Stolen Meta and Google Ad Accounts Hold Greater Value Than Just Money
Stolen Meta and Google ad accounts have become a lucrative asset in the cybercrime market, with their value extending beyond the funds they hold.
The Structured Cybercriminal Economy of Ad Account Theft
Ad account theft, involving the unauthorized takeover of Meta Business Manager and Google Ads accounts, has evolved into a structured cybercriminal economy featuring tiered pricing models, escrow services, and guarantees for compromised accounts.
Temporary Gains vs. Long-Term Value
While media coverage often highlights drained ad budgets, research from Mimecast reveals that this is typically a temporary gain for attackers. Both platforms operate on a pre-loaded credit system, allowing campaigns to run continuously until a budget limit is reached or the account holder intervenes. A compromised account with a $5,000 monthly budget can be depleted within hours, according to the firm.
The Long-Term Value of Stolen Accounts
The long-term value of stolen accounts lies in their historical data. Legitimate ad spend history increases an account’s trust score, enabling it to bypass platform safety checks that would block newly created attacker accounts. This makes older, high-activity accounts significantly more valuable, with Mimecast noting a 2 to 4 times price premium for accounts with established histories.
Pricing Models and Market Trends
Factors such as account age, spending patterns, verification status, and daily spending limits influence pricing. Zscaler reported Meta Business Manager accounts being sold for $15 to $340, while high-risk Google Ads accounts in sectors like finance or healthcare have fetched $200 to $270 on Telegram.
Surge in Detections and Enforcement Cycles
Mimecast’s Threat Research Team has tracked 6.4 million detections of Meta and Google ad account theft over four years, with the second half of 2025 recording 1.86 million incidents—a record high. This spike occurred after significant law enforcement actions targeting the ecosystem. The pattern shows that takedowns and arrests temporarily reduce activity, but threat levels often rebound to previous or higher levels.
Linkages to Malware and Global Operations
Mimecast identified Vietnamese-linked malware families, including DuckTail, NodeStealer, VietCredCare, and PXA Stealer, as key players in these attacks. Separate operations were traced to Brazil, Portugal, China, and Hong Kong. The dismantling of the PXA Stealer group in March 2026, which led to 14 arrests, caused a temporary decline in detections before activity resumed.
Phishing Campaigns and Trusted Infrastructure
Researchers analyzed how these attacks reach inboxes, revealing a shift toward leveraging legitimate, high-reputation platforms to evade detection. Instead of using malicious infrastructure, attackers exploit trusted services like Salesforce, Google Workspace, and SharePoint. Mimecast found that one-third of detections arrived via Salesforce, while 25% used Google Workspace mail-merge tools or SharePoint-hosted links.
Recovery Challenges and Platform Incentives
Reclaiming control of a compromised account is far more complex than stopping fraudulent spending. Attackers often add themselves as administrators and restrict the original owner’s access, a process that platform permission systems may not reverse. Reclaiming ownership can take months, with accounts frequently locked in appeal processes.
Financial Incentives for Platforms
Mimecast noted that platforms continue to profit from compromised accounts, as they earn revenue from every ad impression served, regardless of the advertiser’s legitimacy. A 2026 class-action lawsuit by the Consumer Federation of America cited Meta’s estimates of 15 billion daily scam ad impressions, generating $7 billion in annual revenue.
Ongoing Risks and Security Recommendations
Mimecast emphasized that compromised ad accounts will persist in criminal markets unless businesses adopt stricter administrative controls and platforms refine recovery processes. The firm highlighted the need for aligning security practices with the value of these accounts, which remain a critical target for cybercriminals.
The Future of Cybercrime in Digital Advertising
Cybercrime continues to exploit vulnerabilities in digital advertising ecosystems, with stolen accounts serving as both financial tools and vectors for broader malicious activity. The interplay between platform economics, attacker tactics, and enforcement efforts underscores the complexity of addressing this evolving threat.
