HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud | AdExchanger
image/svg+xml:
Topics Latest Marketers Agencies Publishers Technology Platforms Identity Measurement Data Privacy Artificial Intelligence CTV Commerce AdExplainer Exclusive Report Daily News Roundup
Opinion All Columns Data-Driven Thinking On TV & Video The Sell Sider Content Studio Comic Contributor Guidelines
About Us Advertise Newsletter AdExchanger Advisory Board About Us Contact Us
Events Programmatic I/O 2026 CTV World 2027 Top Women in Media & Ad Tech Webinars All Events Network Events
Podcasts AdExchanger Talks The Big Story Inside the Stack
Programmatic I/O
CTV World 2027
Become an AdHero
Subscribe
Sign In
Sign In
Topics Latest Marketers Agencies Publishers Technology Platforms Identity Measurement Data Privacy Artificial Intelligence CTV Commerce AdExplainer Exclusive Report Daily News Roundup Opinion All Columns Data-Driven Thinking On TV & Video The Sell Sider Content Studio Comic Contributor Guidelines Events & Awards Programmatic I/O 2026 CTV World 2027 Top Women in Media & Ad Tech Webinars All Events Network Events Podcasts AdExchanger Talks The Big Story Inside the Stack Subscribe Free Sign Up About Us Advertise Newsletter AdExchanger Advisory Board About Us Contact Us CONNECT
Home Platforms HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud
Platforms HBO MAX’s Reddit Account Was Compromised And Used For Ad Fraud By James Hercher
Friday, September 18th, 2026 – 2:59 pm SHARE:
Have you checked your accounts lately? The ad industry had a nice laugh earlier this week when news popped about a nine-year- old who used his father’s already-logged-in Google business account to spend $118,000 on YouTube ads promoting his Minecraft and Roblox channel. His dad, a media buyer who got into hot water at work over the incident, had set a $20 limit. Whoops. Funny story (well, maybe not for the dad). But account takeovers aren’t usually this benign, as another incident that came to light this past week demonstrates. Advertiser account security is a major cybersecurity flaw. One not-so-comical takeover occurred when HBO MAX had its verified Reddit account overrun by a hacker group, which eluded notice for two days while it ran 108 different ad permutations targeting an unknown number of Redditors. Cybersecurity company Hudson Rock wrote a detailed breakdown of the scam, which was orchestrated by a sophisticated group with links to previously documented cyber and ad fraud attacks. In this case, the official HBO MAX Reddit account served ads offering different flavors of HBO MAX downloads or promos that featured convincing landing pages and the URL “hbomax.us”, which could easily fool undiscerning users. (The real URL is hbomax.com.) The campaign was identified after two days only because the scammers had the bad luck to serve an ad to a cybersecurity pro in the r/cybersecurity subreddit, blowing their cover. “After learning of the issue, we locked the account, removed the ads and began working with HBO Max to strengthen its account security,” a Reddit spokesperson told AdExchanger in an email.
Warner Bros. Discover, which owns HBO MAX, did not respond to request for comment. AdExchanger was told by a party with knowledge of the account takeover that it was the result of a compromised account from someone working on the HBO MAX team. “User error” is generally the root cause of account takeover scams. Google Ads and Merchant Center account operators have been plagued for years by sophisticated fraudsters who swipe their budgets. But vampires need to be invited in. Bad actors typically require a moment of human gullibility or naivety to get their foot in the door, like, for example, foolhardily doing a search for “Google Ads account” and then hitting the top link. Sometimes that link is a scammer’s ad, and users end up authenticating the multi-factor token because they think they’re actually logging into the account. In fact their authorizing someone else. In the case of the crew that took over HBO MAX’s Reddit account, they ran several scam ad campaigns at once, targeting people with different ad experiences and routing them to data harvesting pages based on whether they had cryptocurrency wallets, say, or were on a Mac, Android or Windows device. Taking on takeovers The growing prevalence of ad account takeover scammers should make it clear that we need new standards and best practices to guard against them. One way is for platforms to prod their ad customers to improve their own practices, like Reddit did when it noted that it immediately “began working with HBO Max to strengthen its account security.” Reddit clearly wants other advertisers to know the breach happened on HBO Max’s end, not Reddit’s. Although platforms can also do more than point the finger and publish best practices. In August, for example, Google took steps to shore up account security by requiring all Ads API account users to log in using a device authenticator app or passkey (which is a biometric sign-in like a fingerprint or facial recognition). New passkeys are now also placed in a week-long “trust period” before they can unlock budgets. There’s lower-hanging fruit, however, that isn’t being addressed. Reddit could at least notify every user who clicked on or was served one of the HBO MAX scam ads. Likewise, Google and Meta could inform users if they’ve clicked on an ad that turns out to be part of a known crypto scam, for instancer. But none of the platforms do this. Some scams take days or weeks to play out, and victims don’t know they’re victims. Software installed from a fake ad can quietly hand control of a device to someone else or lift saved passwords from their Notes app, including the answers to security questions for their bank and crypto accounts. People who are scammed out of their Google Ads credentials are immediately aware, and so those fraudsters act fast. On an account that buyers may not be checking regularly, though, like Reddit, a bad actor could lurk for days without their activity drawing notice. Catching the HBO scammers within two days was pure luck. Stay safe out there.
