Illustrative: examples in this piece are constructed to demonstrate a pattern. They do not describe any specific client or engagement.
Most incidents reported as hacking are access failures: a former employee retained admin rights, a personal profile with business permissions was phished, or a partner agency was removed from the wrong asset. The account was not breached at a technical level — control simply passed to someone it should not have.
Three distinct situations
- Credential compromise: a person's login was obtained, usually through phishing or reused passwords. The account owner still exists; the session does not belong to them.
- Permission drift: nobody was attacked. Roles accumulated over years and were never audited, so people and agencies hold access that no longer matches their relationship with the business.
- Asset capture: an attacker who gained access adds themselves as an admin of a business portfolio, then removes the legitimate owners — which is why the recovery window is short.
Illustrative: a mid-sized retailer discovers unfamiliar ad spend. The cause is not a breach of the ad account but a personal profile with admin rights that was phished nine days earlier.
What to do in the first hour
- Secure the human accounts first — password resets and two-factor authentication on every profile with business access.
- Remove unrecognised users from the business portfolio before touching individual ad accounts.
- Pause spend rather than deleting campaigns; deleted assets are harder to reference in an appeal.
- Record everything with timestamps. Platform escalation is an evidence process.
Once recovered, the work is preventive: a documented access register, quarterly permission reviews, and business assets that are never owned by an individual's personal profile alone.
Sources & references
- Business Suite / business portfolio access and role documentation
- Platform account security and compromised-account recovery flows
