// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

HBO Max

DISCLOSED 2026-09-18 · STOLEN CREDS

Attackers hijacked HBO Max's verified Reddit account and used it to run 108 malicious ads delivering ClickFix malware to Windows and Mac users. The incident involved unauthorized access to the social media account, likely through stolen credentials. The malware targeted endpoint devices via malicious advertisements.

The record

What we know

Disclosed
2026-09-18
Attack vector
Stolen Creds
Sector
Media/Entertainment
ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

A positive-security model would not directly prevent account hijacking on a third-party platform like Reddit, as the attack vector is credential theft rather than unauthorized changes on endpoints.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the HBO Max disclosure. It updates if new public reporting emerges. All tracked breaches →

HBO Max just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →