Child Ran $118,000 Ad Bill on Parent's Work Card
Saved payment information allowed a nine-year-old to launch unauthorized YouTube ad campaigns.
Updated on Sept. 19, 2026 in Pre-Teens

Live Poll
Are you concerned that default-saved payment information on your devices poses a financial risk?
A nine-year-old boy spent $118,000 on YouTube advertising to boost his channel, Mighty Mike Plays, by using his father's saved corporate credit card. The three-week campaign ran without secondary authentication, now putting the father's employment at risk.
Why it matters
This incident highlights the significant financial liability parents face when corporate payment credentials remain accessible on personal devices. The automated nature of modern ad platforms allows for rapid, large-scale spending if account security measures like re-authentication are not strictly enforced.
The nine-year-old ran ad campaigns for three weeks, accumulating $118,000 in charges. While two of his videos received 200,000 views, the company is still reviewing the unauthorized use of the corporate card to determine if the father will be terminated.
The players
Mighty Mike Plays
The YouTube channel belonging to the nine-year-old boy that was the subject of the unauthorized advertising campaign.
YouTube
A global video-sharing platform that provides automated advertising tools, including the Promote feature used in this incident.
The details
The charges occurred because the father had his corporate credit card information saved directly to his Google account. By using the YouTube Promote tool, the child bypassed secondary authentication requirements, enabling the ad campaigns to run continuously for three weeks without intervention.
Timeline
Three weeks prior to September 2026: The unauthorized ad campaigns occurred.
Late August to mid-September 2026: The timeframe of the activity.
The Home Front
This incident highlights the risks associated with digital payment security and family account management. It reflects a growing need for parents to strictly separate corporate financial credentials from personal and family-accessible device profiles.
Audit your browser and account settings immediately to remove saved corporate credit cards from any device accessible to children. Ensure that secondary authentication or biometric verification is required for all payments to prevent unintentional or unauthorized charges.
The takeaway
Large-scale unauthorized spending can happen instantly when saved payment methods lack additional security barriers. Periodically check your Google and browser payment profiles to ensure sensitive financial data is not stored on devices used by family members.
Further reading
For more on managing digital safety for your family, visit the Pre-Teens section.
Live Poll
Are you concerned that default-saved payment information on your devices poses a financial risk?







