'Legitimate owners locked out of accounts'],
'revenue_loss': ['$7 billion annually in fraudulent ad impressions '
'(estimated)'],
'systems_affected': ['Meta Business Manager', 'Google Ads']},
'initial_access_broker': {'data_sold_on_dark_web': ['Meta Business Manager '
'accounts ($15–$340)',
'Google Ads accounts '
'($200–$270)'],
'entry_point': ['Phishing emails via trusted '
'platforms (Salesforce, Google '
'Workspace, SharePoint)'],
'high_value_targets': ['Aged, high-spending ad '
'accounts']},
'lessons_learned': 'Advertisers must treat ad accounts with the same security '
'rigor as other high-value assets. Platforms need to '
'improve recovery processes to mitigate the persistent '
'threat of stolen accounts.',
'motivation': ['Financial gain',
'Fraudulent ad spend',
'Sale of compromised accounts'],
'post_incident_analysis': {'corrective_actions': ['Improve detection of '
'phishing emails from '
'trusted platforms',
'Enhance account recovery '
'speed and transparency',
'Implement zero-liability '
'protections for ad account '
'fraud'],
'root_causes': ['Exploitation of trusted platforms '
'(Salesforce, Google Workspace, '
'SharePoint) to bypass security '
'filters',
'Lack of zero-liability '
'protections for ad account fraud',
'Delayed account recovery '
'processes incentivized by '
'platform revenue models']},
'recommendations': ['Enhance security for ad accounts (e.g., multi-factor '
'authentication, monitoring for unauthorized admin '
'additions)',
'Improve platform recovery processes to reduce delays for '
'hijacked accounts',
'Implement zero-liability protections for ad account '
'fraud',
'Increase enforcement against scam advertisers and '
'underground marketplaces'],
'references': [{'source': 'Mimecast'},
{'source': 'Zscaler'},
{'source': 'Consumer Federation of America'}],
'regulatory_compliance': {'legal_actions': ['2026 class-action lawsuit by '
'Consumer Federation of America']},
'response': {'law_enforcement_notified': ['March 2026 dismantling of PXA '
'Stealer ring (14 prosecutions)']},
'threat_actor': ['Vietnam-based groups (DuckTail, NodeStealer, VietCredCare, '
'PXA Stealer)',
'Operations from Brazil, Portugal, China, and Hong Kong'],
'title': 'Cybercriminals Turn Ad Account Theft into a Lucrative Underground '
'Economy',
'type': ['Account Hijacking', 'Phishing', 'Malware'],
'vulnerability_exploited': ['Legitimate sender reputations (SPF, DKIM, '
'IP-based filters bypass)',
'Lack of zero-liability protections for ad '
'accounts',
'Delayed account recovery processes']}