
Almost every legitimate business that gets this has been hacked rather than caught. That matters, because the two situations are different policies with different remedies, and appealing through the wrong one fails no matter how good the appeal is.
No cost. A straight answer within one business day on which of the two you are in.
Read the notice carefully
Malicious software and compromised sites are separate policies. Most pages about this treat them as one thing, which is why so many appeals go to the wrong place.
Google defines a compromised site as one whose code has been manipulated to benefit a third party without the owner's knowledge, usually harming visitors. A hacked site with an injected script, redirect or skimmer is this.
It is the common case for legitimate businesses, and it is enforced differently from the deliberate policy. The remedy runs through Google Search Console and Safe Browsing rather than the Google Ads appeal form: clean the site, then appeal to have the domain removed from the Safe Browsing threat list.
Google states that once that process completes successfully, the site or landing pages should automatically be re-enabled to serve ads. That is unusual and it is worth knowing, because it means the Google Ads appeal is not always the thing standing between you and running again.
This covers software that harms or gains unapproved access to a device or network, forced redirects to infected destinations, and ads built to steal credentials from the page they appear on.
Google classes violations of this policy as egregious, which means suspension on detection with no warning and no strike sequence.
Legitimate businesses do land here, usually because the compromise was severe or long-running enough to look deliberate. The appeal has to establish that it was not, with evidence of the compromise and of the cleanup.
Not sure which policy your notice names?
Get it reviewedBefore you do anything else
For a compromised site the remedy runs through Search Console, with an appeal to remove the domain from the Safe Browsing threat list. Submitting a Google Ads appeal while the domain is still listed argues with a system that is not the one holding you.
Google assesses the ad, the landing page and everything the page loads: scripts, iframes, content delivery networks, third-party forms, and any redirect that follows. One compromised third-party script is enough to keep the flag in place after the visible site looks fine.
Google's own guidance notes that its Safe Browsing tool might not catch everything and is a starting point rather than a verdict. A single scan returning nothing is not evidence that the compromise was found.
If the entry point is still open, the injection returns, often within days. A second flag on the same domain is a materially harder conversation than the first.
If one of these has already happened, the case is harder but not over.
Get it reviewedHow this works
Six questions about the notice and what changed in the business before it arrived. Answered within one business day with a read on the likely cause and whether it is worth pursuing.
If it is worth pursuing, read-only access to the account and a look at the site. The real cause is rarely the one the advertiser expects, and it is not visible from outside.
What actually triggered it, what has to change on the account and the site before an appeal can succeed, and the evidence to submit alongside it.
Drafted and submitted once the account is genuinely ready for re-review, then managed through to the decision.
Get it reviewed
The notice you received and what changed in the business before it arrived are usually enough to identify the cause. No account access needed to answer these, and you get a reply within one business day.
Thanks — that's come through.
I'll come back to you shortly.
That didn't send. Something went wrong at our end, not yours.
Email me directly at rob@leftclick.co.nz and I'll pick it up from there.
A reply within one business day, from me. No cost, no obligation, and if it isn't worth pursuing you'll be told that plainly.
Prefer email? rob@leftclick.co.nz

Nineteen years in search marketing. Eight of them running my own agency, sold in 2021. Four years managing seven-figure United States advertising accounts in consumer credit, a category Google scrutinises hardest.
In that industry, compliance, suspensions, disapprovals and verification reviews are a frequent occurrence and a condition of operating.
You deal with me directly, from the first reply through to the decision.
Questions
No. Google decides. What can be committed to is an honest read on whether the case is arguable, a correctly identified root cause, and an appeal built around the actual detection rather than around fairness.
In Google Ads, filter policy details for compromised site. Google sometimes names the compromised domains it detected, which is both the confirmation and the start of the fix. If that filter returns nothing and the notice names malicious software, you are in the other one.
Not on its own. It changes which policy applies and therefore the route and the urgency, but Google's position is that the end result for the user is the same either way. The appeal has to show the compromise was found, removed, and the entry point closed.
That is worth testing rather than trusting. Google's check covers everything the page loads, including third-party scripts, content delivery networks and embedded forms, and it follows redirects. A site can be clean in the sense your developer means and still fail.
For a compromised site, Google states the site or landing pages should automatically be re-enabled to serve ads once the Safe Browsing removal process completes successfully. If they do not, something in the chain is still flagged.
Yes. Google Search Console can send email notifications for security issues on your property. Most businesses find out from a suspension rather than from the notification, and the notification is free.