An email, SMS, or WhatsApp note claims your Google Ads account has a past-due balance, a “suspended ad account,” or a refund waiting—then pushes a login page, remote-access “billing specialist,” or gift-card payment. Real ad billing lives inside ads.google.com after you sign in through Google’s official apps. Same credential-theft pattern as Phishing and account takeover and Fake Facebook Ads Manager scams. Remote-access “refund desks”: Fake tech-support refund scams.
Gift-card unlock fees: Gift cards and prepaid debit risks. Consumer fraud overview: Credit and debt scams.
Scripts to expect
| Script | Hook | Goal |
|---|---|---|
| Fake past-due Google Ads invoice | “Ad account disabled in 24 hours—pay $612” | Phished password / payment card on a clone site |
| Spoofed Google Ads support chat | “Share screen to restore billing” | Remote-access malware; drains connected cards |
| Gift-card “verification” | “Buy Google Play / Apple cards to unlock Ads” | PIN theft; Google does not collect ad spend that way |
| Fake refund for overcharged ads | “Confirm refund via this portal” | Credential + card harvest |
| Compromised MCC / partner message | “Your agency needs a new payment method today” | Adds attacker’s billing permissions or steers you off Google |
Google Ads support does not demand iTunes, Steam, grocery gift cards, or crypto ATMs to clear an Ads balance.
Red flags
- Links that are not ads.google.com, pay.google.com, or other google.com properties (extra hyphen domains, “google-ads-billing” hosts).
- Urgency plus a request to move to WhatsApp, Telegram, or a phone number that only appears in the phishing message.
- Payment by gift card, wire, crypto ATM, or Friends & Family P2P for “ad account reinstatement.”
- Attachments labeled “Invoice_GoogleAds.pdf.exe” or password-protected zips from unknown senders.
- Callers who already “know” your customer ID but will not wait while you hang up and sign in through the official app.
Worked example: the past-due Ads invoice
Sam runs a small Shopify store and spends about $400/month on Google Ads billed to a Chase Ink card on file in ads.google.com. An email from “ads-billing@secure-google-ads-pay.com” says Customer ID 389-441-2207 owes $1,480 and will be permanently disabled in 6 hours. Sam clicks, enters the Google password on a lookalike page, then “updates” the card. Attackers change the payment method and run $3,100 in ads overnight. Sam also bought $250 in Google Play cards when a follow-up “specialist” claimed that would reverse the suspension.
Recovery path: freeze the Chase card; revoke sessions and change the Google password from a known-good device; review users and billing in the real Ads account; dispute unauthorized charges (Disputing a credit card charge); report at ReportFraud.ftc.gov. The gift cards are usually gone.
Safer Google Ads habits
- Bookmark ads.google.com—do not trust cold invoice links.
- Check Billing inside the real Ads account before you pay anyone who emailed you.
- Keep 2FA on the Google account that owns the Ads login; limit admin and billing roles on the MCC.
- Never “verify” ad billing with gift cards or remote-access tools (AnyDesk, TeamViewer) from an inbound call.
- If you use an agency, confirm payment-method changes out-of-band on a known phone number—not the one in a surprise email.
Named products and institutions in these scripts include Google Ads, Google Pay, YouTube ads billing, Chase / Capital One / Amex cards on file, Apple Gift Card, Google Play, and remote-access brands scammers prefer—none of which excuse off-platform “unlock” payments.
If you already clicked or paid
- Change Google passwords; end other sessions; review Ads users, managers, and payment methods.
- Call the card issuer on the number on the card; dispute unfamiliar ad charges.
- Scan for remote-access software; uninstall anything you did not install on purpose.
- Document the phishing URL and file FTC / IC3 reports for larger losses.
- Do not pay a second “Google Ads recovery” cold caller.
Checklist
- Open billing only from bookmarked ads.google.com URLs.
- Treat past-due ads emails as phishing until the balance shows in-account.
- Refuse gift-card and remote-access “reinstatement.”
- Audit Ads users and MCC links after any suspicious login.
- Dispute unauthorized card charges quickly.
- Train anyone with billing access on the same rules.
Educational only. Not legal, security, or fraud-recovery advice. Google Ads billing and support flows change; verify balances and tickets only inside official Google Ads tools and with your card issuer.