Hi all - I had a wild start to the week today.
What happened:
- One of my PPC specialist’s had their work email account hacked
- The said hacker added themselves as an admin in our Google ads manager account
- They then removed ALL of our legitimate agency team members from the MCC
- 150+ client accounts at risk (Google Ads and LSAs), active campaigns running
- This person has initiated various manual Google ads payments for $50,000…even three for $500,000
Current status:
- I’ve called, chatted and emailed Google support and have case IDs loaded with documentation
- Getting a 24-48 hour resolution estimate just for a response
- Asked clients to freeze their credit cards + block google ads transactions with their banks
- We’ve also: enabled 2FA on all team miners accounts and changed passwords
- Hacker access is solely isolated to Google Ads thus far - no g-drive or access to other documents
Need your input:
- Has anyone dealt with this recently? What expedited your recovery?
- Any direct escalation paths beyond standard support?
- Contact at Google who handles emergency account recovery situations?
- Ways to protect client accounts while locked out of MCC?
- Legal/compliance considerations we should document NOW?
Every minute this person has access increases risk to client data and campaigns. Needless to say, it’s not a fun situation having clients reach out, asking us why they’re seeing attempted charges for 50k from Google Ads.
If you've been through this, or at least know someone at Google who can help escalate and treat this is as truly urgent, I’d really appreciate it your sharing in the comments or shooting me a DM🙏
I’ve already barraged support today and have case IDs, but I’m just trying to work all possible angles to get this resolved ASAP.
Thanks in advance! 🙏