Skip to content
Google Ads suspension experts based in ScotlandMon–Fri, 9:00–18:00 UK time 07777 148453
Guides
Guide · Google Ads Policy

Your account violated the Malicious Software policy – Google Ads

Gianluca Catinella, Director, Ad Restore Ltd12 min read
A mint shield outline with a cross, beside a lilac file-warning badge, on a dark navy ground.
The notice

Your account violated the Malicious Software policy.

An advertiser pasted the banner on the Google Ads Community in July 2024 as “Your account is suspended” followed by “Your account violated the Malicious Software policy”. We found no Google help page that prints the banner itself.

This notice means Google has decided that your ads, or the destination behind them, carry malware: software that aims to harm or get unapproved access to a computer, device or network. It is an egregious policy, so nothing arrives first: accounts are suspended upon detection and without prior warning. The way back is an appeal, and before it comes the part most people skip — working out what Google saw.

First, check you are in the right guide. This one is about the destination: your site or app and what it hosts or links to. If someone got into your Google Ads account and ran ads from it, read unauthorised access attempts or activity instead: that guide covers a stolen login, not malware on your site, and this one is the other way round. The wording above is from an advertiser’s post in July 2024, which never says how it ended.

Checked against Google’s help pages on 23 September 2026 and again on 4 October 2026. Google changes them without notice, so check the linked page before relying on a detail.

At a glance

  • No warning, by design

    Google suspends on detection under this policy.

  • Compromised sites gets seven days

    The neighbouring policy warns first.

  • It covers what you link to

    Your site, your app and anything they host.

  • Search Console first

    Google calls its Security Issues report the source of truth.

  • Usually a small detail, in our experience

    Correct it, then have it recrawled.

On this page11 sections

What Google means by malicious software

Google’s troubleshooter says it doesn’t allow advertisers to promote ads, apps, or websites that contain or link to malware, and the requirements apply to your ads and any software that your site or app either hosts or links to. A download on a page you never advertise, or a script pulled in from someone else’s server, is in scope.

One word matters. In 2023 Google said the scope of the Malicious software policy is narrowed to prohibit the intentional distribution of malware, and the live page still lists the first prohibited item as “Intentional distribution of malicious software”. Enforcement doesn’t ask your intent first, but intent is what an appeal for a hacked site has to establish.

The suspension is account-level: the account goes read-only and is permanent unless the appeal is submitted and succeeds. It can arrive alongside other policies on one notice.

Does Google warn you first?

No. Not under this policy.

Google’s suspensions overview says that on detecting violations of its egregious policies, your account will be suspended immediately without prior warning, and Malicious software is on its list of egregious policies. The policy page agrees: violations are taken very seriously and are considered egregious.

The neighbouring policies work the other way. Under Compromised sites, Google says violations won’t lead to immediate account suspension without prior warning, and a warning is issued at least seven days prior to any suspension of your account. Unwanted software says the same.

So your notice tells you something real. “Malicious Software” means the suspension came first and the conversation comes second. “Compromised sites” means Google should have written at least seven days earlier, so search your inbox, including spam. It also sometimes shows compromised domains in your Google Ads account — a named domain is the most useful thing you can have.

What a compromised site is

If nobody at your business put anything harmful on the site, the next question is whether somebody else did. Google has a policy for that: a compromised site is one whose code has been manipulated to act in ways that benefit a third party without the owner’s knowledge — destinations that are hijacked and hacked, sites injecting scripts or code that transmits user data without consent, or an exploited content management system with known security vulnerabilities. If that label is on your ads rather than a suspension on your account, and you can’t find anything wrong with the site, read “Disapproved: Compromised site”: in our experience it can be a false positive.

The two can land together. In October 2023 an advertiser reported one suspension naming Circumventing System, Malicious Software, and Compromised Site; their host found the site clean, they appealed, and were rejected two days later. The thread doesn’t say how it ended. If Circumventing Systems is on your notice, read our cloaking guide.

What sets it off

Google’s examples run from computer viruses, ransomware, worms, trojan horses, rootkits, keyloggers to forced redirects that send people to an unknown site infected with malicious software. In deciding whether an advertiser or destination is in breach, it says it may review information from multiple sources including your ad, your website, your accounts and third-party sources — broader than a scan of your home page.

Advertisers posting about the older “Malicious or unwanted software” disapprovals reported the same frustration: one external ad-script URL as the only detail (August 2019), flagged links that were “simply images or css files” (March 2020), and links that never existed within the site itself after a professional clean-up (October 2019). None says how it ended.

In our experience, the work is looking at the front end, the back end and the code. Ordinary site builders don’t produce this on their own — it takes a maladaptive plugin that allows it to happen. Google’s guide to how sites get hacked agrees: outdated or unpatched themes and plugins are a major source of vulnerabilities, and adding malicious code to free versions of paid plugins is a common tactic.

What Google asks you to do

Find it, clean it, prove it is clean, then appeal. In that order.

  1. Read the notice and the email.

    The email will identify all policies you were suspended for, with a link to appeal. Write down every one; if Compromised sites is among them, look for the earlier warning.

