We usually write for business owners. This article is for other agencies. Fake "clients" trying to get into our Google Ads manager account come through our contact form so often that we built a filter just to flag them. Most are easy to spot. One recently wasn't: it was good enough to pass most of the checks agencies rely on. If it's hitting our inbox, it's hitting yours, so we're stepping outside our normal lane to share exactly what we saw, how we caught it, and what to lock down before the next one shows up.
Here is the short version. A fake prospect contacts your agency through your website, dangles a large Google Ads budget, and offers you read-only access to their account so you can "take a look before the call." Every version we've seen eventually asks for the same thing: the email address you'd use to accept that access. That address is usually the login that controls your manager account (MCC), and the manager account is the whole point.
Every Version Asks for the Same Email Address
The disguises change. The ask never does.
Sometimes it's blunt. One lead, claiming to be the CEO of a national hotel chain, wrote: "please reply with the email linked to your Google Ads Manager Account (MCC), and we will issue an invite within 24 hours." Others are patient. They trade a few friendly emails first, then ask for "the email address you'd like us to use for the read-only invite." One sent us to a booking page where the form itself asked: "What email address should we use to grant you read-only access to our Google Ads account before our call?"
Notice what that question assumes. Most agencies do audits from the same login they use to run client work, because it's convenient. So when a stranger asks where to send an invite, the natural answer is the most valuable email address in the business.
The read-only access they're offering is not the prize. In some versions there may not even be a real account behind it. The prize is getting you to take an action tied to that login: click an invitation link, sign in on a page you didn't navigate to yourself, open a "brief," or connect an account to your manager account. Each of those is a door. They only need you to walk through one.
Why a Fake Client Wants Your Manager Account
A manager account is a master key. From one login, you can see and change every client account under it: the campaigns, the budgets, and in many cases the billing. Someone who gets into it doesn't need to run up spend on one account. They can do it across twenty, with payment methods that belong to your clients, and it can run for days before anyone notices.
That's why agencies are the target instead of individual advertisers. Breaking into one small business's account gets a scammer one budget. Breaking into an agency's MCC gets them a portfolio.
There is a second risk that has nothing to do with passwords. Google's third-party policy holds agencies accountable for what happens in the accounts they manage, and since June 2025 a manager account found in violation can take the client accounts linked to it down with it. So even setting aside theft, you do not want an account run by fraudsters anywhere in your hierarchy.
We wrote about the owner's side of this in Your Ad Account Is Not Yours., which covers how businesses lose access to their ad platforms. This is the agency's side: the account you manage for everyone else is the one worth stealing.
Four Leads, Three Disguises
Here are four of the leads that reached us this year, with enough detail that you'll recognize the pattern when it lands in your inbox.
Disguise One: a Famous Brand on a Look-Alike Domain
In late August, "BISSELL" wrote to say it was "beginning conversations with a select group of agencies" about digital and ecommerce growth, with a starting budget of about $40,000 a month. The email came from bissellglobal.com. BISSELL's real website is bissell.com. The look-alike domain had been registered three days before the message arrived.
In September, "Chuck Drury, CEO" of Drury Hotels wrote from dururyhotel.com (note the extra "u"), dangling a search for an agency to run marketing across "150+ U.S. properties" and offering read-only access to the live account in exchange for the email tied to our MCC. That domain was 17 days old.
These are the easy ones. The brand is famous, the domain is a near miss, and a registration lookup takes ten seconds. They still work often enough to keep being sent, because a big name and a big number do something to your judgment when a sales pipeline is thin.
Disguise Two: a Made-Up Company on a Brand-New Domain
In April, a lead named "Olivia" came in through our form claiming over $50,000 a month in ad spend. When we asked for more detail, the reply was polished and specific: a compliance software company, roughly $500,000 a month across Search, Performance Max and YouTube, HubSpot integration, offline conversion imports already in place. The proposed next steps were sensible too: they'd grant read-only access, we'd review the account, then we'd get on a call to talk about pricing.
We replied with the email we use for account reviews. That's worth admitting, because it's exactly what a busy agency owner does with a lead that sounds this good. The invite never came. Instead came a nudge to get on a call.
Looking back, the tells were sitting in the very first message. The phone number on the form was (415) 555-2938, and 555 is the prefix movies use for made-up numbers. The domain had been registered seven days before the lead arrived. A company spending half a million dollars a month does not run its advertising from a week-old website.
Disguise Three: a Real Startup's Old Domain, Taken Over
This is the one that made us write the article.
In September, a collaboration software startup reached out through our form. It said it was a B2B SaaS company in the communication space looking for an experienced Google Ads agency. Two weeks later, a second person from the same company sent almost the same message, word for word in places. When we replied, the first contact said their Business Development Director would lead the conversation and sent us to that director's booking page. The booking form asked where to send read-only access.
Every quick check passed. The domain was over a decade old, not days. The website looked like a real product, with a features page, a blog, integrations and a login screen. The "Business Development Director" had a LinkedIn profile listing the company. Email ran on Google Workspace, and the booking link was a genuine Google Calendar page.
We are not naming the company, and that's deliberate. It was a real startup once, and the people who built it are still out there. What appears to have happened is that the business went quiet, its domain was re-registered in October 2024, and the old website was kept running because years of history make it look trustworthy. A new "team" was then added with LinkedIn profiles to match.
The Standard Checklist Catches Three of Them
When this scam drew wide attention in April, PPC Land reported on an agency founder who nearly fell for it, along with a thread full of agency owners who had received the same messages. The checks shared there are good, and you should run them on every inbound lead that mentions account access:
- Look at the sender's domain. Is it the company's real domain, or a near miss? Where does it go when you type it into a browser?
