I have hard times feeling any sympathy for these companies. When you trust an ad company like Google what did you expect? Maybe Google will shutdown this product and fix the secuity hole in the process.
Knowing the byzantine ways of Google support, I wouldn't be surprised if Google's reaction to this would be to ban the account of everyone involved in this episode.
Fair enough, but it's also worth noting that this mistake is difficult to make in AWS. You can do it, but you have to be so explicit about what you're doing that I can't imagine anyone managing it accidentally.
The system is broken if this has happened _multiple_ times to this guy.