LmCast :: Stay tuned in

HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud

Recorded: Sept. 18, 2026, 7:10 p.m.

Original Summarized

HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud | AdExchanger

image/svg+xml:

Topics
Latest
Marketers
Agencies
Publishers
Technology
Platforms
Identity
Measurement
Data Privacy
Artificial Intelligence
CTV
Commerce
AdExplainer
Exclusive Report
Daily News Roundup

Opinion
All Columns
Data-Driven Thinking
On TV & Video
The Sell Sider
Content Studio
Comic
Contributor Guidelines

About Us
Advertise
Newsletter
AdExchanger Advisory Board
About Us
Contact Us

Events
Programmatic I/O 2026
CTV World 2027
Top Women in Media & Ad Tech
Webinars
All Events
Network Events

Podcasts
AdExchanger Talks
The Big Story
Inside the Stack

Programmatic I/O

CTV World 2027

Become an AdHero

Subscribe

Sign In

Sign In

Topics
Latest
Marketers
Agencies
Publishers
Technology
Platforms
Identity
Measurement
Data Privacy
Artificial Intelligence
CTV
Commerce
AdExplainer
Exclusive Report
Daily News Roundup

Opinion
All Columns
Data-Driven Thinking
On TV & Video
The Sell Sider
Content Studio
Comic
Contributor Guidelines

Events & Awards
Programmatic I/O 2026
CTV World 2027
Top Women in Media & Ad Tech
Webinars
All Events
Network Events

Podcasts
AdExchanger Talks
The Big Story
Inside the Stack

Subscribe Free
Sign Up

About Us
Advertise
Newsletter
AdExchanger Advisory Board
About Us
Contact Us

CONNECT

Home Platforms HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud

Platforms
HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud By
James Hercher

Friday, September 18th, 2026 – 2:59 pm
SHARE:



Have you checked your accounts lately?
The ad industry had a nice laugh earlier this week when news popped about a nine-year- old who used his father’s already-logged-in Google business account to spend $118,000 on YouTube ads promoting his Minecraft and Roblox channel. His dad, a media buyer who got into hot water at work over the incident, had set a $20 limit. Whoops.
Funny story (well, maybe not for the dad). But account takeovers aren’t usually this benign, as another incident that came to light this past week demonstrates. Advertiser account security is a major cybersecurity flaw.
One not-so-comical takeover occurred when HBO MAX had its verified Reddit account overrun by a hacker group, which eluded notice for two days while it ran 108 different ad permutations targeting an unknown number of Redditors.
Cybersecurity company Hudson Rock wrote a detailed breakdown of the scam, which was orchestrated by a sophisticated group with links to previously documented cyber and ad fraud attacks.
In this case, the official HBO MAX Reddit account served ads offering different flavors of HBO MAX downloads or promos that featured convincing landing pages and the URL “hbomax.us”, which could easily fool undiscerning users. (The real URL is hbomax.com.) The campaign was identified after two days only because the scammers had the bad luck to serve an ad to a cybersecurity pro in the r/cybersecurity subreddit, blowing their cover.
“After learning of the issue, we locked the account, removed the ads and began working with HBO Max to strengthen its account security,” a Reddit spokesperson told AdExchanger in an email.

Warner Bros. Discover, which owns HBO MAX, did not respond to request for comment.
AdExchanger was told by a party with knowledge of the account takeover that it was the result of a compromised account from someone working on the HBO MAX team. “User error” is generally the root cause of account takeover scams.
Google Ads and Merchant Center account operators have been plagued for years by sophisticated fraudsters who swipe their budgets. But vampires need to be invited in.
Bad actors typically require a moment of human gullibility or naivety to get their foot in the door, like, for example, foolhardily doing a search for “Google Ads account” and then hitting the top link.
Sometimes that link is a scammer’s ad, and users end up authenticating the multi-factor token because they think they’re actually logging into the account. In fact their authorizing someone else.
In the case of the crew that took over HBO MAX’s Reddit account, they ran several scam ad campaigns at once, targeting people with different ad experiences and routing them to data harvesting pages based on whether they had cryptocurrency wallets, say, or were on a Mac, Android or Windows device.
Taking on takeovers
The growing prevalence of ad account takeover scammers should make it clear that we need new standards and best practices to guard against them.
One way is for platforms to prod their ad customers to improve their own practices, like Reddit did when it noted that it immediately “began working with HBO Max to strengthen its account security.”
Reddit clearly wants other advertisers to know the breach happened on HBO Max’s end, not Reddit’s.
Although platforms can also do more than point the finger and publish best practices.
In August, for example, Google took steps to shore up account security by requiring all Ads API account users to log in using a device authenticator app or passkey (which is a biometric sign-in like a fingerprint or facial recognition). New passkeys are now also placed in a week-long “trust period” before they can unlock budgets.
There’s lower-hanging fruit, however, that isn’t being addressed.
Reddit could at least notify every user who clicked on or was served one of the HBO MAX scam ads. Likewise,  Google and Meta could inform users if they’ve clicked on an ad that turns out to be part of a known crypto scam, for instancer. But none of the platforms do this.
Some scams take days or weeks to play out, and victims don’t know they’re victims. Software installed from a fake ad can quietly hand control of a device to someone else or lift saved passwords from their Notes app, including the answers to security questions for their bank and crypto accounts.
People who are scammed out of their Google Ads credentials are immediately aware, and so those fraudsters act fast. On an account that buyers may not be checking regularly, though, like Reddit, a bad actor could lurk for days without their activity drawing notice. Catching the HBO scammers within two days was pure luck.
Stay safe out there.

