What buying a Facebook ads account actually means
When someone sells you a "Facebook ads account," you are not buying an asset in any legal or technical sense. You are buying credentials — a personal profile login, or admin access to an ad account and Business Manager that someone else created and still owns under Meta's systems. The ad account object in Meta's own API is defined as representing "a business, person or other entity who creates and manages ads on Facebook," with an owner field and an account_status — it is tied to an entity, not transferable like a domain name.
What sellers actually hand over falls into a few patterns:
- Aged personal accounts: a personal profile with years of history, sometimes with an ad account attached, sold with password and recovery email access.
- Business Manager access: you are added as an admin or partner to someone else's Business Manager and its ad accounts.
- "Warm" ad accounts: accounts with prior spend history, marketed as passing review more easily.
None of these transfers are recognized by Meta. The Business Management API documentation describes claiming ad accounts into a business as a one-time procedure where the requester must be an admin of the ad account, and Meta's own error codes treat personal accounts "that do not have any history of activity" as ineligible for migration. There is no documented mechanism for purchasing an ad account from a stranger. What you bought is a login that the original owner — or a thief — can reclaim, and that Meta's risk systems are built to detect changing hands.
The market exists because restrictions create demand: buyers who lost their own account or need more capacity look for a shortcut. But the shortcut is the problem, not the solution.
Why Meta restricts purchased and aged personal accounts
Meta's published enforcement policy states that restrictions may be placed when advertisers go against its policies and standards "or if Meta observes any unusual or high-risk activity." Purchased accounts trip both wires at once.
Why the restriction happens:
-
Circumvention is itself a policy violation. Meta's Advertising Standards prohibit evading enforcement — using an account bought after a restriction is the textbook pattern. The ad account API even exposes a
disable_reasonenum includingMISREPRESENTED_AD_ACCOUNTandCOMPROMISED_AD_ACCOUNT, showing Meta classifies exactly these situations at the account level. -
Login-pattern anomalies. A new device, new IP range, new payment method, and new geographic location appearing simultaneously on an aged account is the signature of both a purchased account and a hacked one — the login pattern is identical whether the new user is a buyer or a thief. Practitioner reporting on rising Facebook lockouts notes that Facebook now uses more aggressive security signals, and that even "traveling, using a VPN, or switching devices can trigger lockouts" for legitimate users.
-
Many accounts for sale are literally stolen. Threat research from Zscaler and Mimecast documents a commodity underground market in hijacked Meta Business Manager and ad accounts, with stolen Business Manager accounts listed from roughly $15 to $340 and aged accounts with legitimate spend history commanding a 2–4x premium precisely because they pass safety checks. If you buy one, you may be funding the DuckTail/NodeStealer ecosystem and inheriting a compromised asset.
-
Restrictions cascade across assets. Meta applies restrictions at four levels — business portfolio, ad account, Page, and user account. A flagged user account can disable ad accounts where that person is the only attached user. A purchased account's contaminated history follows the asset, not the seller.
-
Recovery is slow and uncertain. Meta does not publish a timeline for restriction reviews, and practitioner reporting describes advertisers stuck in automated appeal loops with limited human support. If a purchased account is disabled for a policy violation and remains ineligible for reinstatement for six months, Meta's help center states unused prepaid services may be forfeited and the account cannot be reinstated after that point.
What you cannot buy: account ownership under Meta's terms
Meta's Self-Serve Ad Terms govern "creation, submission and/or delivery of any advertising" through its interfaces and APIs. Under those terms, the ad account is licensed to the entity that created it — it is not property that can be sold. Meta's Business Management documentation is explicit about the approved models: a Marketing Partner (agency) can own ad accounts and manage them for customers, or the advertiser owns its own assets — but "Marketing Partner stores customer passwords" is labeled "not an approved model," and creating fake shared users is flagged as behavior that gets suspended.
Concretely, what you cannot buy:
- Ownership of an ad account. The API's claim flow requires the claimant to be an admin of the account, and confirmed ownership cannot be removed once established. There is no transfer mechanism.
- A personal profile. Personal accounts belong to individuals under Meta's terms of service; buying login credentials gives you no rights, and the original owner can reclaim it at any time — or report it stolen, which is often accurate.
- Immunity from history. An ad account's spend history, rejection history, and attached entities are permanent attributes. Buying an account with a flagged history buys the flag.
What you can legitimately obtain is access: an agency's Business Manager can be granted partner access to your assets, or you can be granted tasks (ANALYZE, ADVERTISE, MANAGE) on an agency-owned ad account. That is the compliant model — access and management, never a sale.
