Google Ads Phishing Scams Targeting Agencies — How to Protect Your Accounts in 2026
Agencies running Google Ads are being hit with sophisticated phishing scams impersonating Google representatives. MediaPost and Google's fraud advisory confirm the attacks. Here's how to spot them, protect your accounts, and what Google is doing about it.
Key Takeaways
- In June 2026, MediaPost reported that “Agencies Using Google Ads Hit With Phishing Scams” — a coordinated campaign targeting…
- The attack follows a consistent pattern, according to reports from affected agencies:
- Google’s July 15 passkey mandate is the strongest defense, but agencies should act now:
The short version
Agencies managing Google Ads accounts are being actively targeted by sophisticated phishing scams that impersonate Google representatives, as confirmed by MediaPost and Google’s own fraud advisory. Attackers use fake login portals, urgent account-suspension threats, and even phone calls to steal credentials. Once inside an agency’s Google Ads account, scammers drain ad budgets by running fraudulent campaigns. Starting July 15, 2026, Google will require passkeys for sensitive account actions — a direct response to this wave of attacks.
Key facts
- Agencies are the primary target of mid-2026 Google Ads phishing scams
- Attackers impersonate Google reps via email, phone, and fake login pages
- Scammers drain ad budgets once they gain account access
- Google requires passkeys for sensitive actions starting July 15, 2026
- Scammers have stolen up to $400K through fake ads, per TradingView reports
What happened
In June 2026, MediaPost reported that “Agencies Using Google Ads Hit With Phishing Scams” — a coordinated campaign targeting the very professionals who manage Google Ads for clients. The attacks are more sophisticated than generic phishing: scammers research the agency, reference real client account names, and use personalized email templates that mimic Google’s official communication style.
Google’s fraud and scams advisory confirmed the uptick, publishing updated guidance for advertisers. PPC Land separately reported that starting July 15, 2026, Google will require passkeys — biometric or device-based authentication — for all sensitive account actions, replacing passwords for high-risk operations like changing billing details, adding users, or modifying security settings.
The urgency is real. TradingView documented a case where scammers made $400,000 through fake Uniswap ads on Google, illustrating that the platform’s ad infrastructure is being actively exploited by financially motivated attackers. Reader’s Digest warned readers about a particularly convincing “Google scam that looks totally legit,” while Mashable and Cybernews both confirmed that Google is facing EU complaints over scam ad protections.
How the phishing scam works
The attack follows a consistent pattern, according to reports from affected agencies:
-
Initial contact — an email or phone call claiming to be from “Google Ads Support” or a “Google Account Strategist,” often referencing a real campaign name or client account to build credibility.
-
Urgency trigger — the message claims there’s a policy violation, billing issue, or account suspension that requires immediate action.
-
Fake login portal — the victim is directed to a page that looks exactly like the Google Ads login screen but is hosted on a lookalike domain (e.g.,
google-ads-support.comorads-google-verify.net). -
Credential theft — once the victim enters their email and password, the attacker captures both. If two-factor authentication is enabled, the fake portal may also prompt for the 2FA code in real time (a technique called “2FA relay”).
-
Account takeover — the attacker logs in, adds themselves as a user, removes the legitimate owner, and begins running their own campaigns — often for cryptocurrency scams, counterfeit goods, or phishing sites — using the victim’s ad budget.
The most dangerous variant: attackers who gain MCC (My Client Center) access can compromise every client account under that agency in minutes.
How to protect your agency
Google’s July 15 passkey mandate is the strongest defense, but agencies should act now:
-
Enable passkeys immediately — don’t wait for the July 15 requirement. Go to Google Account → Security → Passkeys and register your device. Passkeys are phishing-resistant because there’s no password to steal.
-
Verify every Google call — legitimate Google reps will never ask for your password or direct you to a login page via email. If you receive a suspicious call, hang up and contact Google through the official Ads support channel.
-
Audit MCC user access — remove former employees, limit admin privileges to essential personnel, and enable login auditing in Google Workspace if your agency uses it.
-
Check connected apps — go to Google Account → Security → Third-party apps and remove anything you don’t recognize. Attackers often maintain persistent access through authorized apps.
-
Monitor billing alerts — set up real-time budget alerts and billing change notifications. A sudden budget increase or payment method change is the most common signal of account takeover.
What this means (our take)
The wave of phishing attacks targeting agencies isn’t random — it’s an acknowledgment by attackers that agencies are the weak point in Google Ads security. A single compromised agency account can unlock dozens of client accounts, multiplying the attack’s payout.
Google’s July 15 passkey requirement is the right response, but it won’t stop all attacks. Phishing scammers will adapt — expect social engineering attacks (phone-based) to increase as email phishing becomes harder. The agencies that protect themselves now are the ones that treat security as part of their service delivery, not an IT afterthought.
Related: For agencies managing client accounts at scale, automation is both a risk amplifier (if compromised) and a defense layer (if monitored correctly). See our guide on Google Ads Scripts automation for script-based monitoring patterns.
What to do now
- Register passkeys today — Google Account → Security → Passkeys. Takes 2 minutes.
- Notify your team — share this article or Google’s fraud advisory with every person who has Google Ads access.
- Enable login alerts — Google sends an email for every new device login. Make sure these go to a monitored inbox, not a personal email no one checks.
- Create an incident response plan — if an account is compromised, you need to know: who do you call at Google, how do you freeze the account, and how do you notify affected clients within the first hour.
FAQ
Q: How can I tell if an email from “Google Ads” is real or fake?
Check the sender’s email domain — legitimate Google emails come from @google.com, not @google-ads-support.com or similar lookalikes. Hover over any links before clicking — they should point to ads.google.com or support.google.com. When in doubt, open a new browser tab and navigate to Google Ads directly rather than clicking through an email.
Q: Will passkeys completely stop Google Ads phishing? Passkeys will stop credential-theft phishing — the most common type — because there’s no password to steal. However, they won’t stop social engineering attacks where scammers convince victims to grant them account access voluntarily or install remote-access software. Security awareness training remains critical.
Q: What should I do if my Google Ads account has been compromised? Contact Google Ads support immediately through the official help center (not through any emails or phone numbers the attacker provided). Freeze all campaigns. Remove unauthorized users. Check billing for fraudulent charges. Then audit every connected app and API key.
Sources
- MediaPost — Agencies Using Google Ads Hit With Phishing Scams (June 16, 2026)
- blog.google — Our latest fraud and scams advisory (June 2026)
- PPC Land — Google Ads will require passkeys for sensitive actions from July 15 (June 2026)
- TradingView — Scammers make $400K through fake Uniswap ads on Google (June 2026)
- Reader’s Digest — Warning! This New Google Scam Looks Totally Legit (June 2026)
Frequently Asked Questions
Is this strategy suitable for small budgets?
Yes. Most of the tactics on this page work at any budget level from $500/month upward. The key is focusing on the highest-intent keywords and thorough negative keyword management. Start small, prove ROI, then scale.
Where can I learn more about AI-managed Google Ads?
Our free Google Ads Expert skill at roa-marketing.com/skills/google-ads-expert/ covers every PPC workflow in detail. It updates daily from live campaign data and is designed for AI agent consumption.