  2. Collect what Google is pointing at.

  3. Look at the pages safely.

    Google’s hacked-with-malware guide says to avoid using a browser to view pages on your site, because an infected page can damage your computer, and to fetch them with cURL or Wget instead — with and without a Google referrer, because some malware is only activated when users come from Google Search results. Search the responses for iframes and for “script”, “eval”, and “unescape”, and record your findings.

  4. Find the way in, then clean it.

    Google says to review relevant server configuration files such as .htaccess for redirects to unknown sites. The US version of its Compromised sites page adds: contact your web developer or security specialist for a thorough security assessment, and get your content management system (CMS), themes, and plugins updated to the latest versions. Take a suspect plugin out properly — remove all its files, not just disable it — then remove any code that refers to the identified domains.

  5. Prove it is clean.

  6. Then appeal in Google Ads.

    Select the Contact us link in the notification at the top of your screen. Say what was on the site, how it got there, what you removed, how you closed the hole and what the report shows now. Google’s tips for egregious appeals: explain your situation and take the time to be thorough, accurate and honest.

When every scanner says the site is clean

In December 2025 an advertiser suspended under this policy said Safe Browsing, VirusTotal and Search Console all showed nothing; in May 2020 another said nine different tools called the site clean. Neither reports an outcome. Google’s own pages explain most of it.

After it is cleaned

Give Google’s systems time to look again. The US version of its Compromised sites page says to resubmit your ads and allow the system up to 72 hours to recrawl and re-evaluate the landing page, and to set up email notifications in Search Console. Where Safe Browsing was involved, the policy page says your landing pages should automatically be re-enabled to serve ads once the domain is off the threat list, and to contact support if your ads are still disapproved.

Every service we sell includes 14 days of support after reinstatement: in our experience, a second suspension is what clients worry about most.

Can it be fixed?

Be clear-eyed about the policy page. Alongside the suspension line it says you will not be allowed to advertise with Google Ads again. Read that next to what the same page says further down: accounts are only reinstated in compelling circumstances, such as in the case of a mistake. Hard is not hopeless, and an infected site that has been cleaned is a case worth explaining properly.

In our experience we don’t turn these down: they are redeemable, typically a small detail flagging the system that needs to be corrected and recrawled. That is our experience, not a promise — only Google decides. If we review your case and can’t take it on, you get a full refund; when a suspension can’t be fixed covers the harder cases.

Don’t open a new Google Ads account to get round this.

Google says any new accounts that the advertiser tries to create may also be suspended, and its Circumventing Systems policy names creating new accounts to re-enter the system as a violation in its own right. It would also leave the infection on the site. Read why a new account makes things worse.

The appeal route

If you can’t fix the destination, Google says you can update the ad with a new destination that follows this policy — its route for a disapproved ad, not for a suspended account, and it leaves the infected page infected.

Before you write the appeal, read what the appeal form asks and why appeals get rejected.

Frequently asked questions

Does Google warn you before a Malicious Software suspension?

No. Google says accounts violating its egregious policies are suspended upon detection and without prior warning, and Malicious software is on that list. Compromised sites and Unwanted software are different: there, a warning comes at least seven days before any suspension.

Every scanner says my site is clean. Why am I still suspended?

A Google Ads suspension isn’t decided by a site scan. Google says it may review your ad, your website, your accounts and third-party sources, and Search Console adds that its list of affected URLs is not necessarily complete.

Is “Malicious or unwanted software” the same policy?

It is the old name. Google announced in February 2023 that the Malicious or unwanted software policy will be split into three — Malicious software, Compromised sites and Unwanted software — enforced from 9 May 2023, and only Malicious software is egregious. The advertiser posts quoting the old label pre-date the split, and we found no current Google page still using it: its Compromised sites page now tells you to filter ads for “Policy Details: Compromised site”.

How long does it take to get the site re-checked?

The US version of Google’s Compromised sites page says to allow up to 72 hours to recrawl and re-evaluate the landing page, and Search Console says most reconsideration reviews take several days or weeks. Neither publishes a time for a Google Ads appeal; in our experience, an appeal is typically seen within one to five days.

Can I open a new account instead?

No. Google says new accounts a suspended advertiser tries to create may also be suspended, and its Circumventing Systems policy treats creating new accounts to re-enter the system as a violation in itself.

Gianluca Catinella, director of Ad Restore
Written by

Gianluca Catinella

Director, Ad Restore Ltd

Gianluca Catinella is the Director of Ad Restore Ltd. He has worked with businesses across a wide range of industries, managing high-spend Google Ads accounts and handling complex account suspensions — including some of the most challenging policy and reinstatement cases. His work covers Circumventing Systems Policy, Suspicious Payment Activity and Unacceptable Business Practices, along with advertiser verification, Merchant Center and Google Business Profile suspensions. He came to this work from the receiving end. Running Google Ads for his own first business, he had an account suspended and found almost no support available to explain what had actually been flagged or how to put it right. He spent the months that followed reading the policies properly — every suspension type, what reviewers look for, and what a successful appeal has to contain — and he now tracks Google’s policy changes as they ship. Automated enforcement has to cast a wide net to keep scammers and bad actors out, and legitimate businesses get caught in it. Gianluca’s job is the bridge from confusion to clarity: working out exactly which policy was triggered, fixing the underlying issue, and putting a clear, evidenced appeal in front of Google so the business can get back to trading.

More from the blog