VYPR
researchPublished Jul 29, 2026· 1 source

Underground Market Thrives on Stolen Meta and Google Ad Accounts

A sophisticated cybercrime economy has emerged around the theft and resale of Meta Business Manager and Google Ads accounts, with attackers profiting from account sales rather than just draining ad budgets.

A burgeoning underground market is actively trading in compromised Meta Business Manager and Google Ads accounts, transforming account theft into a lucrative, commodity-driven cybercrime enterprise. This illicit economy features tiered pricing, escrow services, and even money-back guarantees, indicating a high degree of organization among threat actors.

While public attention often focuses on the immediate financial drain of ad budgets from compromised accounts, Mimecast researchers highlight that this is frequently a secondary or short-term objective for attackers. The primary profit often comes from reselling the accounts themselves. Platforms like Meta and Google typically operate on a pre-loaded credit or card-on-file system. Attackers can quickly deplete an account's available budget, sometimes within hours, before the legitimate owner intervenes or a cap is reached.

The true value in the underground market, however, lies in the account's history and reputation. Accounts with a long history of legitimate ad spending are more trusted by platform algorithms. This established trust score allows compromised accounts to serve ads that might otherwise be flagged as suspicious or rejected by platform safety checks. Consequently, older accounts with significant spending history command a premium, often selling for two to four times the price of newly compromised or created accounts.

Pricing for these stolen accounts is determined by several factors, including age, verification status, daily spending limits, and crucially, the ad spend history. Zscaler reports indicate that stolen Meta Business Manager accounts can fetch prices ranging from approximately $15 to $340. Similarly, some Google Ads accounts, particularly those in high-risk sectors, have been observed selling for $200 to $270 on platforms like Telegram.

Mimecast's Threat Research Team has tracked over 6.4 million detections of Meta Business Manager and Google Ads account theft over a four-year period. Alarmingly, the second half of 2025 saw a new high of approximately 1.86 million detections, occurring even after significant enforcement actions against these criminal networks. This pattern suggests that takedowns and arrests provide only temporary dips in activity before the volume rebounds to previous or even higher levels.

These campaigns are often linked to malware families originating from Vietnam, such as DuckTail, NodeStealer, VietCredCare, and PXA Stealer. However, similar operations have also been traced to threat actors in Brazil, Portugal, China, and Hong Kong. The dismantling of a PXA Stealer ring in March 2026, resulting in 14 prosecutions, led to a temporary decrease in detections, but activity soon began to recover.

Attackers are increasingly sophisticated in their delivery methods, moving beyond basic phishing templates. They are abusing legitimate, high-reputation sending infrastructure from trusted platforms like Salesforce and Google Workspace. By using these established services, threat actors ensure their malicious emails bypass reputation-based filtering, as the sending IP, domain, and authentication records (SPF, DKIM) all pass standard security checks. The attacker's primary focus then shifts to crafting convincing content to trick the recipient.

The long-term consequences of account theft extend far beyond the immediate financial loss from drained ad budgets. Reclaiming a compromised account can be a lengthy and arduous process. Attackers often add their own administrators and downgrade the legitimate owner's access, making recovery difficult. Platform permission structures can hinder the legitimate owner's ability to reverse these changes. Months can pass during appeals and reviews, all while the account might remain locked or under scrutiny. Unlike credit card fraud, where chargeback and zero-liability protections exist, ad platforms offer limited recourse, and their financial models can even incentivize continued ad serving, regardless of the legitimacy of the advertiser.

Synthesized by Vypr AI