A Client's Meta Ad Account Was Hacked This Week, Here's Exactly How It Happened

Earlier this week, a client called us in a panic. Their Meta ad account had been spending money on a campaign they never set up, and roughly $300 had already gone out the door. This post is a walkthrough of exactly what we found, because the scam behind it is currently doing the rounds and it is far more convincing than the phishing emails you're used to ignoring.

What We Found When We Investigated

We logged into the client's Meta Business Suite and, at first glance, nothing looked wrong. No suspicious login locations, no password changes, no obvious red flags on the surface. The account itself hadn't been "broken into" in the way most people picture a hack.

The real answer was sitting in Business Settings, under account access and the business history settings. There, we found that the business owner had granted access to an entity along the lines of "AI Strategic Partner," a bot-style business account with no real history, sitting alongside the client's actual staff and agency access. Neither the owner nor anyone on their team had knowingly added it.

We then checked the client's email inbox for anything from Meta around the time the access was granted. Sure enough, there it was: an email that looked exactly like a genuine Meta Business Manager partner request notification. Correct logo, correct layout, correct sender pattern. The owner had clicked through, believing it was a legitimate offer from an AI ads company promising to run and optimise their campaigns for them. That single click was enough to hand over access to the ad account, and from there, the attacker quietly launched their own campaign funded by the client's card.

Why This One Is So Convincing

This isn't a generic "your account has been suspended" email with bad spelling and a dodgy link. This particular scam has been actively tracked since around April 2026, and security researchers have documented it hitting business inboxes globally under names like "Agency Partner Invoice Program" and, in some versions, a bot account literally called "AI Strategic Partner" carrying Meta's own corporate branding.

The reason it slips past people (and often past spam filters too) is that the notification is a genuine email, sent from Meta's real infrastructure. Attackers aren't spoofing Meta's email address. They're abusing a legitimate feature: Meta's Business Manager Partner Request system. The attacker creates the request, Meta's own servers send the notification, and the email arrives looking exactly like every other legitimate partner or agency access request a business owner has clicked "Accept" on before.

Click through, and the "View request" or "Accept" button takes you to a credential harvesting page dressed up as Meta's Agency Partner Program, often on a freshly registered lookalike domain. Once you're through, the attacker doesn't need your password. Approving the partner request itself hands over direct access to your ad account, Page, pixel, and payment method, no login theft required.

From there, attackers typically do one of two things: quietly launch scam or malvertising campaigns funded by your card (as happened to our client), or lock out the legitimate admins entirely and hold the business portfolio to ransom. Several US state attorneys general have written to Meta this year specifically about the scale of these account takeovers, which gives you a sense of how widespread the problem has become.

How to Check If Your Ad Account Has Been Compromised

This takes about five minutes and every business running Meta ads should do it today, whether or not anything looks wrong:

  1. Open Meta Business Suite and go to Business Settings.

  2. Click into "Partners" or "Business assets" and review every partner and person with access as well as business activity history. Look for anything you don't recognise, especially generic or "AI" sounding business names with no history.

  3. Check "People" access as well as "Partners". Both can be used to gain a foothold.

  4. Review recent ad campaigns and ad spend for anything you didn't create.

  5. Check your linked email inbox for any "Business Manager partner request" emails you don't remember actioning, and note the date, since that tells you roughly when access may have been granted.

  6. Remove any access you can't personally account for, then change your Facebook password and turn on two factor authentication if it isn't already on.

If you find unauthorised spend, report it to Meta Business Support immediately and ask your bank or card provider about a chargeback, since Meta's own refund process for this kind of fraud can be slow.

How to Protect Your Ad Account Going Forward

The uncomfortable truth is that this scam works because it targets a genuine Meta feature that most business owners rarely think about, let alone audit. A few habits make a real difference:

Treat every "partner request" email as suspicious by default, even when it looks completely legitimate. Legitimate agencies (including us) will always tell you directly, in person or by phone or an established channel, before sending any access request. If an unsolicited email promises to run your ads for free or for a suspiciously low cost, that urgency and generosity is the tell.

Audit your Business Settings partner and people list monthly, not just when something goes wrong. It takes five minutes and it's the single most effective habit here.

Limit who has admin level access, and use the most restrictive role that still lets each person or partner do their job.

Turn on two factor authentication on the Facebook account tied to your Business Manager, and make sure whoever owns that login isn't sharing it loosely across the team.

Set a spend alert or daily budget cap on your ad account so any unauthorised campaign is capped in dollars, not left to run until someone notices.

The Takeaway

Our client's story has a relatively good ending: caught within days, spend capped at $300, and access cleaned out before anything worse happened. Plenty of businesses aren't so lucky, particularly if nobody checks Business Settings until the bill arrives or the account gets locked entirely.

Next
Next

Google AI Mode Is Changing Google Ads: What NZ Businesses Need to Know