Tagged in:

ad fraud

//
featured

//
fraud

//
HBO Max

//
reddit

//
Takeover Ad Scams

//
WBD

Next In Platforms

The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR

Related Stories

Platforms
Magnite Targets CTV, SMBs And Google's SSP Market Share

Platforms
Conversion APIs Are Becoming Table Stakes – But Not All Brands Have Bought In

Platforms
Reddit’s Ad Biz Is Up, But Its Stock Is Way Down

Platforms
Reddit Reports A 75% Boost In Q1 Ad Revenue As It Reaches For 100 Million Daily US Users

Must Read

Gaming
Gaming Wants To Prove It’s Just Like Other Media Channels – While Also Owning How It’s Different

Adapting other channels’ strategies might be what gaming platforms need to do to get advertisers comfortable spending more. Leaning into gaming’s differentiators will come later, after bigger budgets arrive.

ad tech acquisition
Taboola Eyes The Finance Vertical With An Offer To Acquire Ad Network Dianomi

Taboola has made an offer to buy Dianomi, a UK-based ad tech company that connects financial advertisers with premium business and finance publishers.

Google remedies
The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR

The court has unsealed Judge Leonie Brinkema’s full remedies opinion in US v. Google (ad tech edition). So, what’s in there?

CTV
Horizon Is Bringing Roku’s TV Data ‘In House.’ Here’s What That Means For Advertisers

Horizon is bringing Roku’s streaming-TV data into its homegrown intelligence platform to help advertisers act on viewing signals while campaigns are still in flight.

Publishers
Chrome Has A New Way To Measure Ad Overload On The Web

Chrome is introducing new metrics that give advertisers and publishers a more data-driven picture of what users actually experience on ad-heavy sites.

Platforms
Why Wall Street Turned Against The Trade Desk

The Trade Desk is less than a third as valuable as it was a year ago. It retains about one-tenth of its high-water market cap from December 2024, when the company was worth almost $70 billion. Why did investors lose the faith?

Popular

Platforms

Why Wall Street Turned Against The Trade Desk

Publishers

Chrome Has A New Way To Measure Ad Overload On The Web

Platforms

The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR

CTV

Horizon Is Bringing Roku’s TV Data ‘In House.’ Here’s What That Means For Advertisers

AI

Everyone Has An Opinion On The Best AEO Tactics. Do Any Of Them Really Work?

Join the AdExchanger Community
Join Now

Your trusted source for in-depth programmatic news, views, education and events.
AdExchanger is where marketers, agencies, publishers and tech companies go for the latest information on the trends that are transforming digital media and marketing, from data, privacy, identity and AI to commerce, CTV, measurement and mobile.

NEXT EVENT
Programmatic I/O New York
September 28-29, 2026Marriott Marquis, New York
Learn More

ABOUT ADEXCHANGER
About Us
Advertise
Contact Us
Events
Subscribe
RSS
Cookie Settings
Privacy & Terms
Accessibility
Diversity, Equity, Inclusion & Belonging

CONNECT

© 2026 Access Intelligence, LLC - All Rights Reserved

The reported security breach involved the compromise of HBO MAX's verified Reddit account, which was subsequently exploited by a hacker group to run numerous ad permutations targeting an unknown audience. This incident highlights significant cybersecurity flaws in advertiser account security, as noted by James Hercher. The scammers utilized the account to serve advertisements featuring deceptive landing pages and the URL hbomax.us, attempting to mislead users, while the actual domain remains hbomax.com. The malicious campaign was eventually uncovered after only two days because the perpetrators inadvertently served an advertisement to a cybersecurity professional in the r/cybersecurity subreddit, leading to the exposure of the fraud.

The investigation suggested that the account takeover originated from a compromised account belonging to someone working on the HBO MAX team, pointing to user error as a primary cause for such compromises. The criminals ran these scam ad campaigns simultaneously, routing traffic to data harvesting pages based on various user attributes, such as the presence of cryptocurrency wallets or the operating system used (Mac, Android, or Windows). This type of account takeover often relies on exploiting human gullibility, where users might authenticate multi-factor tokens by mistaking a fraudulent link for a legitimate login interface.

The prevalence of such ad account takeover scams necessitates the development of new standards and best practices to enhance security across the industry. Platforms have a responsibility to proactively protect their advertisers and users. In response to the breach, Reddit communicated that they immediately began collaborating with HBO Max to fortify the account security measures. Furthermore, platforms like Google have implemented stricter security measures, such as requiring Ads API account users to log in using device authenticator applications or passkeys, and introducing trust periods for new passkeys before they can access budgets.

Despite these efforts, the text points out areas where greater accountability is needed. There is a lack of system-level notifications for users who interact with fraudulent advertisements, such as informing users who clicked on ads that are part of known crypto scams. The underlying issue is that sophisticated scams can persist for days or weeks before victims realize they have been targeted, especially if the targeted accounts, like Reddit’s, are not subject to frequent monitoring. Consequently, there is a need for platforms to implement mechanisms that alert users when they encounter known fraudulent content or advertisements, thereby preventing prolonged exposure to data and financial risk.