Tagged in:
ad fraud
// featured
// fraud
// HBO Max
// reddit
// Takeover Ad Scams
// WBD
Next In Platforms
The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR
Related Stories
Platforms Magnite Targets CTV, SMBs And Google's SSP Market Share
Platforms Conversion APIs Are Becoming Table Stakes – But Not All Brands Have Bought In
Platforms Reddit’s Ad Biz Is Up, But Its Stock Is Way Down
Platforms Reddit Reports A 75% Boost In Q1 Ad Revenue As It Reaches For 100 Million Daily US Users
Must Read
Gaming Gaming Wants To Prove It’s Just Like Other Media Channels – While Also Owning How It’s Different
Adapting other channels’ strategies might be what gaming platforms need to do to get advertisers comfortable spending more. Leaning into gaming’s differentiators will come later, after bigger budgets arrive.
ad tech acquisition Taboola Eyes The Finance Vertical With An Offer To Acquire Ad Network Dianomi
Taboola has made an offer to buy Dianomi, a UK-based ad tech company that connects financial advertisers with premium business and finance publishers.
Google remedies The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR
The court has unsealed Judge Leonie Brinkema’s full remedies opinion in US v. Google (ad tech edition). So, what’s in there?
CTV Horizon Is Bringing Roku’s TV Data ‘In House.’ Here’s What That Means For Advertisers
Horizon is bringing Roku’s streaming-TV data into its homegrown intelligence platform to help advertisers act on viewing signals while campaigns are still in flight.
Publishers Chrome Has A New Way To Measure Ad Overload On The Web
Chrome is introducing new metrics that give advertisers and publishers a more data-driven picture of what users actually experience on ad-heavy sites.
Platforms Why Wall Street Turned Against The Trade Desk
The Trade Desk is less than a third as valuable as it was a year ago. It retains about one-tenth of its high-water market cap from December 2024, when the company was worth almost $70 billion. Why did investors lose the faith?
Popular
Platforms
Why Wall Street Turned Against The Trade Desk
Publishers
Chrome Has A New Way To Measure Ad Overload On The Web
Platforms
The Court Just Unsealed Judge Brinkema’s Remedies Decision In The Google Ad Tech Antitrust Case. Here’s Your TL;DR
CTV
Horizon Is Bringing Roku’s TV Data ‘In House.’ Here’s What That Means For Advertisers
AI
Everyone Has An Opinion On The Best AEO Tactics. Do Any Of Them Really Work?
Join the AdExchanger Community Join Now
Your trusted source for in-depth programmatic news, views, education and events. AdExchanger is where marketers, agencies, publishers and tech companies go for the latest information on the trends that are transforming digital media and marketing, from data, privacy, identity and AI to commerce, CTV, measurement and mobile.
NEXT EVENT Programmatic I/O New York September 28-29, 2026Marriott Marquis, New York Learn More
ABOUT ADEXCHANGER About Us Advertise Contact Us Events Subscribe RSS Cookie Settings Privacy & Terms Accessibility Diversity, Equity, Inclusion & Belonging
CONNECT
© 2026 Access Intelligence, LLC - All Rights Reserved |
The reported security breach involved the compromise of HBO MAX's verified Reddit account, which was subsequently exploited by a hacker group to run numerous ad permutations targeting an unknown audience. This incident highlights significant cybersecurity flaws in advertiser account security, as noted by James Hercher. The scammers utilized the account to serve advertisements featuring deceptive landing pages and the URL hbomax.us, attempting to mislead users, while the actual domain remains hbomax.com. The malicious campaign was eventually uncovered after only two days because the perpetrators inadvertently served an advertisement to a cybersecurity professional in the r/cybersecurity subreddit, leading to the exposure of the fraud.
The investigation suggested that the account takeover originated from a compromised account belonging to someone working on the HBO MAX team, pointing to user error as a primary cause for such compromises. The criminals ran these scam ad campaigns simultaneously, routing traffic to data harvesting pages based on various user attributes, such as the presence of cryptocurrency wallets or the operating system used (Mac, Android, or Windows). This type of account takeover often relies on exploiting human gullibility, where users might authenticate multi-factor tokens by mistaking a fraudulent link for a legitimate login interface.
The prevalence of such ad account takeover scams necessitates the development of new standards and best practices to enhance security across the industry. Platforms have a responsibility to proactively protect their advertisers and users. In response to the breach, Reddit communicated that they immediately began collaborating with HBO Max to fortify the account security measures. Furthermore, platforms like Google have implemented stricter security measures, such as requiring Ads API account users to log in using device authenticator applications or passkeys, and introducing trust periods for new passkeys before they can access budgets.
Despite these efforts, the text points out areas where greater accountability is needed. There is a lack of system-level notifications for users who interact with fraudulent advertisements, such as informing users who clicked on ads that are part of known crypto scams. The underlying issue is that sophisticated scams can persist for days or weeks before victims realize they have been targeted, especially if the targeted accounts, like Reddit’s, are not subject to frequent monitoring. Consequently, there is a need for platforms to implement mechanisms that alert users when they encounter known fraudulent content or advertisements, thereby preventing prolonged exposure to data and financial risk. |