The compliant route: managed agency ad accounts
The model Meta explicitly documents for partners is the agency-owned ad account. Meta's own Best Practices documentation describes the "Marketing Partner Owns Ad Accounts" scenario: the agency's Business Manager creates and owns the ad accounts, manages them with its own employees or system users, and grants the client access at the appropriate task level. The API supports this natively — ad account creation under a business specifies media_agency and partner fields, and the agency_client_declaration field exists precisely to declare "the agency advertising on behalf of this client account."
How a managed agency ad account works in practice:
- Ownership: the agency's verified Business Manager owns the ad account. You never depend on a stranger's personal profile.
- Access: you are added as a user with
ADVERTISEandANALYZEtasks (orMANAGEwhere appropriate) on the ad account — documented, revocable, and auditable roles, not shared passwords. - Billing: the agency can attach the account to its own credit line with Meta (the API supports
invoiceand extended credit attachment), then bill you — or you fund the account directly. Either way, billing is documented and traceable, avoiding the failed-payment signals that trigger restrictions. - Portability and offboarding: because access is granted through Business Manager roles rather than credential sharing, offboarding is clean — roles are removed, assets are reassigned, and your Pages, pixels, and audiences can stay under your own ownership throughout. Ask any provider to put the offboarding path in writing: who owns each asset, who holds admin access, and how access, billing, and data transfer work on exit.
This is why the agency-owned model is the durable route at high spend where purchased accounts are not: the structure is the one Meta designed for exactly this use case. It is not a loophole; it is the documented architecture. Note that no provider can promise immunity from enforcement — compliant structure reduces risk; it does not eliminate it.
Evaluating agency ad account infrastructure?
Review dedicated agency ad accounts across Meta, TikTok, and Google, with compartmentalized billing, access custody, and human-led escalation.
Explore Agency AccountsHow to vet any provider before paying
Whether you are evaluating an agency ad account provider or (against our advice) any other vendor, apply the same checks before money changes hands:
-
Ask what exactly is being granted. A compliant provider grants you documented roles on an agency-owned ad account inside a verified Business Manager. If the answer is "we send you a login and password," walk away — Meta's own documentation labels password storage "not an approved model."
-
Verify the business entity. A real agency has a verifiable Business Manager, a registered company, a contract, and named humans. Ask for the Business Manager ID and check that the entity is real and established.
-
Ask about billing structure. How is the account funded — your card, the agency's credit line, prepay? Who receives invoices? A provider who cannot explain billing clearly will create the disputed-payment signals that trigger restrictions.
-
Ask about the offboarding path. What happens if you leave? Who owns the pixel, the audiences, the Page connections? A provider who cannot answer this in writing is designing your dependency, not your infrastructure.
-
Ask about restriction response. What is the documented process when a restriction lands — who requests the review, who escalates, what is the communication SLA? Meta's own help center directs restricted advertisers to request a review in Business Support Home; a professional provider has a workflow for this, not a shrug.
-
Check what they will and will not accept. A provider who takes any client, any vertical, no questions, is aggregating risk that will eventually land on your account. Compliant providers screen verticals against Meta's policies.
-
Beware of outcome promises. No provider can promise an approval outcome, unlimited spend, or protection from enforcement. Meta does not publish timelines or outcomes for reviews, and anyone claiming otherwise is selling you something that does not exist.
Red flags that predict a short-lived account
These signals predict an account (or a provider relationship) that will not last:
- Credentials handed over by chat. Password and recovery-email transfers mean the account is either violating Meta's terms or stolen — often both. Meta's documentation is explicit that storing customer passwords is not an approved model.
- "Aged" as the primary selling point. Age and spend history are exactly what the theft underground prices at a premium, because they help stolen accounts pass checks. An account marketed mainly on its age is more likely to be someone else's.
- Prices that make no sense. Stolen Business Manager access has been listed from around $15. If a "premium warmed account" costs a few hundred dollars, you are not buying infrastructure; you are buying a stolen good with a markup.
- No contract, no entity, no offboarding terms. If there is no written answer to "what happens to my data and access when we part ways," the provider owns you, not the account.
- Requests to pay via gift cards, crypto-only, or game credits. Practitioner reporting describes fraudulent recovery and account services demanding unconventional payment — a hallmark of the underground market, not a business.
- Promises of certain approval or restriction-proof accounts. These do not exist. Meta's enforcement is probabilistic and its review timelines unpublished; anyone promising fixed outcomes is misrepresenting what they control.
- Shared "warm" accounts across many buyers. If multiple advertisers rotate through the same ad account, one buyer's policy failure contaminates everyone — Meta's asset-level enforcement spreads across attached Pages and users.
- No screening of your vertical or creatives. A provider who never asks what you sell is not managing risk; they are deferring it to the moment your account is flagged.
The pattern across all of these: anything that depends on hiding what is happening from Meta will eventually be found, because Meta's systems are built to find exactly that. Durable capacity comes from structure Meta recognizes, not structure it is forced to detect.