← Home
CYBERSECURITY

Hackers Hijack HBO Max Reddit Account to Spread Malware via ClickFix Ads

September 22, 2026 Lawrence Abrams

How the Breach Went Undetected Initially

The attackers exploited the trusted status of HBO Max's Reddit presence to bypass user skepticism, crafting ads that appeared legitimate but delivered payloads capable of harvesting sensitive data. ClickFix, a technique that manipulates browser behavior to force unwanted downloads, was used to install malware without direct user interaction beyond clicking the ad. Researchers noted the campaign focused on stealing login credentials, financial details, and personal files from infected devices, with evidence suggesting the operation had been active for several hours before detection.

The hijacking remained unnoticed for a period because the malicious posts mimicked typical promotional content HBO Max might share, such as show updates or special offers. This allowed the ads to blend into the account’s normal feed, reducing suspicion among followers. Hudson Rock analysts explained that attackers often time such intrusions during high-traffic periods to maximize reach, and in this case, the timing coincided with a major weekend release on the platform. The use of a verified account also meant the posts avoided automatic spam filters that might flag unfamiliar sources.

What Steps Are Being Taken to Prevent Recurrence

Following the discovery, HBO Max immediately revoked access to the compromised Reddit account and issued a security alert to users warning them not to engage with recent posts from the profile. The company confirmed it is working with Reddit’s security team to investigate how the credentials were stolen and to strengthen authentication protocols. Experts recommend that organizations implement multi-factor authentication and regular access audits for social media accounts, especially those with large followings, to reduce the risk of similar hijackings.

How did hackers gain control of the HBO Max Reddit account? Researchers believe the attackers obtained login credentials through phishing or malware-infected devices used by HBO Max’s social media team, though the exact method remains under investigation.

Frequently Asked Questions

Can users who clicked the ads remove the malware themselves? Security advisors recommend running a full system scan with updated antivirus software and changing passwords for any accounts accessed on the affected device, as the malware may persist without professional removal tools.

Is HBO Max user data at risk from this breach? The attack targeted individuals who interacted with the malicious ads, not HBO Max’s internal systems, so subscriber databases and streaming infrastructure were not compromised according to current findings.

Read full article on Tech Site News →