A verified account is supposed to be the thing you point to when someone asks "is this really them." HBO Max's Reddit account had that badge, that history, that accumulated trust with a subreddit's userbase, and none of it stopped someone else from logging in and running ad fraud through it. The account didn't get faked. It got taken.

That distinction matters more than it sounds like it should. A brand safety audit that checks whether an account is verified, whether it's the "real" one, whether it matches the logo and bio on file, is checking the wrong thing if the actual risk is that the real account gets hijacked and used against the brand that owns it. The badge answered a question nobody was asking. The question that mattered went unasked.

The account was never a static asset

Marketing teams tend to treat owned social accounts the way they treat a domain name or a trademark registration: something you set up once, verify, and then mostly leave alone except for posting. The password lives with a small group, maybe rotates through a password manager, maybe doesn't. Access review happens when someone leaves the team, if it happens at all. Nobody schedules a recurring check on who can still log in, because nobody thinks of the login as the thing worth checking.

That model assumes the account is inert between posts. It isn't. A verified brand account with an established audience is a distribution asset with real value attached to it, which is exactly what makes it worth stealing. Whoever compromised HBO Max's Reddit account wasn't after the account itself. They were after what the account could do: post with credibility, reach an existing audience, and run ad fraud under cover of a name people already trusted.

That's the same value proposition brands pay for when they buy paid media. Reach, credibility, an audience that already showed up and already trusts the name in the corner of the post. The account had all three, for free, sitting behind a login that someone else eventually got into. Whoever ran the fraud didn't need to build an audience or buy reach. HBO Max had already done that work for them, over years, one post at a time, and handed it over the moment the login was compromised.

Brand safety audits stop at the wrong layer

Most brand safety processes are built to catch two kinds of failure. One is a placement problem: your ad running next to content you don't want to be near. The other is a message problem: your own creative causing offense, which is what happened when Converse ran ads that evoked a lynching and drew immediate backlash on social media. Both of those are about what the brand is choosing to say or where it's choosing to say it. Both assume the brand is the one holding the pen.

Account compromise is a third category, and most audit frameworks don't have a line item for it. Nobody chose to run the ad fraud. Nobody approved the creative. The account did exactly what a hijacked paid media account does: it ran someone else's campaign using the brand's own reach as the delivery mechanism. The audit question isn't "did we approve this" but "who currently has access to post as us, and how would we know if that changed." Those two questions live in different departments at most companies, which is itself part of the problem.

Those are different questions requiring different tools. Approval workflows and creative review boards don't catch a stolen login. Access logs, session monitoring and two factor authentication enforcement do, and those aren't things most agencies or in house social teams treat as part of brand safety at all. They get filed under IT security, handled by a different team, on a different schedule, often with no connection to the brand safety audit that happens around the content calendar. The creative team reviews the post before it goes up. Nobody reviews who was capable of posting it in the first place.

Treat the account like a media buy

If an owned account is functionally a paid media surface, complete with reach and credibility that can be diverted, it should get the scrutiny a media buy gets. Nobody would run a programmatic campaign without checking who has access to the account that controls the spend. Owned social deserves the same discipline, and mostly doesn't get it.

  • Access reviewed on a schedule, not just when staff turnover forces it, with a list of who can currently post that someone actually checks against who should be able to
  • Login activity monitored the way you'd monitor delivery on a campaign, so a change in posting pattern or a login from an unfamiliar location gets flagged the way a spike in impressions would
  • A named owner for the account who is accountable for its security posture, not just its content calendar, so there's a single person who can answer "who has access" without a meeting
  • An incident response plan that assumes compromise is possible, not just content approval that assumes it isn't, including who gets notified first and how fast the account can be locked down

None of this replaces the existing brand safety checklist. Converse's ad situation shows the content risk is still real and still requires its own review process, separate from any of this. But the account itself, the badge, the login, the standing audience behind it, is a separate asset with a separate threat model, and right now most brand safety processes don't look at it at all until something has already gone wrong and the ad fraud is already running.

The badge was never proof of anything

The verified badge tells an audience "this account belongs to who it says it belongs to." It never told anyone "and only the people who are supposed to be posting are posting." Those are two different claims, and the second one is the one that actually protects a brand from ad fraud running under its own name. HBO Max's account passed the first test right up until the moment it failed the second one, and the badge never changed.

An audit that only checks the first claim will keep passing accounts that have already been compromised, because the badge doesn't change when the login does. It sits there, verified, credible, trusted, while someone else uses it to run a campaign the brand never approved and would never have approved. The people running brand safety reviews need to stop treating "is this verified" as the end of the question and start treating "who has access right now" as the actual one. The badge was never the security measure. It was just the thing that made everyone stop asking whether one existed.