You are locked out of a Google Ads Manager Account, unfamiliar administrators are appearing, or client billing has started changing without approval. Treat that as an active identity, advertising, and financial incident. Your first job is not to restore the MCC dashboard. It is to stop the compromised manager from reaching more client accounts.
The recovery order matters. Contain accounts through access you still trust, secure the Google identities behind that access, escalate every affected Customer ID, and only then rebuild the manager hierarchy. This playbook gives you a practical sequence for doing that without mistaking a restored login for a clean account.
Treat the manager account as hostile until you contain it
A Google Ads Manager Account, still commonly called an MCC, concentrates access. That makes it operationally convenient and potentially dangerous: one compromised administrator can expose multiple client accounts, manager relationships, campaigns, and billing arrangements.
Once you see a credible takeover signal, stop using the affected MCC as your control center. An attacker with administrative access may be able to remove your users, alter allowed-domain settings, create another manager account with a familiar company name, issue invitations, change payment arrangements, and launch unauthorized campaigns. Work from client-owned accounts and clean identities wherever possible.
- Open an incident record outside the affected account. Record the detection time, every known Customer ID, the manager hierarchy you expected, suspicious email addresses, unauthorized campaigns, billing changes, and every action your team takes. Assign one person to maintain the timeline so simultaneous recovery work does not create conflicting instructions.
- Identify access you can still trust. Contact each client’s known account owner through a previously established channel. Ask an existing client administrator to sign in directly, confirm that their own Google identity is secure, and inspect the account without relying on an invitation sent during the incident.
- Disconnect exposed client accounts from the compromised MCC. A client administrator with retained access can remove the manager relationship and preserve an independent route into the account. Coordinate this with the client because disconnecting an agency manager can interrupt normal management workflows, but leaving a hostile manager attached preserves the attacker’s reach.
- Escalate every affected account to Google. Contact your established Google representative if you have one, and use Google’s compromised-account process. Submit an Account Takeover Form for each affected client account and for the MCC itself. Do not assume a single manager-level report automatically creates cases for every linked Customer ID.
- Control advertising exposure. Through clean client access, inspect recently created or materially changed campaigns, budgets, ads, and destination URLs. Pause clearly unauthorized activity when you have confirmed that doing so will not stop legitimate campaigns. Keep a record of what you paused and why.
- Bring the authorized billing owner into the incident. Review the payment manager, payment methods, failed or pending charges, and any unfamiliar billing profile changes. Ask the bank or card issuer about suspicious attempts. Do not indiscriminately delete payment information or replace billing ownership without documenting the existing state; that can disrupt legitimate campaigns and make reconciliation harder.
The potential blast radius is not theoretical. In one documented MCC takeover, administrators were removed, the allowed domains were changed to admit Gmail addresses, more than a dozen people were invited to a newly created manager account, payment arrangements were altered, and unauthorized campaigns appeared. Attempted fraudulent charges reached half a million on some accounts. Control was restored within eight hours and the direct loss was limited to $100, but that outcome is an incident example, not a recovery-time or loss benchmark.
If you cannot reach a clean administrator, do not create a new relationship through an identity that may also be compromised. Preserve the Customer ID and other evidence, continue the Google escalation, and involve a cybersecurity professional when the attacker remains active across multiple email accounts or devices.
Recover each client account in a controlled order

Containment removes or limits the attacker’s path. Recovery proves that each layer is clean. Getting back into the MCC does not establish that its administrators, manager links, payment manager, or client campaigns are safe. Reconnecting every client immediately can restore broad access before you know whether the underlying identity breach has been removed.
Create a recovery worksheet from records outside the compromised hierarchy: contracts, client contact lists, prior invoices, Customer ID inventories, and configuration backups. Track every client separately. At minimum, include the Customer ID, trusted client administrator, expected manager relationship, takeover-case status, billing owner, suspicious changes, cleanup owner, and approval to reconnect.
| Recovery layer | What to verify | Condition before sign-off |
|---|---|---|
| Google identity | Email security, passwords, active sessions, recovery methods, and 2FA enrollment for every retained user | Only verified people control the identities that will receive Ads access |
| Users and manager links | Administrators, invitations, allowed domains, linked managers, and any similarly named MCC | Every user and manager relationship has a documented business owner |
| Billing | Payment manager, payment methods, billing profiles, failed attempts, pending charges, and client authorization | The client or authorized finance owner confirms the intended arrangement |
| Campaign configuration | New campaigns, budgets, ads, destinations, schedules, and other changes made during the incident window | Unauthorized changes are reversed or paused and legitimate changes are preserved |
Use Google Ads change history to build the account-side timeline. Start slightly before the first visible symptom and follow the sequence forward. Look for user removals, invitations, domain-setting changes, new manager relationships, billing modifications, campaign creation, budget changes, and cleanup attempts. Detailed timestamps can help you distinguish the attacker’s actions from the emergency changes made by your own team.
- Record the earliest suspicious Ads change and the identity associated with it.
- Match later changes to the account, campaign, billing, or manager layer they affected.
- Mark your own emergency actions so they are not mistaken for attacker activity.
- Compare the final configuration with a known-good export or Google Ads Editor backup.
- Keep unresolved items open instead of treating restored access as proof that they are harmless.
Change history is valuable, but it is not a complete identity-forensics record. It can show what changed in Google Ads and when; it may not prove how an employee mailbox was first compromised. Pair it with the security activity available for the affected Google identities and with your internal email, device, and access records.
Reconnect a client only after its trusted administrator approves the user list, manager relationship, billing state, and campaign configuration. Use the original verified Customer IDs rather than accepting a link merely because the manager account has your agency’s name. A copycat MCC can look convincing while remaining fully controlled by an attacker.
Investigate the identity breach even when 2FA was enabled
Two-factor authentication is an important control, but its presence does not prove that an identity is clean. If an attacker has maintained access to an employee’s email account, recovery settings, or approved device, that attacker may be able to establish an authentication path that looks legitimate. Resetting only the Google Ads password can leave that path intact.
In the documented takeover, the attackers tried multiple employee identities before succeeding through a junior employee’s email. That email had apparently been compromised for months, and the attackers had configured their own 2FA before taking over the MCC. Phishing or a compromised password was considered a likely initial route, but the exact entry method was not established. The lesson is precise: investigate the user’s wider Google identity and device sessions, not just the Ads permission that was abused.
- Secure the mailbox first. Change any compromised or reused password, review recovery options, remove unfamiliar access, and revoke active sessions. A unique password for every service limits the chance that credentials exposed elsewhere can be reused against a Google identity.
- Rebuild 2FA enrollment. Remove authentication methods you cannot attribute to the user and enroll a dedicated method under a controlled process. Do not rely solely on device approval notifications that a user can accept reflexively or that an attacker-controlled device may receive.
- Review every person with MCC access. Check administrators as well as standard users. A low-privilege employee identity can still become an entry point if it has more Google Ads permissions than the role requires.
- Revoke old sessions and devices. A password change is not the same as a complete session reset. End existing sessions as part of the recovery so a previously authenticated attacker is not silently left connected.
- Restore the minimum required Ads role. Give the returning user only the access needed for current work. Do not restore administrative access merely because the person held it before the incident.
Apply the same skepticism to invitations. Tell clients that unexpected Google Ads access or manager-link requests must be verified with a known agency contact through a separate channel. They should not confirm legitimacy by replying to the invitation email or by trusting the manager’s display name. In the takeover described above, clients avoided a larger problem by ignoring invitations from the fraudulent manager.
If suspicious access reappears after passwords, sessions, and 2FA have been reset, stop cycling credentials without a broader investigation. Persistent access can indicate that another mailbox, recovery route, device, or administrator is still compromised. That is the point to involve an identity-security or incident-response specialist.
Build an MCC that can fail without taking clients with it

