Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud
28 July 2026
By Hiwot Mendahun and the Mimecast Threat Research Team
Over four years, Mimecast has tracked 6.4 million detections of the systematic theft of Meta Business Manager and Google Ads accounts. This is a widespread commodity crime in the advertising ecosystem where threat actors drain business budgets, when possible, but what they really trade on is account reputation. Aged Business Managers and Google Ads accounts with clean spend history are graded, sold, and reused in a mature underground market with tiered pricing, escrow, and money-back warranties. Unlike card fraud, where chargeback and zero-liability protections exist, platforms offer no equivalent — and have a structural financial incentive not to act quickly.
Key variants span Vietnam (DuckTail, NodeStealer, VietCredCare, PXA Stealer), Brazil/Portugal (Google Ads heist), and China/Hong Kong (parallel Google Ads operation). The threat is not sector-specific; any organization running paid advertising on Google or Meta is in scope.
How It Begins
A marketing director at a mid-sized UK e-commerce agency checks their inbox before the first meeting of the day, when a message catches their attention. It looks like it's from Meta Business Support. The subject line reads: "Final Notice: Policy Violation Detected," familiar enough to recognize, urgent enough to open.
The body is brief. The Business Manager may be restricted. There are 24 hours to review the violation. The display name looks right. The director doesn't check the sender address.
They click.
The page that follows resembles Meta's real login portal. The director enters their credentials and completes the MFA prompt.
Behind it, their credentials and authentication code are forwarded to a Telegram bot.
By the next morning, the agency's ad campaigns are paused. New ads are running from the Business Manager account, with offers no one on the team created and spend no one authorized. The director unlinks any linked cards and contacts support.
Meta support replies days later. By then, backup admins are in place, billing has changed, and clients are asking questions.
The card is stopped in hours. The account is not.
The World of Ads - How the Target Works
Digital advertising is the financial backbone of the modern internet. In 2025, Google earned $224 billion in search-based ad revenues alone, $295 billion across its full advertising portfolio; Meta generated a further $196 billion. These platforms sell access to audiences at scale through self-serve portals that anyone with a payment method can access.
Google Ads Ecosystem
Businesses bid for placement in search results via Google Ads Manager. Campaigns are managed through linked Google accounts with payment cards on file. Agencies often manage multiple clients from a single Manager Account (MCC), making a single account compromise a multi-victim event. Ads serve across search, display network, YouTube, shopping, and maps.
Meta Business Manager Ecosystem
Meta's Business Manager (BM), now Meta Business Suite controls Facebook and Instagram advertising. It holds Pages, Ad Accounts, Pixels, payment methods, and Partner access. A single BM can consolidate many client ad accounts and payment methods under one permission tree.
How Ads Are Purchased and Why Accounts Have Value
Both platforms operate on a pre-loaded credit or card-on-file model. Campaigns spend continuously until a budget cap, or the account holder intervenes. A newly compromised account with a $5,000 monthly budget can be drained in hours. Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account. This is what makes the older, higher-history account worth a 2–4× premium in the underground market.
Why Ad Accounts Are Valuable - Five Use Cases
The criminal value of a stolen ad account is often misunderstood. Public reporting tends to focus on attackers draining the victim's ad budget but in practice, the budget is frequently a secondary or short-lived gain. What buyers pay for is the account itself: its age, spend history, policy standing, and the trust that platform review systems assign to established advertisers.
Victims tend to detect payment fraud quickly. Regaining full access to the Business Manager could take months.
Once inside, attackers typically run their own campaigns: dropshipping, crypto scams, counterfeit goods, lead-gen fraud funded with their own stolen or fraudulent payment cards, not the victim's.
Victims who notice quickly often remove compromised cards within hours or days. Support queues, identity verification, and platform appeal routinely take weeks or months. That recovery gap is the window attacker's exploit: they keep spending, add backup admins, and lock the legitimate owner out while the account's reputation continues to deliver ads that a freshly registered account could not.
