Meta and Google ad account thefts hit record 6.4M detections
Mimecast reports 6.4 million detections of Meta and Google ad account thefts over the past four years, with a record 1.86 million incidents in late 2025. The research identifies that attackers utilize legitimate sending infrastructure like Salesforce and Google Workspace to bypass security filters, posing significant operational and financial risks to streaming marketers.
Key Takeaways
- Threat actors hijacked 1.86 million accounts in H2 2025 alone, surpassing all previous reporting periods.
- One in three detected phishing campaigns originated from Salesforce infrastructure to exploit established sender reputations.
- Stolen Meta Business Manager accounts trade for up to $340, while high-risk Google Ads accounts fetch $270 on Telegram.
- Legitimate ad history acts as a trust multiplier, making older accounts 2x to 4x more valuable than new attacker-created ones.
Why It Matters
The industrialization of ad account theft creates a permanent drain on marketing efficiency and platform integrity. For streaming marketers, the risk extends beyond immediate budget loss to the long-term erosion of account trust scores and disruptive multi-month recovery cycles. As attackers transition toward the 'legitimate infrastructure' model, traditional reputation-based filters are becoming insufficient. This indicates a shift where account security must move from simple credential protection to rigorous administrative monitoring and least-privilege access. Watch for mandatory passkey implementation across ad platforms, as Google began requiring passkeys for sensitive billing and user changes starting July 15, 2026.
Additional Context
The surge in account theft aligns with broader litigation and regulatory scrutiny regarding platform accountability. In April 2026, the Consumer Federation of America filed a class-action lawsuit in Washington, D.C., alleging that Meta knowingly profited from fraudulent advertising. The complaint cited internal estimates that scam ads generate approximately 15 billion daily impressions, contributing an annualized $7 billion to Meta’s revenue. Per Reuters in May 2026, similar civil enforcement actions have emerged in California, accusing platforms of using AI tools to optimize reaching vulnerable users with high-risk content while charging scammers higher 'penalty' rates for distribution. Platforms have responded with localized enforcement and technical shifts. In June 2026, Meta and Microsoft partnered with the U.S. Department of Justice to disrupt Southeast Asian scam compounds, resulting in the removal of 1.4 million online assets and 63 arrests. Concurrently, Google introduced a 'Security Tasks Summary' tab in June 2026 to push advertisers toward two-factor authentication and passkeys. Despite these efforts, industry groups like Pubcon and analysts from Malwarebytes continue to report that sophisticated 'attacker-in-the-middle' phishing can bypass standard security layers, leaving aged manager accounts vulnerable to overnight takeovers, a trend exacerbated by digital ad fraud reaching new heights.
Read full article at helpnetsecurity.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source