An email, SMS, or WhatsApp note claims your Facebook Ads Manager or Meta Business Suite account has a past-due balance, a “suspended ad account,” or a refund waiting—then pushes a login page, remote-access “billing specialist,” or gift-card payment. Real ad billing lives inside business.facebook.com / Meta Business Suite after you sign in through Meta’s official apps. Same credential-theft pattern as Phishing and account takeover and Fake tech-support refund scams.
Gift-card unlock fees: Gift cards and prepaid debit risks. Consumer fraud overview: Credit and debt scams.
Scripts to expect
| Script | Hook | Goal |
|---|---|---|
| Fake past-due ads invoice | “Ad account disabled in 24 hours—pay $487” | Phished password / payment card on a clone site |
| Spoofed Meta Business support chat | “Share screen to restore Ads Manager” | Remote-access malware; drains connected cards |
| Gift-card “verification” | “Buy Meta / Apple / Google Play cards to unlock billing” | PIN theft; Meta does not collect ad spend that way |
| Fake refund for overcharged ads | “Confirm refund via this portal” | Credential + card harvest (Netflix billing cousins) |
| Compromised Page / partner message | “Your agency needs a new payment method today” | Adds attacker’s card permissions or steers you off Meta |
Meta’s ad support does not demand iTunes, Steam, or grocery gift cards to clear Ads Manager balances.
Red flags
- Links that are not facebook.com, fb.com, or meta.com business properties (extra hyphen domains, “meta-ads-billing” hosts).
- Urgency plus a request to move to WhatsApp, Telegram, or a phone number that only appears in the phishing message.
- Payment by gift card, wire, crypto ATM, or Friends & Family P2P for “ad account reinstatement.”
- Attachments labeled “Invoice_AdsManager.pdf.exe” or password-protected zips from unknown senders.
- Callers who already “know” your Business Manager ID but will not wait while you hang up and sign in through the official app.
Worked example: the past-due Ads Manager invoice
Sam runs a small Shopify store and spends about $300/month on Facebook ads billed to a Capital One business card on file in Meta Business Suite. An email from “meta-billing-support@secure-meta-ads.com” says Account ACT-184229 owes $1,240 and will be permanently disabled in 6 hours. Sam clicks, enters the Business Suite password on a lookalike page, then “updates” the card. Attackers change the payout/payment method and run $2,800 in ads overnight. Sam also bought $200 in Apple gift cards when a follow-up “specialist” claimed that would reverse the suspension.
Recovery path: freeze the Capital One card; revoke sessions and change Meta password from a known-good device; remove unknown admins in Business Settings; dispute unauthorized charges (Disputing a credit card charge); report at ReportFraud.ftc.gov. The gift cards are usually gone.
Safer Ads Manager habits
- Bookmark business.facebook.com (or open Business Suite from the official Facebook/Meta apps)—do not trust cold invoice links.
- Check Billing & payments inside the real Business Suite before you pay anyone who emailed you.
- Keep 2FA on the Meta account that owns the Business Manager; limit admin roles.
- Never “verify” ad billing with gift cards or remote-access tools (AnyDesk, TeamViewer) from an inbound call.
- If you use an agency, confirm payment-method changes out-of-band on a known phone number—not the one in a surprise email.
Named products and institutions in these scripts include Meta Business Suite, Facebook Ads Manager, Instagram ads billing, Capital One / Chase / Amex cards on file, Apple Gift Card, Google Play, and remote-access brands scammers prefer—none of which excuse off-platform “unlock” payments.
If you already clicked or paid
- Change Meta passwords; end other sessions; review Business Settings → People / Partners.
- Call the card issuer on the number on the card; dispute unfamiliar ad charges.
- Scan for remote-access software; uninstall anything you did not install on purpose.
- Document the phishing URL and file FTC / IC3 reports for larger losses.
- Do not pay a second “Meta recovery” cold caller.
Checklist
- Open billing only from bookmarked Meta Business Suite URLs.
- Treat past-due ads emails as phishing until the balance shows in-app.
- Refuse gift-card and remote-access “reinstatement.”
- Audit Business Manager admins after any suspicious login.
- Dispute unauthorized card charges quickly.
- Train anyone with Page admin rights on the same rules.
Google Ads account-suspension and billing phishing uses the same gift-card and clone-login pattern: Fake Google Ads account scams.
Educational only. Not legal, security, or fraud-recovery advice. Meta billing and support flows change; verify balances and tickets only inside official Meta Business tools and with your card issuer.