|
Criminal Use Case |
How It Works |
|
Reputation Laundering (primary commodity) |
Aged accounts skip new-signup friction, face weaker automated review, and keep delivering while the legitimate owner waits on appeals. |
|
Spend Hijack (Opportunistic, often brief) |
Attacker runs their own campaigns on the victim's budget, malware downloads, crypto scams, phishing lures. The victim pays; the attacker profits from secondary fraud. No upfront capital required. |
|
Account Resale |
Accounts sold on Telegram channels and dark-web forums. Buyers get a trusted delivery vehicle with no signup friction and an immediate trust score. |
|
Account Recovery Services |
Businesses and individuals who lose access to compromised Meta or Google Ads accounts frequently turn to third-party "recovery specialists" advertised on Google, Facebook, and Telegram. These services charge upfront fees under the pretense of restoring access through platform escalation or insider contacts. |
|
Data Exfiltration |
BM accounts hold Facebook Pixel data, custom audience lists, and retargeting data first-party audience intelligence saleable to data brokers or used to target future fraud campaigns more precisely. |
Who Is Behind It – Documented Threat Actor Landscape
Public reporting and law enforcement actions repeatedly point to Southeast Asian operators, particularly Vietnam-linked clusters as a major source of the malware and phishing used to steal Meta Business and Google Ads accounts. That does not make this a single group or a Vietnamese-only threat: the tooling is Vietnamese-attributable in many high-profile cases, while resale, rental, and use of stolen inventory are global.
|
Threat Actor/Group |
Origin |
Primary Target |
Key Detail |
|
DuckTail |
Vietnam |
Meta BM (global) |
Active since 2021. LinkedIn/job offer lures .NET stealer. Telegram C2. Attribution confirmed by Meta (May 2023). Remains active post-2024 arrests with updated techniques. |
|
NodeStealer |
Vietnam |
Meta BM + browser credentials |
Python-based. Steals Facebook Business and browser credentials simultaneously. Multiple versions tracked 2022–2024. Disruption report published May 2023. |
|
VietCredCare |
Vietnam |
Meta BM (Vietnam + international) |
Malware-as-a-Service (MaaS) rental model. Auto-filters accounts with positive ad credit balance. 23 operators prosecuted May 2025. New variants emerged by late 2025. |
|
PXA Stealer |
Vietnam |
Facebook ad accounts (global) |
Built-in Facebook Graph API account checker. 14 prosecuted March 2026 including a 12th-grade programmer earning 15% of profits. 94,000 computers infected globally. |
|
Brazilian Group |
Brazil/Portugal |
Google Ads (global) |
Google Ads heist actor (Malwarebytes Jan 2025). Self-replicating campaign using stolen accounts. Portuguese JS comments. 24/7 live malicious ad maintained. |
|
Chinese/Hong Kong-based group |
China/Hong Kong |
Google Ads (global)
|
Parallel Google Ads heist operation using HK advertiser accounts. Phishing kit contains Chinese-language code comments and pinyin function names entirely different architecture from the Brazilian group but the same Google Sites gateway technique. |
Four Years of Detections - Mimecast Data
Mimecast has been tracking these campaigns since May 2022. The data below represents four years of continuous detection telemetry across the Mimecast customer base.
The rule set recorded approximately 125,000 detections across 2022, reflecting an early-stage campaign environment. What the low baseline obscures is that the underlying malware infrastructure including VietCredCare had already been operational since at least August 2022, before any public attribution existed. Campaigns were running, but they simply hadn't reached the volume thresholds that would define later periods.
The first significant step-change occurs in H2 2023 (~560k), a 3.6× increase on the prior half-year which likely reflects the organic growth in Malware-as-a-Service distribution, as operators rented stealer infrastructure, lowering the barrier to entry across the Vietnamese cybercrime ecosystem and beyond.
H1 2024 produced the highest single-period volume on record at approximately 1.67 million detections, coinciding with the concurrent operation of multiple infostealer families VietCredCare, DuckTail, and NodeStealer alongside growing Meta Business Manager partner-request abuse.
H2 2024 shows a corresponding decline to ~807k, consistent with post-arrest disruption to VietCredCare operations specifically (see Law Enforcement Response), while DuckTail continued largely unaffected with updated techniques.
H1 2025 recorded a partial recovery (~924k). The Google Ads heist campaign in which compromised advertiser accounts served fake ads targeting other advertisers had begun in mid-November 2024 and was gaining scale through this period, adding a second platform's victim pool to the detection set for the first time.
H2 2025 reached a new record of approximately 1.86 million detections, higher than the previous peak despite major enforcement actions concluding mid-year. The largest enforcement actions in the ecosystem's history produced only a temporary dip followed by a new high.
