Stolen Meta Business Manager and Google Ads Accounts Traded as High‑Value Commodity in Cybercrime Market
What Happened — Threat actors are hijacking Meta Business Manager and Google Ads accounts, then selling the compromised accounts on underground forums. Prices range from $15 – $340 for Meta accounts and $200 – $270 for high‑risk Google Ads accounts, reflecting the premium placed on aged accounts with clean spend histories. Over the past four years Mimecast recorded 6.4 million detections, with a surge to 1.86 million in H2 2025 despite major law‑enforcement crackdowns.
Why It Matters for Compliance & Audit Readiness
- Credential compromise of cloud‑based advertising platforms is a classic SOC 2 CC6 (Logical Access) failure; continuous monitoring of privileged account activity is required to prove due diligence.
- The resale market shows that attackers can monetize “trusted” accounts for months, underscoring the need for documented access‑control policies, MFA enforcement, and regular review of privileged‑access logs as audit evidence.
Who Is Affected — Digital‑marketing agencies, e‑commerce brands, SaaS firms, and any organization that runs paid campaigns on Meta or Google platforms.
Recommended Actions —
- Enforce MFA and least‑privilege for all Business Manager and Google Ads admin accounts.
- Implement continuous log‑monitoring and anomaly detection for ad spend spikes.
- Conduct regular access‑review cycles and update security‑awareness training to cover credential‑theft phishing tactics.
Source: Help Net Security
Technical Notes — Attackers use phishing emails that exploit trusted sending infrastructure, then harvest credentials with malware families such as DuckTail, NodeStealer, VietCredCare, and PXA Stealer. Compromised accounts are drained quickly, but the historic spend profile lets the accounts continue serving ads undetected. Source: Help Net Security