Google Ads · Status at source date: Newsletter archive
MCC phishing scam wave targets agency Google Ads accounts
Jeremy Young has flagged a growing wave of phishing attacks targeting agency Google Ads Manager accounts. The scam involves fraudulent audit invites followed by a phishing email mimicking a read-only MCC access invite.

What changed
Young notes the destination link and sender address (an @gmail account) were the tell: the domain referenced pointed to a real website, making the deception more convincing than typical phishing attempts.
Why it matters for advertisers
For you, this means briefing all staff who handle client MCC invites to verify sender domains and destination URLs before accepting any external access request: read-only framing does not reduce the risk if credentials are compromised at the point of acceptance.
Perspective from the original PMC newsletter.Sources & contributor credit
- Newsletter coverage · Paid Media Collective newsletter
Original newsletter text, contributor labels and media for this update.
- Source referenced in newsletterLinkedIn
Linked from the original newsletter. The source publication date has not been independently confirmed.
Original creator unverified
The names below are source credits. The original creator and first-reporting priority have not yet been independently verified.
Attribution evidence and limitations
Full attribution review pending.
A source link alone does not establish original authorship.
Original image and video creators have not yet been verified.
- Published on this site
This update reflects the dated source reporting. Availability may have changed. Further coverage of this same development will be added to this page.
Original newsletter text and archive evidence
MCC phishing scam wave targets agency Google Ads accounts
Jeremy Young has flagged a growing wave of phishing attacks targeting agency Google Ads Manager accounts. The scam involves fraudulent audit invites followed by a phishing email mimicking a read-only MCC access invite. Young notes the destination link and sender address (an @gmail account) were the tell: the domain referenced pointed to a real website, making the deception more convincing than typical phishing attempts.
For you, this means briefing all staff who handle client MCC invites to verify sender domains and destination URLs before accepting any external access request: read-only framing does not reduce the risk if credentials are compromised at the point of acceptance.
Source captured . No explicit first-contributor label was provided for this update.