H1 2026 shows a decline to ~349k, following the PXA Stealer takedown in March (see Law Enforcement Response). Whether this decline reflects that disruption, Mimecast detection updates, or seasonal patterns can't be determined from volume data alone. Based on the observable pattern across this dataset, troughs have consistently preceded renewed activity at equal or greater volume.
Beyond the phishing templates and credential harvesting pages, we looked at how these campaigns were landing in inboxes, and the answer points to a deliberate and consistent abuse of trusted sending infrastructure.
Threat actors have systematically moved away from purpose-built malicious infrastructure toward legitimate, high-reputation sending platforms services that email security tools are configured to trust.
Mimecast telemetry shows that across the campaigns, approximately one in three detections arrived via Salesforce infrastructure. A further quarter arrived via Google Workspace mail-merge, and SharePoint-hosted links.
This distribution is not accidental. Salesforce and Google carry established sender reputations that bypass reputation-based filtering. Delivery through these platforms means the sending IP, domain, and authentication records (SPF, DKIM) all pass checks that would reject an unknown domain. The attacker's only task is to make the content convincing.
The pattern reflects a broader shift documented across multiple threat families, rather than building infrastructure, actors rent it. The same platforms businesses use to run legitimate marketing campaigns are being used, without authorization, to deliver credential phishing at scale. Detection therefore depends on content and behavioral analysis rather than sender reputation alone. A gap these campaigns are deliberately engineered to exploit.
Top Email Lures
Copyright / trademark infringement
Ad Partnership
Threat actors abuse Meta's legitimate Business Partner request feature to send phishing emails that pass authentication checks. Huntress documented an active variant of this technique as recently as July 2026, including a pivot to a Facebook Messenger chatbot component.
Job offer / social media manager / marketing brief
Impersonated Brands seen in 2026
|
FIFA |
Samsung |
|
Google AI |
Ferrari |
|
Reality Labs at Meta |
Warner Bros. Discovery |
|
Louis Vuitton |
Red Bull |
Meta verification / badge / account confirmation
AI app / product review
Impersonated Brands
|
Gemini |
|
Open AI |
Once Compromised – How Accounts Are Used
Once an account is compromised, threat actors typically add their own administrators so they can manage pages, ad accounts, and billing without relying on the victim’s login. The legitimate owner is then often downgraded to a basic or limited admin role, rather than removed outright.
That is usually intentional. Platform access controls mean a newly added admin cannot always strip the original owner’s access. Leaving the victim as a limited admin keeps the attacker’s seats in place while the owner can only sit and watch the damage being done.
With control secured, operators burn through the account budget as quickly as possible, raising spend limits where they can. Once that spend is blocked or the account is restricted, they rotate in additional payment methods, their own or other stolen ones, along with fresh ad accounts, to keep campaigns running.
The Underground Marketplace
Public reporting confirms stolen Meta Business Manager and Google Ads accounts are traded on Telegram channels and online marketplaces. Mimecast observations show the same pattern with account menus, crypto payment, and short warranty windows on replacement if the account locks.
The underground market for ad accounts has no single national identity, Vietnamese or otherwise. The channels and storefronts we observed carried listings in Vietnamese, Russian, Indonesian, and English. The seller's language reveals little about where an account came from, how it was obtained, or who will use it next.
The examples below illustrate public groups offering Ad accounts with tiered pricing, warranties, and rental models not proof that every listing is a stolen account. Much of what is sold is marketed as aged or “ready-to-run” inventory, which may be compromised, farmed, or otherwise prepared for grey-area advertising. In open Telegram and similar channels, sellers rarely document provenance, buyers often cannot tell whether an account was hijacked, generated, or legitimately created and later resold.
Public web shop selling FB / TikTok / IG inventory. Glossary: Via (real accounts), Clone (software-created), XMDT / 902 (verified/green-tick tiers). Crypto (USDT) deposits for foreign buyers; Telegram + Zalo contacts; cookie-login guidance to reduce checkpoints; API access for bulk automation.
Marketplace warranty terms (garansi) observed on a Telegram ad-account resale channel. Rules translated from Indonesian. Warranty covers account deliverability within 24 hours of purchase, not ad campaign performance. Tiered coverage applies to Freepaid and CC/threshold account types above IDR 1–2 million.
Resale channel (~17K subscribers) with #SOLD posts, order IDs, and pinned Rules. Listing workflow, not theft. Third-party overlay on Meta billing (Ads Check by SMIT ) status, daily limit, threshold, total spend, creation date, admin role. Likely used to grade accounts.
