Skip to main content
My Consumer Finance

Fake Google Ads account, billing, and suspension phishing scams

Fake Google Ads account, billing, and suspension phishing: cloned invoices, gift-card unlock fees, and how to verify charges in the real Ads account.

An email, SMS, or WhatsApp note claims your Google Ads account has a past-due balance, a “suspended ad account,” or a refund waiting—then pushes a login page, remote-access “billing specialist,” or gift-card payment. Real ad billing lives inside ads.google.com after you sign in through Google’s official apps. Same credential-theft pattern as Phishing and account takeover and Fake Facebook Ads Manager scams. Remote-access “refund desks”: Fake tech-support refund scams.

Gift-card unlock fees: Gift cards and prepaid debit risks. Consumer fraud overview: Credit and debt scams.

Scripts to expect

ScriptHookGoal
Fake past-due Google Ads invoice“Ad account disabled in 24 hours—pay $612”Phished password / payment card on a clone site
Spoofed Google Ads support chat“Share screen to restore billing”Remote-access malware; drains connected cards
Gift-card “verification”“Buy Google Play / Apple cards to unlock Ads”PIN theft; Google does not collect ad spend that way
Fake refund for overcharged ads“Confirm refund via this portal”Credential + card harvest
Compromised MCC / partner message“Your agency needs a new payment method today”Adds attacker’s billing permissions or steers you off Google

Google Ads support does not demand iTunes, Steam, grocery gift cards, or crypto ATMs to clear an Ads balance.

Red flags

  • Links that are not ads.google.com, pay.google.com, or other google.com properties (extra hyphen domains, “google-ads-billing” hosts).
  • Urgency plus a request to move to WhatsApp, Telegram, or a phone number that only appears in the phishing message.
  • Payment by gift card, wire, crypto ATM, or Friends & Family P2P for “ad account reinstatement.”
  • Attachments labeled “Invoice_GoogleAds.pdf.exe” or password-protected zips from unknown senders.
  • Callers who already “know” your customer ID but will not wait while you hang up and sign in through the official app.

Worked example: the past-due Ads invoice

Sam runs a small Shopify store and spends about $400/month on Google Ads billed to a Chase Ink card on file in ads.google.com. An email from “ads-billing@secure-google-ads-pay.com” says Customer ID 389-441-2207 owes $1,480 and will be permanently disabled in 6 hours. Sam clicks, enters the Google password on a lookalike page, then “updates” the card. Attackers change the payment method and run $3,100 in ads overnight. Sam also bought $250 in Google Play cards when a follow-up “specialist” claimed that would reverse the suspension.

Recovery path: freeze the Chase card; revoke sessions and change the Google password from a known-good device; review users and billing in the real Ads account; dispute unauthorized charges (Disputing a credit card charge); report at ReportFraud.ftc.gov. The gift cards are usually gone.

Safer Google Ads habits

  1. Bookmark ads.google.com—do not trust cold invoice links.
  2. Check Billing inside the real Ads account before you pay anyone who emailed you.
  3. Keep 2FA on the Google account that owns the Ads login; limit admin and billing roles on the MCC.
  4. Never “verify” ad billing with gift cards or remote-access tools (AnyDesk, TeamViewer) from an inbound call.
  5. If you use an agency, confirm payment-method changes out-of-band on a known phone number—not the one in a surprise email.

Named products and institutions in these scripts include Google Ads, Google Pay, YouTube ads billing, Chase / Capital One / Amex cards on file, Apple Gift Card, Google Play, and remote-access brands scammers prefer—none of which excuse off-platform “unlock” payments.

If you already clicked or paid

  1. Change Google passwords; end other sessions; review Ads users, managers, and payment methods.
  2. Call the card issuer on the number on the card; dispute unfamiliar ad charges.
  3. Scan for remote-access software; uninstall anything you did not install on purpose.
  4. Document the phishing URL and file FTC / IC3 reports for larger losses.
  5. Do not pay a second “Google Ads recovery” cold caller.

Checklist

  1. Open billing only from bookmarked ads.google.com URLs.
  2. Treat past-due ads emails as phishing until the balance shows in-account.
  3. Refuse gift-card and remote-access “reinstatement.”
  4. Audit Ads users and MCC links after any suspicious login.
  5. Dispute unauthorized card charges quickly.
  6. Train anyone with billing access on the same rules.

Educational only. Not legal, security, or fraud-recovery advice. Google Ads billing and support flows change; verify balances and tickets only inside official Google Ads tools and with your card issuer.