All Vendors
advertising

GoogleAds

Google Ads deploys consent bypass infrastructure for advertising attribution. Zero Oracle/Broker risk (ads provide value, not surveillance intel), but Counselor violations create liability for core marketing tooling.

63 IOCs314 detections66% pre-consent274 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what GoogleAds discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

314 detections across 274 sites66% pre-consent activity
CRITICAL

Pre-Consent Activity

GoogleAds was observed loading and executing before user consent was obtained on 66% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps
Customer Impact

What This Means For You

Marketing teams inherit consent liability for advertising that drives revenue. Legal teams must defend privacy violations for platform with documented business value. Compliance teams face regulatory scrutiny for technical implementation (pre-consent loading) not business necessity (advertising).
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use GoogleAds

  • Configure Google Ads consent mode: enables conversion tracking after consent without pre-consent loading
  • Audit current tag implementation: remove remarketing pixels from pre-consent loading
  • Review Google Tag Manager setup: ensure Ads tags fire only after consent signal

If You're Evaluating GoogleAds

  • Implement Google Consent Mode v2 for privacy-compliant advertising measurement
  • Evaluate consent impact on attribution: quantify performance difference between pre-consent and post-consent tracking
  • Consider alternative attribution: server-side conversion APIs, contextual advertising without tracking

Negotiation Leverage

  • Google Ads creates consent liability through pre-consent deployment despite availability of privacy-compliant alternatives (Consent Mode)
  • Unlike niche surveillance vendors, Google Ads provides clear ROI - focus on technical compliance (Consent Mode implementation) not contract termination
  • Google provides consent-first tooling (Consent Mode v2) - current violation is implementation choice, not technical limitation
  • Document business necessity and implement technical controls: consent-first loading, server-side attribution, or legitimate interest assessment if consent impacts performance
Runtime Detections

Runtime Detections

3 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Advertising tracking loads before user consent opportunity, creating per-visitor GDPR Article 7 violation. Google Ads scale amplifies exposure - high-traffic sites face penalty calculations based on millions of visitors.

BTI-C14Identity Resolution

PII deanonymization

IOC Manifest

IOC Manifest

60 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

EXFIL
*www.google.com/recaptcha/api.js*
Data collection endpoint
TRACK
*ads.google.com/aw/google_ads_prefetch.js*
Tracking script
TRACK
*ads.google.com/aw/JsPrefetch*
Tracking script
TRACK
*ads.google.com/aw_accountonboarding/JsPrefetch*
Tracking script
TRACK
*ads.google.com/aw_cm/editing/JsPrefetch*
Tracking script
TRACK
*ads.google.com/aw_express/management/JsPrefetch*
Tracking script
TRACK
*ads.google.com/aw_essentials/JsPrefetch*
Tracking script
TRACK
googleadservices.com/pagead/conversion
Tracking script
TRACK
ads.google.com/aw/google_ads_prefetch.js
Auto-extracted from scan
TRACK
ads.google.com/aw/JsPrefetch
Auto-extracted from scan
TRACK
ads.google.com/aw_essentials/JsPrefetch
Auto-extracted from scan
TRACK
ads.google.com/aw_express/management/JsPrefetch
Auto-extracted from scan
TRACK
ads.google.com/aw_cm/editing/JsPrefetch
Auto-extracted from scan
TRACK
ads.google.com/aw_accountonboarding/JsPrefetch
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Google Ads operates as core advertising platform, not niche surveillance vendor. Standard deployment includes conversion tracking, remarketing, and attribution features. Consent bypass widespread in Google Ads implementations due to performance optimization focus over privacy compliance.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

63 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details