Facebook ad accounts for gambling and adjacent verticals; daily limits ($250/$1,500/no limit. Seller content also markets Meta risk-scoring guidance, positioning the channel as an operator rather than a one-off scam. English and Russian copy.
Crypto / iGaming Google Ads accounts (Spain/USD); prior spend $1,000–$2,000; ~$270 retail / ~$200 bulk; replacement if auto-banned before launch.
Business Manager storefront with aged BM3/BM50 listings from ~$6–$50; stock counts; 24-hour warranty (void if buyer shares access, changes permissions, or creates ad accounts). Escrow-style "funds held for 3 days", order history retained 3 days. Retail packaging of BM access as an e-commerce product.
Grey Market Tooling
Between the phishing kit and the Telegram storefront sits a grey market of tools that operate in plain sight: legitimate branding, real advertising use cases, indistinguishable from standard agency software until you look at who else is using them.
Vietnamese brand SMIT.VN markets "Ads Check" as a Facebook ad management tool (see table); the same overlay that legitimate agencies use to manage client accounts also serves as a pre-sale grading tool for stolen ones. Its second product, SMIT Connect, manages multiple cookies across browsers and devices via cloud sync, a capability with no conventional advertising use case, but exactly what's needed to maintain and hand off stolen account sessions.
The original Ads Check extension was removed from the Chrome Web Store on 28 November 2023 for malware classification, after accumulating 1,924 users and requesting full access to facebook.com. A separate extension under the same branding later reappeared in the store, and the website still offers a Chrome extension plus an Android APK distributed outside the Play Store, bypassing Google's review entirely.
Whether SMIT.VN operates with knowledge of how its tools are used cannot be determined from open sources. What can be said: its tooling appears in Telegram resale listings as a pre-sale verification step, and its permissions, cookie-handling capability, and removal history are each individually consistent with dual-use design.
Underground Pricing - What Accounts Sell For
Pricing reflects criminal utility, not face value. Age, spend history, verification status and daily limits matter more than residual ad credit. Zscaler’s 2023 analysis of Vietnamese-language underground markets linked to DuckTail found low-grade accounts at roughly $15, and higher-value accounts around $340. Price driven by BM vs. personal ads access, budget/threshold, verification, and prior successful payments. Surface markets observed in 2026 still sit in a similar band for many Meta BM listings, while specialized Google Ads inventory for high-risk verticals has been listed higher (around $200–$270 in one Telegram sale channel). Exact prices vary by channel, niche, and warranty terms.
Law Enforcement Response - Arrests, Whack-a-Mole, and the New Law
Vietnam sits at the center of this ecosystem. The government has been active, but the pattern of arrests followed by ecosystem regeneration reveals a structural limitation that legal reform alone cannot fix.
|
Date |
Action |
Key Outcome |
|
May 2023 |
Meta publicly attributes DuckTail and NodeStealer to Vietnamese actors. Files civil action for $36M+ in unauthorized ad spend. First major public attribution. |
|
|
Mid-2024 |
20+ individuals arrested for VietCredCare and DuckTail distribution. VietCredCare volume declines post-arrest but DuckTail continues with updated techniques. |
|
|
Jan–Apr 2025 |
26-country operation. 18 suspects arrested in Vietnam. 20,000+ malicious IPs/domains seized. 41 servers taken down. 216,000 victims notified. Evidence of corporate account registration-and-sale scheme seized. |
|
|
6 May 2025 |
23 individuals prosecuted for producing and distributing VietCredCare. Millions of records confirmed stolen across Vietnam and internationally. |
|
|
17 Mar 2026 |
14 prosecuted including a 12th-grade student programmer (15% of criminal profits). 94,000 computers infected globally. Primary target: Facebook accounts with advertising capabilities. |
|
|
27 Mar 2026 |
343 suspects repatriated from Cambodian compound. Facebook, Instagram, WhatsApp, Zalo used. Overlap with ad fraud infrastructure documented. |
|
|
1 Jul 2026 |
Mandates faster content removal, tighter data localization, enhanced AI governance, expanded Ministry of Public Security powers to compel platform cooperation. |
The Expanding Attack Surface - Beyond Meta and Google
The commoditization of ad account theft has made it platform-agnostic. Mimecast detection data and external research show the same tactics, credential phishing, session cookie theft, fake support lures appearing across TikTok, X, and Microsoft's advertising ecosystem, not just the Meta and Google environments where the playbook was first developed.
