\n\n\n\n Verification Theater and the Dodgy Ads That Keep Getting Through - AgntBox Verification Theater and the Dodgy Ads That Keep Getting Through - AgntBox \n

Verification Theater and the Dodgy Ads That Keep Getting Through

📖 4 min read•673 words•Updated Sep 14, 2026

Remember when Google rolled out advertiser verification and told us it would clean up the ad ecosystem for good? Identity checks, business documentation, the whole airport-security routine. We were promised that bad actors would finally get bounced at the door. Fast forward to 2026, and I’m still seeing phishing scams targeting the very agencies that run Google Ads for a living. So let me ask the obvious question nobody at Mountain View seems eager to answer directly. Why is Google still serving dodgy ads?

Even the Pros Are Getting Phished

In April 2026, reports surfaced that agencies using Google Ads were being hit with phishing scams. Not random consumers clicking on sketchy links. Agencies. The people who live inside this platform every day, who know what a legitimate Google email looks like, who train their clients on security hygiene. If the professionals are getting targeted through the ads ecosystem, what chance does your average small business owner have?

Google’s response came through Ginny Marvin, the Google Ads product liaison, who wrote on LinkedIn that “while we proactively monitor for unusual account activity to stop these incidents, advertisers must remain alert.” Translation, as I read it: we’re watching, but you’re also on your own. That’s an honest admission, and I respect the honesty. But it’s also a quiet acknowledgment that the verification machinery isn’t catching everything, or even close to everything.

Policy Expansion Everywhere, Enforcement Somewhere

To be fair, Google hasn’t been sitting still. In 2026 the company expanded its Limited Ad Serving policy to cover every Google Ads surface, from Search and Shopping to YouTube, Gmail, the Play Store, and Demand Gen. Accounts classified as “unqualified advertisers” now face restrictions across the board rather than on a single surface. On paper, that’s the right move. A scammer shouldn’t be blocked on Search and free to run wild on YouTube.

Google’s written policies are also genuinely strict. Counterfeit goods, for example, are explicitly prohibited. The policy language bars the sale or promotion of products carrying a trademark or logo that’s identical to or substantially indistinguishable from a real brand’s mark. Dangerous products get similar treatment. The rulebook is fine. The rulebook has always been fine.

The gap, as always, is between the rulebook and reality. Phishing scams and policy violations keep slipping through despite increased verification and ad quality measures. As a reviewer, I evaluate tools on outcomes, not intentions. And the outcome here is that dodgy ads still reach real people.

Automation Cuts Both Ways

Here’s my toolkit-reviewer angle on why this keeps happening. In 2026, AI-generated ad copy and auto-applied recommendations are standard across Google Ads. The platform is more automated than it has ever been, and that automation is a double-edged sword. The same machinery that makes it trivially easy for a legitimate business to spin up campaigns also lowers the barrier for bad actors. When ad creation is fast, cheap, and machine-assisted, moderation has to move at machine speed too. And judging by what keeps getting through, it doesn’t always.

Meanwhile, honest advertisers who blindly follow every auto-applied recommendation often just inflate their spend without improving profit. So the automation isn’t reliably serving the good guys either. When I review a tool, one of my core questions is whether the defaults protect the user. Google Ads in 2026 fails that test more often than it should.

What You Should Actually Do

Since Google itself is asking advertisers to stay vigilant, take that seriously. Here’s my short list:

  • Treat unexpected account emails as hostile until proven otherwise. Phishing campaigns are actively targeting Google Ads users, agencies included.
  • Report suspicious activity. Google explicitly asks for this, and enforcement improves when violations get flagged.
  • Don’t rubber-stamp auto-applied recommendations. Review them. Following every suggestion blindly inflates spend without improving your returns.
  • Watch the policy changelog. Between the expanded Limited Ad Serving policy and the June 2026 spam update, the rules under your account are shifting constantly.

My verdict, in typical AgntBox fashion: Google Ads still works as a tool, but its safety systems earn a “partially working” rating from me

🕒 Published:

🧰
Written by Jake Chen

Software reviewer and AI tool expert. Independently tests and benchmarks AI products. No sponsored reviews — ever.

Learn more →
Browse Topics: AI & Automation | Comparisons | Dev Tools | Infrastructure | Security & Monitoring
Scroll to Top