- Look up the domain's registration date. A free whois lookup shows when a domain was created. Fraud domains are usually days or weeks old.
- Find the person on LinkedIn. A marketing contact at a real company almost always has a profile.
- Compare what they tell you with what you can see. Their website, their ads, their public footprint.
- When in doubt, contact the real company through a channel you find yourself.
Run those against our four leads and the first three fall apart. BISSELL and Drury fail the domain check immediately. The compliance company fails on domain age and that 555 number.
The fourth lead passes every one. The domain is old, the person is on LinkedIn, and there's no famous brand to call. The standard checklist was built for scammers in a hurry. This one wasn't in a hurry.
The Checks That Catch the Fourth
What finally exposed the startup lead were five checks that take a few minutes each and aren't on most agencies' lists.
1. Read their About page in the Wayback Machine. Go to the Internet Archive's Wayback Machine at web.archive.org, paste in the company's About or Team page, and open captures from a few different years. The startup's About page showed the same six-person founding team in every capture from 2016 through September 2025. Today it shows an entirely different team, including the people who contacted us. Real companies change staff; they don't replace an entire team overnight while keeping the same website word for word. This was the single most convincing check.
2. Search Google's Ads Transparency Center. Go to adstransparency.google.com, search the company's domain, and set the date range to any time. A company asking an agency to improve "our current Google Ads activity" should have ads on record. This one had zero, ever. That's the entire premise of the lead contradicted by Google's own records, and it takes thirty seconds to check.
3. Try the product. Click "Get started" or "Sign up." A real software company lets you create an account. The startup's "free" signup was a lead form asking for your company, role and team size so they could "get your free account ready." A front has no back.
4. Search your inbox for the same pitch. Scam operations send the same script under different names. The startup came in twice, from two "employees," two weeks apart, with the same core sentence. The second person wasn't even on the company's new team page. If your form tool keeps a history, search for a distinctive phrase from the message and see what else turns up.
5. Check whether the details agree with each other. The two startup inquiries were submitted from New York and Arizona. The company phone number had a Nebraska area code. The compliance company used a 555 number. Any one of these can have an innocent explanation. When nothing lines up, it's not a coincidence.
None of these checks require special tools, and none of them are accusations. You're not calling anyone a fraud. You're just confirming the company is what it says it is before you hand over the keys to your clients' accounts.
Lock Down Your MCC Before the Next One Arrives
Spotting fake leads helps. Making sure a mistake can't cost you your manager account helps more. Here's what we'd do this week, starting with the change that matters most.
1. Stop using your MCC login for audits. Create a separate Google account that exists only to accept read-only access from prospects. Put it on your own domain, something like audits@youragency.com, so it looks professional and still works with clients whose accounts only allow business email addresses. Give it no access to your manager account or any client account. When a prospect asks where to send an invite, that's the address you give. If the prospect turns out to be a scammer, the worst they can reach is an account that controls nothing. This one change removes most of the risk in this article.
2. Put passkeys or security keys on every admin login. A stolen password is useless without the second factor, and a passkey or hardware security key only works on Google's real sign-in page, so a fake login page can't capture it. For the logins that own your MCC, consider Google's Advanced Protection Program, which requires a passkey or security key to sign in, limits which outside apps can access your account data, and tightens account recovery. Text-message codes are better than nothing, but they're the weakest option because a phone number can be hijacked.
3. Only sign in on pages you navigated to yourself. If an email says someone has invited you to their Google Ads account, check that it came from Google and that the link points to ads.google.com. If anything about it feels off, don't click it. A real invitation will still be there after you've run the checks above. And never type your Google password on a page whose address doesn't start with accounts.google.com.
4. Never link a prospect's account into your manager account. Reviewing an account doesn't require linking it. Linking should happen after a signed agreement, a verified client and a real kickoff call, not before.
5. Know how multi-party approval protects you, and when it doesn't. Google Ads now has multi-party approval, which requires a second administrator to approve sensitive changes like adding users, changing roles, or linking an outside account into your MCC. Google turns it on automatically, but only for accounts with more than three administrators. Below that, one compromised admin login can add users with nobody else signing off. So keep your admin list short and trusted, and check Admin, then Access and security, including the Security requests tab, for anything you did not start.
6. Don't open their files or install their software. A "brief," a "media plan," a "meeting app." If the call can't happen on a platform you already use, it doesn't need to happen.
7. If you've already sent the email, check rather than panic. Change the password on that login, review your Google account's recent security activity, and look at the Users list under Access and security in your manager account for anyone you don't recognize. In your Google account settings, remove any third-party apps you don't recognize from the list of apps with access. Then mark the lead's emails as spam so your filters learn the pattern. If you see changes you didn't make, Google has a dedicated process for compromised Google Ads accounts in its help center.
8. Tell everyone who answers your contact form. The first person to see one of these leads is often not the person who owns the MCC. Share the checks above with whoever handles new inquiries, and agree on one rule: no one sends a login email to a prospect until someone has run them.
The Real Prospects Are Still Out There
None of this should make you suspicious of every lead. Real businesses still fill out contact forms, and some of them really do spend serious money on Google Ads. The goal isn't to stop replying. It's to keep your most valuable login out of the conversation until you know who you're talking to. Five minutes of checking is cheap. Explaining to twenty clients why their accounts were drained is not.
If you run an agency and any of this hit a little close to home, we'd genuinely like to hear from you. BrandRocket works with other agencies behind the scenes, handling white-label Google Ads management for teams who want an extra set of experienced hands without adding headcount, and quietly supporting agencies whose clients need more than their team can cover. We'd rather build a community of agencies doing outstanding work than compete with one. If that sounds useful, reach out. We're real, and we're happy to prove it.




