Why did Google disapprove my ads for a compromised site?
Direct answerGoogle disapproves the ad because the destination’s code was changed to benefit someone else without the site owner’s knowledge. Typical signs are a card skimmer, malware installed on visitors, pop-up ads, or a redirect. This is not a finding that you meant to sell malware. The live policy warns at least 7 days before an account suspension. Clean the site, then appeal.
Read the label before you touch the copy
Google’s Compromised sites policy, reviewed on September 26, 2026, defines a compromised site as a destination whose code was manipulated to act in ways that benefit a third party without the owner’s knowledge, often in a way that harms users. The examples are hijacked sites: scripts that send user data without consent, such as credit-card skimmers; malware installed on visitors’ devices; pop-up ads; redirects; and a CMS with a known vulnerability that has been exploited.
In Ads, filter for “Policy Details: Compromised site.” If the email says malicious software or unwanted software, use that playbook instead. Rewriting a headline does not remove a skimmer. Cloaking and extra accounts are circumventing systems.
Two queues: the site, then the ad
Google says the disapproval can name domains the content loads from. Remove code that refers to those domains. Use the Safe Browsing checker linked from the policy page, and Search Console’s Security Issues report. Update the CMS, theme, and plugins.
If Safe Browsing has disallowed the site, fix the malware and file the Search Console appeal so the domain can leave that threat list. Google says the landing page should then be able to serve ads again. If ads stay disapproved after that, contact support. A new final URL is allowed when you cannot repair the old one. Editing the ad resubmits it.
When only the landing page changed, appeal in Google Ads with “Made changes to comply with policy.” Use “Dispute” when you believe the finding is wrong. Google says to allow up to 72 hours for the system to recrawl the page. Violations of this policy do not suspend the account immediately. A warning comes at least 7 days before suspension. The steps if the account is already suspended are in why Google Ads accounts get suspended.
Setup workflow
- Filter ads for Policy Details: Compromised site. Confirm the label before you rewrite the RSA.
- Read the disapproval for any domain Google identified. Remove code on your site that refers to those domains.
- Check the final URL in the Safe Browsing checker Google links from the policy page, and run a Security Issues report in Search Console.
- Update the CMS, themes, and plugins. If Safe Browsing disallowed the site, appeal there after the malware is gone.
- In Google Ads, appeal with Made changes to comply with policy. If you cannot clean the URL, point the ad at a clean destination. Allow up to 72 hours for a recrawl.
Frequently asked questions
Is a compromised site the same as malicious software?
No. Malicious software is a product or destination Google treats as egregious, with suspension on detection and no warning. A compromised site is a destination whose code was changed to benefit someone else without the owner’s knowledge. The live Compromised sites page says that label gets a warning at least 7 days before suspension.
Do I appeal in Google Ads or in Search Console?
Both can apply. If Safe Browsing has disallowed the site, Google says to fix the malware and appeal in Search Console so the domain can leave that threat list. Ad disapproval is appealed in Google Ads: Dispute if you believe the finding is wrong, or Made changes to comply with policy after you cleaned the page. Allow up to 72 hours for Google to recrawl the landing page.
Sources
This reading is as of September 26, 2026. It is not a security audit of your site.
Separate a hacked URL from a policy claim
LaunchGuarding reads the ad and the destination so a skimmer is not treated as a headline problem.