We got blamed for getting our client's ad account hacked.
Monday morning. The client calls. Panicking.
₹80,000 spent overnight on their Meta ad account. Campaigns they didn't recognise. Audiences in countries they'd never targeted. Every real campaign paused.
First thing they said: "What did your team do."
Nothing. We checked immediately. The access logs were clean. No arlox.io team member had touched the account after 6pm the previous evening.
The account was compromised through the client's own Facebook login. No two-factor authentication. Someone got in through a phishing link the founder had clicked weeks earlier.
Meta support took 72 hours to respond. Reversing the fraudulent spend took three weeks of back and forth.
We managed the entire recovery. Rebuilt the campaigns from scratch. Set up proper account security before anything went live again.
The founder apologised. We moved on.
What arlox.io now does with every new client before campaigns go live: a full ad account security audit. Two-factor authentication on every admin login. Business Manager access reviewed and cleaned up. Only the necessary people with only the necessary permissions.
A hacked Meta ad account in D2C fashion can set a brand back months. The prevention takes 20 minutes.
If your Meta Business Manager has never had a security audit — arlox.io. Do it before someone else does it for you.
- Arlox.io | Best Brand Scaling Agency for D2C Fashion
