Hackers Compromise HBO Max Reddit Account to Distribute Malware
AI-generated from multiple sources. Verify before acting on this reporting.
LOS ANGELES — Hackers breached the official HBO Max account on Reddit on Sunday, deploying malicious advertisements that infected Windows and macOS devices with information-stealing malware. The cyberattack, which began in the late afternoon hours of September 14, 2026, targeted users seeking updates or links related to the streaming service's content.
The attackers utilized a technique known as "ClickFix," creating deceptive posts that mimicked official troubleshooting guides. These posts urged users to click on links to resolve alleged playback issues or access exclusive features. Instead of providing assistance, the links directed victims to download fraudulent applications containing malware designed to harvest sensitive data. Security analysts identified the payload as capable of stealing login credentials, financial information, and personal files from compromised systems.
The operation appears to be part of a broader campaign aimed at financial gain through multiple vectors. Beyond simple data theft, the malicious software included cryptocurrency clippers, which automatically alter wallet addresses in transaction history to redirect funds to attacker-controlled accounts. Additionally, the campaign distributed fake applications that masqueraded as legitimate tools, further expanding the scope of the intrusion.
The compromise of a verified corporate account on a major social platform significantly amplified the reach of the attack. By leveraging the trust associated with the HBO Max brand, the perpetrators were able to bypass user skepticism that typically guards against phishing attempts. The breach affected users across the United States, where the streaming service maintains its largest subscriber base and where the targeted operating systems are most prevalent.
HBO Max has not yet issued a public statement detailing the extent of the intrusion or the number of accounts potentially exposed. Reddit representatives confirmed that the official account had been unauthorized accessed and were working to secure the channel and remove malicious content. The streaming service's security team is reportedly investigating how the attackers gained initial access to the social media credentials.
Cybersecurity experts warn that users who clicked on links from the compromised account between Sunday afternoon and early Monday morning should immediately change their passwords and scan their devices for malware. The incident highlights the growing risk of supply chain attacks where criminals compromise trusted third-party channels to reach end-users.
Questions remain regarding whether the attackers have moved laterally into other corporate systems or if the breach was isolated to the social media account. Investigators are also examining if similar campaigns are targeting other major entertainment brands using identical methods. As the investigation continues, users are advised to verify official communications directly through the company's primary website rather than relying on social media links.