Your Google Ads account was hacked. The first four hours

Most of the difference between full recovery and partial recovery is decided before you finish reading this.

In the first four hours of a Google Ads account compromise: revoke unrecognised access, freeze the payment method, pause campaigns you did not create, and enforce two-factor on every Google account with admin rights. Then stop. Do not delete campaigns, users or history — deletion destroys the evidence a spend recovery claim depends on, and it is the most common self-inflicted wound in these incidents.

Do these four things now

Revoke every access you do not recognise, at both the account and manager level. Remove or freeze the payment method. Pause the campaigns you did not create. Reset passwords and enforce two-factor authentication on every Google account with admin access, starting with whichever is most likely to be the entry point.

That sequence stops the bleeding. Everything after it is about recovering what already left.

A compromised ad account is a finance incident with a marketing surface. Spend leaves in hours, not weeks, which is why containment comes before diagnosis.

Then stop, and do not delete anything

This is the part people get wrong under pressure. Do not delete the malicious campaigns. Do not remove the unauthorised users beyond revoking their access. Do not clear browser history on the affected machine.

Change history, access records and account security events are the evidence a spend claim rests on. They are finite and time-boxed. Deleting the campaigns feels like cleaning up and is actually destroying the record that proves the spend was not yours.

A claim built on a documented, coherent timeline behaves entirely differently in escalation than one built on a description of events. First-line platform support is not where recovery is decided. Escalation is, and escalation reads evidence.

How this usually happened

Almost always through a compromised Google account with admin access, rather than a breach of Google itself. Phishing, credential reuse, or a session token stolen by a browser extension.

That is why hardening happens at the identity layer rather than inside Google Ads. The advertising account was the target; the person's Google account was the door.

Accounts with no enforced two-factor and standing third-party access are the usual entry points. If you are reading this preventively, those two are the highest-value things to fix today.

Preventive hardening versus incident response

Preventive hardening versus incident response
Preventive hardeningIncident response
TriggerScheduledActive compromise
DurationDays1–2 weeks plus platform time
CostMaterially lowerHigher, plus the lost spend
OutcomeControlled, certainDepends on a platform decision
What you getAccess matrix, 2FA, alertingTimeline, claim, hardening, report

The Outcome row is the honest one. Hardening produces a result you control. Recovery produces a claim, and whether it succeeds is Google's decision, not yours or your provider's.

Anyone guaranteeing recovery of hijacked spend is guessing on your behalf. What is genuinely within anyone's control is containment speed and evidence quality.

What recovery actually depends on

Three things. How fast containment happened. Whether malicious spend can be cleanly separated from legitimate spend in the same window. And whether the access timeline is documented rather than narrated.

Kodelytics led the forensic response on a compromise involving more than $41,000 of unauthorised spend, and recovered it in full — containment, a reconstructed access timeline, a separated spend figure, and a claim pursued past first-line support. That outcome is not a promise for the next incident, because fund recovery is a platform decision.

What generalises is the method, which is what ad account security and compromise recovery is scoped around: contain inside twenty-four hours, document to the standard a credit claim requires, then harden the estate so it does not recur.

After the money question is settled

Hardening is the part that decides whether you do this again. Two-factor enforced rather than encouraged. An access matrix rebuilt so you know who has what at which level. Manager account isolation, so one compromised login does not reach everything. Billing controls, and alerting on spend anomalies so the next event is caught in hours rather than days.

If you run many accounts, the access governance half of that belongs with the MCC layer rather than being handled account by account. Thirty accounts secured individually is thirty chances to miss one.

Start a conversationMore insights