Observed Signal · Dec 3, 2025 · Fraud Incident · Source: AdExchanger · Impact: 3/5 · Sentiment: Negative

Ad Buyers Face New Wave of Google Account Takeover Scams

Executive Signal Summary

Ad buyers managing Google Ads and Merchant Center accounts report sophisticated account takeover scams that hijack client accounts, drain funds, and sometimes lock out administrators for weeks. Incidents occurred between August and October, echoing earlier fraud documented by Malwarebytes. Earlier attacks used fraudulent Google Search links and fake sign-in pages, with 2FA prompts coming from outside the US (often Brazil). Newer variants are linked to Gmail-based phishing and other integrations, including suspected Salesforce involvement, with Google warning of related threat activity by Vietnamese actors. Google says it secures compromised accounts, restores advertiser access, and issues credits where appropriate. Agencies describe the attacks as opaque and difficult to attribute, with some reporting multi-million-dollar losses in Merchant Center budgets and partial refunds only via ad credits. The events highlight ongoing risks of account takeover fraud on the Google platform and the challenges of recouping losses while campaigns remain frozen.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Significant industry risk from ongoing ad account takeover fraud affecting advertisers and platform responses (Google) without complete visibility or recourse.

SIGNAL RADAR

Track Salesforce Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Three agency executives reported account takeover incidents affecting Google Ads and Merchant Center between August and October.
  • Earlier attacks used fraudulent Google Search links and fake sign-in pages; 2FA prompts appeared to originate from outside the US, often Brazil.
  • Malwarebytes previously documented related takeover activity in the prior year.
  • Newer takeovers involved Gmail-based phishing and other integrations, with theories including Salesforce integrations; Google warned of related Vietnam-based threat actor activity.
  • Reported losses include multi-million-dollar fraud in Merchant Center budgets for some agencies; refunds are often limited to Google ad credits, with some losses below $1 million for others.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: AdExchanger•Published: Dec 3, 2025
Original Coverage Title: “Google Ad Buyers Are (Still) Being Duped By Sophisticated Account Takeover Scams”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Market IntelligenceOct 7, 2026

From Autonomy to Accountability: How to Think About Trust in the Multi-Agent Future

Salesforce published a new article on trust in multi-agent AI systems, discussing accountability and governance in the multi-agent future.

Read assessment
PlatformOct 6, 2026

Treasure AI Launches Personalization Studio, New Pricing Model

Treasure AI announced Personalization Studio, a marketer-facing UI for building and managing real-time website personalization campaigns. The tool leverages the company's unified customer data and real-time decisioning, part of its Agentic Experience Platform (AEP). Personalization Studio aims to reduce marketers' dependence on technical teams by enabling campaign setup in about 10 minutes. The announcement was made at the Agentic World 2026 conference. Concurrently, Treasure AI introduced an engagement-based pricing model for email, tying costs to customer actions such as clicks rather than message volume. This move reflects a broader industry trend among martech vendors adapting pricing to AI-driven capabilities. Chief Product Officer Rafa Flores highlighted the bet on click-through rates, underscoring confidence in the platform's intelligence.

Read assessment
AI ModelsOct 5, 2026

Reflection AI launches open-weight model Beam at lower compute cost

Reflection AI has launched Beam, its first frontier open-weight AI model, claiming it matches leading Chinese models like GLM-5.2 on reasoning benchmarks while using 3-4x less inference compute. The 501B-parameter MoE model (23B active) was trained on 23.8 trillion tokens and features a 1M token context window. It targets enterprises, public sector, and sovereign nations, with plans for 'AI factories' allowing customization on proprietary data. Reflection has raised ~$4.7B from backers including Nvidia and Sequoia, and signed compute deals worth over $7B (including a $6.3B deal with SpaceX) for Nvidia GB300 chips. Independent analyses place Beam around GLM-5.2 level, below DeepSeek V4 Flash on some benchmarks. Beam's weights (under Apache 2.0) and technical details will be released this month via hyperscalers and neoclouds. Additionally, Mistral released 'Mistral Large 4', a 1 trillion-parameter multimodal model. The article also covers the rise of personal AI assistants like Instinct (raising $1B in Series C) and Meta's Muse, alongside a16z's report on AI app adoption and public safety concerns.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.