deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Father says 9-year-old son racked up $118,000 in YouTube ad charges on saved company card

A father says his 9-year-old spent $118,000 on YouTube ads in three weeks, billed to a company card saved to a shared Google account. The case highlights stored-credential and authorization risks.

Father says 9-year-old son racked up $118,000 in YouTube ad charges on saved company card

What happened

According to Tom's Hardware, a father who identifies himself only as "Dave" says his nine-year-old son spent roughly $118,000 on YouTube advertising over about three weeks, with every charge landing on a company credit card that Dave had saved to his own Google account — the same account his son also used.

Dave described the incident in a video titled "Message from Dad…Mighty Mike Plays is Over," posted on September 15 to the channel where the boy publishes Minecraft and Roblox gameplay clips. In his telling, the first sign of trouble was a meeting at his workplace, where his manager, corporate staff and the finance department walked him through the charges. The plan had apparently been to run a single $20 promotion of one of the boy's videos.

How a $20 promotion scales to six figures

The report does not lay out precisely how the spend grew, but the shape of the incident follows a familiar pattern in self-serve advertising. Once a card is on file, an ad platform keeps billing it for as long as campaigns run; there is no per-charge re-authorization, no re-entry of card details and no bank-side confirmation each time budget is consumed. A campaign that is never paused simply keeps spending. Averaged across roughly three weeks, $118,000 works out to well over $5,000 a day.

YouTube's promotional tools are self-serve by design: anyone with access to an account holding a stored payment method can launch campaigns within minutes. The platform's checks confirm that the account can pay, not that the person at the keyboard is entitled to spend that particular card's money.

Three failures stacked together

The story is less about one careless click and more about a chain of weak points compounding one another.

The first is credential sharing. The boy used his father's Google account rather than a supervised child profile. Family features such as purchase-approval prompts only apply when a child actually uses a supervised account; they do nothing when a child logs into an adult's.

The second is stored payment. Saving a card converts payment authorization from a per-transaction decision into a one-time event, after which everything is treated as approved.

The third is a corporate card parked inside a personal consumer account. Business payment credentials saved to a personal Google profile sit outside normal company controls, and corporate card statements are typically reviewed monthly at best — consistent with the roughly three-week lag before anyone at Dave's employer flagged the activity.

Why it matters

The incident, which drew wider attention after surfacing on Hacker News, illustrates the gap between authorizing a payment method and authorizing each payment. Stored credentials make that gap invisible during normal use and catastrophic during abnormal use.

For parents, the practical lesson is that supervision tools only work when children use their own accounts; sharing a parent's login silently disables them. For employers, it is a reminder that company cards should never be saved to personal accounts for convenience. For platforms, the question is harder: self-serve ad systems could impose spending caps, verification steps or anomaly alerts on new campaigns, but friction cuts against conversion.

US regulators have previously pressed Apple and Amazon to refund unauthorized in-app purchases made by children, but advertising spend sits in murkier territory, since the money bought a service the account holder nominally controlled. The report does not say whether the charges have been disputed or whether Google has been asked to intervene, and all figures come from the father's own account of events. What is not in dispute is that the architecture which allowed this — a shared login, a saved card and an open-ended billing relationship — is entirely ordinary.

  • #youtube
  • #google-ads
  • #payments
  • #stored-credentials
  • #online-safety

Related posts