|
Platform |
Status |
Key Detail |
|
TikTok Business |
Emerging |
Lure themes: "TikTok Business account suspended". |
|
X / Twitter Ads |
Confirmed Active |
Verified X account spreading Mac malware via paid promotion. |
|
LinkedIn / Microsoft Ads |
Rising Risk |
LinkedIn Campaign Manager and Microsoft Advertising. |
|
WhatsApp Business API |
Emerging |
Managed via Meta Business Manager. Compromised BM with WA API access enables mass messaging to existing customer contact lists under a trusted business identity. |
Platform Accountability - The Revenue Problem
When a compromised ad account runs malicious campaigns, the platform earns revenue from every impression served whether the advertiser behind it is legitimate or an attacker spending stolen budget. Meta's own internal estimates, cited in a 2026 class-action complaint by the Consumer Federation of America, put the scale of higher-risk scam advertising at 15 billion impressions per day, generating an annualized $7 billion in platform revenue. The CFA complaint, filed in April 2026, alleges Meta knowingly adopted policies that prioritized that revenue over user safety.
A separate class of advertisers, those on the other side of the transaction, paying for reach that may never have existed has pursued Meta through the courts since 2018. In DZ Reserve v. Meta Platforms, a class of advertisers alleges Meta systematically overstated advertising reach by counting accounts rather than people, inflating costs across millions of campaigns. The Ninth Circuit affirmed the damages class in March 2024, the case is ongoing.
Meta has taken some enforcement action of its own filing suit against scam advertisers in February 2026 and coordinating with law enforcement on Southeast Asian criminal networks in March 2026. These actions have not addressed the structural issue: a compromised account continuing to serve ads while under review still generates platform revenue. Malwarebytes documented the same reported advertiser remaining active after 30 separate reports.
Recommendations for businesses running Meta / Google ad accounts
Immediate (if you suspect compromise)
- Pause all campaigns and screenshot anything unfamiliar (ads, spend, creatives, user list).
- Secure the personal Facebook / Google accounts and the mailbox used for login and billing: change passwords, enable authenticator 2FA (not SMS), review active sessions / devices.
- Remove unknown People and Partners in Business Settings - partners can keep access even after a password change.
- Remove unfamiliar payment methods and cancel / replace cards that may still be charged. Contact the card issuer early.
- Audit connected assets: Pages, Instagram accounts, ad accounts, Pixels / datasets, catalogs, audiences, and apps / system users. Disconnect anything not needed.
- Report it as account compromise to Meta / Google Business Support
Common advice from victim communities and platform guidance
|
Recommendation |
Why it matters |
|
Create a trusted backup admin (2–3 people with full control) |
If one login is locked out or downgraded, someone else can still remove attackers and pause spend. |
|
Monitor unusual spend and new campaigns |
Budgets are often raised suddenly for crypto, gambling, dropshipping, or scam stores. |
|
Use least privilege |
Give staff / freelancers asset-only access, not full BM admin. Revoke leavers the same day. |
|
Isolate high-value access |
Separate personal and business profiles; consider dedicated browser profiles / devices for Ads Manager. |
|
Watch billing alerts on a monitored inbox |
Missed “unusual login / payment” emails cost hours. |
|
Don’t rush to spin up “fresh” sibling ad accounts mid-incident |
Lookalike activity can trigger further platform restriction. |
Ad account theft has evolved into a mature, commodity cybercrime. Meta and Google advertising accounts are systematically compromised because they carry established platform trust, then graded, traded, and repeatedly reused long after victims have cancelled associated payment cards. Analysis of 6.4 million Mimecast detections collected over four years identified the email campaigns that fuel this ecosystem. The primary impact is the loss of account control rather than direct financial theft: fraudulent advertising spend can often be stopped quickly, but recovering ownership and trust is significantly more difficult. Until advertisers manage administrative access, partner relationships, and account activity with the same rigor applied to other high-value digital assets, and platforms provide recovery processes that reflect the value of these accounts, compromised advertising accounts will continue to circulate within the criminal ecosystem.
Keep your edge in threat intelligence
Join thousands of security professionals who rely on our curated alerts, expert analysis, and campaign IOCs to defend against the latest cyber threats.
Sign up successful
Thank you for signing up to receive updates for our threat intelligence notifications.
We will be in touch!