The strongest MCC design does not depend on preventing every credential attack. It limits what one compromised identity can reach and preserves a clean way back into every client account. That requires changes to ownership, permissions, authentication, billing, backups, and escalation procedures.
- Keep independent client administrators. Every client should retain access to its own account through an identity the client controls. This is good account governance and a recovery mechanism: the client can inspect activity or disconnect a compromised manager without waiting for the agency’s MCC to be restored.
- Use least privilege for agency users. Reserve administrative access for people who actually manage users, manager relationships, security settings, or billing. Campaign operators should receive the lowest role that supports their work. Reassess permissions when responsibilities change instead of allowing access to accumulate.
- Remove stale surface area. Unlink obsolete client accounts and unused MCCs, remove former employees and contractors, close unnecessary invitations, and review allowed domains. A dormant relationship can remain useful to an attacker even when nobody on your team remembers it exists.
- Run recurring access recertification. Ask a named owner to affirm every user, manager link, and administrative role. Do not treat a spreadsheet export as a completed review; each entry needs a business reason and an accountable owner.
- Use unique passwords and controlled authentication. Each person should have an individual identity rather than a shared login. Enroll 2FA deliberately, favor dedicated authenticators over casual notification approvals, and include session revocation in suspected-compromise procedures.
- Enable multi-party approval where available. Google’s multi-party approval feature requires another administrator to confirm certain major changes. It reduces the chance that one compromised administrator can complete a sensitive action alone. The second approver must use a separately secured identity or the control becomes ceremonial.
- Keep recoverable campaign configurations. Export regular backups with Google Ads Editor, and refresh them after approved material changes. Store them somewhere the compromised MCC cannot alter. A backup will not restore identity or billing ownership, but it gives you a known configuration against which to identify and reverse campaign changes.
- Design billing escalation before an incident. Document who can change the payment manager, who speaks for each client, and who contacts the bank or card issuer. Credit or invoice arrangements helped financial institutions flag irregular transactions in the documented takeover, but no payment method guarantees that fraud will be stopped. Your finance owner still needs a rapid review process.
- Maintain human escalation routes. Keep current contact details for Google representatives, client administrators, finance owners, internal security staff, and agency peers who can help establish the scope. Store this list outside Google Ads so it remains available when the MCC does not.
Test the design by assuming the MCC is unavailable. Can you name every linked Customer ID? Can each client reach its account independently? Can your team find a known-good campaign export? Does everyone know who is allowed to request a manager link and how that request is verified? Any answer that exists only inside the MCC is a dependency worth fixing.
Key takeaways for Google Ads MCC security and recovery
- Treat a suspected MCC takeover as an identity, advertising, and billing incident, not merely a lost-password problem.
- Use verified client-owned admin access to disconnect exposed accounts and reduce the compromised manager’s reach.
- Submit a takeover case for every affected Customer ID, including the manager account, and keep one external incident timeline.
- Validate identities and sessions before restoring Ads permissions; 2FA does not help if the attacker enrolled or controls the second factor.
- Reconcile users, manager links, billing, and campaign changes before reconnecting a client to the recovered MCC.
- Reduce future impact with independent client admins, least privilege, access recertification, multi-party approval, and Google Ads Editor backups.
Set up one recovery drill before you need it. Export the current client and manager inventory, confirm an independent administrator for every client, save a known-good configuration, and put the escalation contacts where the team can reach them without the MCC. The useful standard is simple: if the manager account disappeared tonight, you could still identify, contact, contain, and recover every client account.
References


Leave a Reply