Google Ads Manager Accounts (MCCs) Are Under Attack: What Agencies Must Do Before One Login Compromises Every Client

Google Ads MCC attack and how to be ensure safety
Google Ads security has shifted from individual accounts to Manager Accounts (MCCs). With attackers using sophisticated phishing tactics to compromise agency logins, a single breach now threatens entire client portfolios. This article explores why agencies are high-value targets, how modern attacks exploit trust, where current security measures fall short, and the critical steps every agency must take to protect their clients and business continuity today.
Most agencies still think about Google Ads security at the account level.
  • Enable two-factor authentication.
  • Use strong passwords.
  • Remove old users.
  • Train employees to recognize phishing emails.
  • Those are all important practices.
That is no longer enough.
They do not address the biggest security risk facing agencies today:
Google Ads Manager Account (MCC) compromise.
A compromised advertiser account can create problems for one business.
A compromised MCC can create problems for an entire client portfolio.
One compromised login can potentially affect client access, billing settings, campaign management, reporting visibility, account ownership, and agency credibility across dozens, hundreds, or even thousands of connected accounts.
Recent incidents documented by Malwarebytes, Search Engine Land, and industry agencies suggest that attackers understand this.
They are no longer targeting only advertisers.
They are increasingly targeting agencies.
Recently, InvisiblePPC experienced a Google Ads MCC compromise, requiring immediate coordination with Google, partner agencies, and internal teams to secure account access and review affected accounts.
While the incident was successfully contained, it reinforced a growing reality that every agency should understand:
Google Ads Manager Account security is no longer just a cybersecurity concern.
It is a business continuity concern.

Why Agencies Have Become High-Value Targets

To understand the risk, it helps to think like an attacker.
A compromised advertiser account provides access to a single business.
A compromised agency MCC can provide access to an entire portfolio.
That portfolio may include:
  • Multiple advertiser accounts
  • Billing relationships
  • User permissions
  • Reporting access
  • Historical campaign data
  • Agency-client relationships
From an attacker’s perspective, compromising an agency MCC offers significantly more leverage than compromising a single advertiser account.
A successful compromise may allow an attacker to:
  • Spend advertising budgets
  • Launch scam campaigns
  • Promote malware
  • Create phishing advertisements
  • Harvest additional advertiser accounts
  • Modify user permissions
  • Abuse trusted account history
  • Attempt unauthorized billing activity
The larger the agency, the more attractive the target becomes.
This is one of the primary reasons Google Ads Manager Accounts are becoming increasingly valuable to cybercriminals.

How Attackers Are Getting Access

One of the most revealing investigations into modern Google Ads attacks came from Malwarebytes in 2025. What made the campaign notable was not simply that it existed.
It was how it worked.
Rather than relying on suspicious emails, attackers purchased advertisements directly inside Google Search and impersonated legitimate Google Ads listings.
Users searching for terms such as:
  • Google Ads Login
  • Google Ads Sign In
  • Google Ads Setup
  • Google Ads Account
could encounter sponsored listings that appeared to be legitimate Google properties.
The process looked normal. The advertisement looked legitimate. The branding appeared authentic.
The page looked familiar.
The user was then prompted to sign in, approve access, verify an account, complete setup, or confirm account information. The experience felt routine.
That is precisely why it worked.
Instead of tricking users with obvious scams, attackers leveraged trust and familiarity.
The attack succeeded because victims believed they were interacting with Google.
In reality, they were entering a phishing flow designed to collect credentials, session information, and account access.

The sites.google.com Problem

One of the most concerning details from the Malwarebytes investigation was the use of Google Sites.
In many cases, victims were routed through pages hosted on:
sites.google.com
This matters because Google Sites is a legitimate Google product.
Most marketers, agency employees, and business owners instinctively trust Google-owned domains.
Attackers exploited that trust. The Google Sites page often served as an intermediate step between the advertisement and the final phishing destination.
The victim saw a Google domain. The page looked authentic. The experience appeared legitimate. The likelihood of continuing increased dramatically.
For agencies, the takeaway is simple:
Do not trust a page simply because it carries Google branding. Do not trust a page simply because it is hosted on a Google-owned property.
Avoid logging into Google Ads through sponsored search results.

Fake Approval Requests May Be More Dangerous Than Fake Login Pages

Many agencies train employees to be cautious about passwords.
Far fewer train employees to be cautious about approvals.
Modern phishing attacks increasingly mimic:
  • Account verification requests
  • Access approval requests
  • Manager account invitations
  • Billing confirmations
  • Security reviews
  • Setup completion screens
  • Account ownership confirmations
These prompts often appear legitimate because they resemble tasks agency employees perform every day.
An employee onboarding a new client, accepting account access, approving a request, or updating settings may not immediately recognize a fraudulent prompt.
Attackers understand this behavior.
As a result, some of the most successful attacks today rely less on stealing passwords and more on convincing users to approve something they should not.

The Industry Has Already Seen What Happens Next

In April 2026, Search Engine Land published a first-hand account from an agency whose Google Ads MCC was compromised.
The agency already had two-factor authentication enabled. Domain restrictions were already in place.
Yet attackers still gained access through a compromised employee account.
Once inside, they:
  • Removed legitimate users
  • Added unauthorized users
  • Changed account permissions
  • Modified allowed domains
  • Created a fake MCC using the agency’s name
  • Invited clients into the fake structure
  • Attempted unauthorized billing activity
The incident demonstrated how quickly a compromise can escalate once attackers gain access to a Manager Account.
The greatest risk is not always the initial breach.
The greatest risk is what happens after access is obtained.

