If you received a suspicious email: do NOT click any links. Type the platform address directly in your browser and follow the steps below. |
META / FACEBOOK ADS
Step 1 — Change your password
Go to facebook.com (type manually)
Profile picture → Settings & Privacy → Settings
Security and Login → Change password
Use 12+ characters — mix of letters, numbers & symbols
Step 2 — Enable Two-Factor Authentication (2FA)
Settings → Security and Login → Two-Factor Authentication
Click Get Started → choose Text Message (SMS) or Authenticator App (Google Authenticator recommended)
Follow the on-screen steps and click Finish
Step 3 — Check access & billing
Business Manager → Business Settings → People: remove anyone unfamiliar
Billing → check for unexpected charges in the last 30 days
Security and Login → Where You're Logged In: log out of unfamiliar sessions
Step 4 — Contact us if concerned
If you noticed anything unusual — unexpected charges, unknown users, or suspicious logins — reach out to your account manager immediately.
GOOGLE ADS
Step 1 — Change your password
Go to myaccount.google.com (type manually)
Click Security → Password
Sign in again when prompted (Google re-verifies your identity)
Use 12+ characters — mix of letters, numbers & symbols
Step 2 — Enable Two-Step Verification (2SV)
myaccount.google.com → Security → 2-Step Verification
Click Get Started → choose Google Prompt, SMS, or Authenticator App (Google Authenticator recommended)
Follow the on-screen steps and click Turn On
Step 3 — Check access & billing
ads.google.com → Admin → Access and Security: remove unknown users
Admin → Linked accounts: remove any third-party apps you didn't approve
Billing → Billing Summary: check for unexpected charges in the last 30 days
Step 4 — Contact us if concerned
If you noticed anything unusual — unexpected charges, unknown users, or suspicious logins — reach out to your account manager immediately.
Golden Rule
Legitimate notifications from Meta and Google always appear inside your account dashboard — not in your email inbox. Always type the platform address directly in your browser. Never click a link in an email to log in.
Common phishing red flags: "Your account will be suspended in 15 days" · "Claim your Partner Credit" · "Your payment has failed" · Sender email not ending in @facebook.com, @facebookmail.com, @google.com, or @accounts.google.com