When One Login Becomes Everyone's Problem

This is where MCC compromises become fundamentally different from advertiser account compromises.
A compromised advertiser account typically affects a single business.
A compromised MCC can affect an entire client portfolio.
Once attackers gain access to a Manager Account, they may be able to:
  • Remove legitimate users
  • Add attacker-controlled users
  • Modify user roles
  • Change account permissions
  • Create new manager account relationships
  • Invite clients into fraudulent account structures
  • Modify billing settings
  • Launch unauthorized campaigns
  • Disrupt reporting access
Financial losses are only part of the problem. Operational disruption can be equally damaging. Teams lose access. Clients lose confidence. Recovery efforts consume resources. Normal operations slow down or stop entirely.
For agencies, the real risk is not merely unauthorized ad spend.
The real risk is that one compromised login can trigger a portfolio-wide incident.

Where Google's Current Security Model Falls Short

Google has introduced meaningful improvements in recent years.
Features such as Multi-Party Approval are a step in the right direction.
However, agencies should understand where the current security model still has limitations.

Multi-Party Approval Is Helpful

Multi-Party Approval requires another administrator to approve certain high-risk changes before they can be completed.
This can help prevent attackers from immediately:
  • Adding new administrators
  • Removing legitimate administrators
  • Changing sensitive permissions
For agencies managing large account portfolios, this is a valuable safeguard.

But Single-Admin MCCs Remain Vulnerable

Multi-Party Approval only works when another trusted administrator exists.
If an MCC has only one administrator, there may be nobody available to approve or deny sensitive changes.
This creates a dangerous single point of failure.
Every agency should maintain multiple trusted administrators while limiting overall admin access.

Two-Factor Authentication Does Not Stop Every Attack Path

Two-factor authentication remains essential. Every agency should require it. But agencies should stop viewing it as a complete solution.
Modern attacks increasingly target:
  • Existing browser sessions
  • Authentication cookies
  • Recovery methods
  • Authorized devices
  • Persistent account access
The question agencies should ask is not:
“Do we have 2FA?”
The better question is:
“What happens if one of our authorized users becomes compromised?”

API Access Remains A Blind Spot

Most agencies review human users regularly.
Far fewer review API access.
Yet many agencies connect Google Ads to:
  • Reporting platforms
  • CRM systems
  • Call tracking software
  • Automation tools
  • Dashboards
  • Lead tracking systems
  • Custom integrations
These connections often have significant access to account data and functionality.
Agencies should maintain a documented inventory of every connected platform, understand the permissions granted to each tool, and regularly review whether those permissions remain necessary.
API access should be treated with the same seriousness as user access.

What Agencies Must Do Right Now

The old security standard was:
“Enable two-factor authentication.”
The new security standard is:
“Assume a login can be compromised and design your account structure accordingly.”
That means:

1. Stop Using Sponsored Search Results To Access Google Ads

Use bookmarks. Use saved URLs. Use password manager launch links.
Do not search Google and click a sponsored login result.

2. Audit Every MCC User

Review every user with access. Remove former employees, contractors, vendors, duplicate users, and anyone who no longer requires access.

3. Reduce Admin Access

Not every employee needs administrator permissions. Use the lowest level of access necessary.

4. Maintain Multiple Trusted Administrators

Avoid single-admin Manager Accounts.
Ensure trusted administrators can respond quickly during security incidents.

5. Review API Access Monthly

Know which tools are connected. Know what permissions they have. Remove unnecessary access.

6. Keep Clients As Administrators On Their Own Accounts

Client-side ownership can be critical during recovery situations.

7. Train Clients To Question Unexpected Invitations

Clients should verify any unexpected Manager Account invitation before accepting it.

8. Create An Incident Response Plan

The worst time to decide how to respond to an MCC compromise is during one.

What To Do If Your MCC Is Compromised

If suspicious activity is detected, speed matters.

Contact Google Immediately

Use Google’s compromised account process:
Document all support cases, communications, and timeline events.

Secure Any Accounts Still Accessible

If alternate administrators still have access, disconnect affected accounts from the compromised structure where appropriate.

Review Users, Permissions, and Billing

Once access is restored:
  • Remove unauthorized users
  • Review permissions
  • Validate billing settings
  • Audit manager account links
  • Review account changes
Assume nothing. Verify everything.

Communicate Clearly With Clients

Provide accurate and timely updates regarding:
  • What happened
  • What is known
  • What actions have been taken
  • What clients should do next
Clear communication helps preserve trust during recovery.

Final Takeaway

Recent incidents documented by Malwarebytes, Search Engine Land, and agencies across the industry demonstrate that attackers are increasingly targeting Manager Accounts because they provide access to multiple advertisers, larger budgets, and broader operational control.
Google’s security tools continue to improve, but the blindspots remain.
But agencies cannot outsource security entirely to Google.
Google Ads Manager Account security is now an operational responsibility, a client-retention responsibility, and increasingly, a business continuity responsibility.
The agencies that prepare before an incident occurs will be in a much stronger position than those attempting to build a recovery plan during one.

Leave a Comment

Leave a Comment

Picture of Avi Kumar
Avi Kumar

Avi Kumar is a marketing strategist, AI toolmaker, and CEO of Kuware, InvisiblePPC, and several SaaS platforms powering local business growth.

Read Avi’s full story here.