Close Cookie Popup
Cookie Preferences
We use cookies to operate our website and personalize your experience, understand how our website is used, and provide relevant advertising. You can accept or reject all optional cookies, or manage your preferences by category. You can change your choice at any time through Cookie Settings. For more information about the cookies we use, please see our Cookie Policy.
Strictly Necessary (Always Active)
Cookies required to enable basic website functionality.
Cookies helping us understand how this website performs, how visitors interact with the site, and whether there may be technical issues.
Cookies used to deliver advertising that is more relevant to you and your interests.
Cookies allowing the website to remember choices you make (such as your user name, language, or the region you are in).

Outside the Perimeter: The CISO Report on Social & Ad Account Security

Naveh Ben Dror
Naveh Ben Dror
CEO & Co-Founder at Spikerz
Published -  
October 1, 2026
Last Updated -  
October 1, 2026
Outside the Perimeter: The CISO Report on Social & Ad Account Security

Summary:

Spikerz's new report for CISOs, Outside the perimeter, looks at the social media and advertising accounts most security programs never cover. Brands find only about 9% of the fake accounts targeting them on their own. Fake social profiles and video accounts make up 88.9% of executive impersonation alerts. Hijacked ad accounts come with no chargeback, and tools documented in 2026 can get past multifactor authentication on them. The fix doesn't need a new framework: NIST, ISO 27001 and SOC 2 already have the controls, but these accounts were never added to the asset register. The report closes with a 12-step, 30-day plan for Q4 2026.

Outside the perimeter: what our new CISO report found about social and ad account security

Every October, Cybersecurity Awareness Month brings the same advice: strong passwords, multifactor authentication, spot the phishing email, patch your software. It’s good advice, and it was built for a perimeter that attackers have been stepping around for years.

Corporate social accounts and advertising accounts barely feature in that conversation. They sit outside the firewall, outside the identity provider, outside the asset register and outside the security budget. Marketing runs them day to day, and in most organizations nobody on the security team has ever written them down as assets.

That’s the gap our new report, Outside the perimeter: Securing your organization’s digital marketing accounts, sets out to measure. It’s written for CISOs and security and governance leaders, and it pulls together published research, regulatory filings and what we see when we start protecting a new brand.

In a hurry? Here’s the short version.

  • Brands find only about 9% of the fake accounts targeting them on their own.1
  • Social media and video platforms carry 88.9% of executive impersonation alerts. Lookalike domains, which most brand protection contracts are built around, carry 3.6%.2
  • There’s no chargeback on a hijacked ad account.3
  • The controls to fix this already exist in NIST, ISO 27001 and SOC 2. The accounts were just never scoped in.

Download the full report or talk to our team to help close your organization's security blind spots.

Two account estates, one blind spot

Almost every organization runs two kinds of externally hosted account that its security team has never inventoried.

The first is the accounts you publish from: corporate profiles on Instagram, LinkedIn, X, Facebook, TikTok and YouTube, plus the regional, product and executive accounts around them. When one is compromised, the attacker inherits an audience that has already decided to believe what it reads there.

The second is the accounts you spend from: Meta Business Manager, Google Ads, TikTok Ads Manager and LinkedIn Campaign Manager. These hold a stored company card and a spending ceiling set by whoever controls the account, and they’re routinely shared with agencies and contractors. When one is compromised, the company pays for the attack directly.

Both estates share the same structural problem. They appear on no asset register, feed no SIEM, fall under no framework scope and have no budget line.

Diagram showing a security perimeter containing the firewall, identity provider, asset register and SIEM. Outside it sit the accounts a company publishes from (Instagram, LinkedIn, X, Facebook, TikTok, YouTube) and the accounts it spends from (Meta Business Manager, Google Ads, TikTok Ads Manager, LinkedIn Campaign Manager), with no asset register entry, SIEM feed, framework scope or budget line.
Social and ad accounts sit outside the controls that protect every other business system.

Brand accounts are under attack, and it’s expensive

The attack against a brand account doesn’t need lateral movement or data exfiltration. The account already reaches the audience, so publishing is the exploit.

The financial picture is clear. Losses to fraud originating on social media reached $2.1 billion in 2025, eight times the 2020 figure, and 70% of social media fraud reports involved money actually lost, the highest rate of any contact method tracked.4 Growth has slowed from 202% in 2021 to 11% in 2025, which is worth reading carefully. Social media fraud has settled into a permanent baseline, and baselines rarely attract the emergency budgets that spikes do.

Breach cost data points the same way. The two most expensive ways attackers get in are voice or SMS phishing ($5.29 million on average) and social engineering such as impersonating the help desk ($5.23 million). Exploiting a public-facing application, the scenario most security programs are built around, is the cheapest at $4.68 million.5

Security leaders already know this. In a survey of 200 CISOs, brand impersonation was the second most common attack they’d experienced, at 31%, ahead of ransomware at 22%. Asked to name a single top priority, the same CISOs put external threats seventh out of eight.6

The report walks through three documented incidents, including the January 2024 takeover of the @SECGov account on X. The SEC’s own statement confirmed that multifactor authentication had been switched off on the account six months earlier, at staff request, because of access difficulties.7

Bar chart of reported losses to fraud originating on social media: $261 million in 2020, $789 million in 2021, $1.2 billion in 2022, $1.5 billion in 2023, $1.9 billion in 2024 and $2.1 billion in 2025. Year-on-year growth fell from 202% to 11%.
Social media fraud losses have grown eightfold since 2020, and growth has now slowed into a permanent baseline.

Ad accounts are an unguarded payment instrument

Accounts payable will query a $5,000 invoice from an unfamiliar supplier. Nobody queries a $500,000 day in Ads Manager, because nobody in finance is looking at it.

Ad account theft now runs as an industry. The only longitudinal dataset we found recorded 6.4 million email detections tied to attacks on advertising accounts over four years, with the second half of 2025 the heaviest period on record.8 Stolen accounts resell for roughly $15 to $340, and aged accounts with real spend history carry a two to fourfold premium because the platform’s trust in them travels with the account.8

In one documented case, a skincare company in India was billed about $1.5 million over two days against a daily budget of roughly $120 to $180.9 The platform’s daily cap didn’t help, because the attacker controlled the account where the cap is set.

When it goes wrong, the recourse is thin. Card fraud comes with chargebacks and liability caps. Google’s published policy says an advertiser may be eligible for reimbursement, paid as account credit, and only after account recovery is complete and two-step verification is on.3

Multifactor authentication on these accounts is good practice, and it’s no longer enough on its own. Research from the past 12 months documented a browser extension that steals the passcode seeds behind two-factor authentication for Meta Business accounts, and a campaign against TikTok Business accounts that captures live session cookies.10,11 Neither theft triggers a login alert.

Comparison table of a corporate card and an advertising account. The card has a statutory liability cap, chargebacks, real-time transaction monitoring, reversal of unauthorized spend and finance review. The ad account has none of these, only possible account credit after recovery, and nobody reviews the spend until the invoice arrives.
A corporate card comes with chargebacks and liability caps. A hijacked ad account comes with neither.

Companies don’t find their own impersonators

This is the finding that surprised our team the most. Across their first 90 days of monitoring, brands and their existing suppliers surfaced around 9% of the confirmed fakes targeting them. 94% of brands caught fewer than half, and the median brand caught none at all.1

Where those fakes appear matters too. In a dataset of 43,035 impersonation alerts raised against 270 named executives, fake social media profiles made up 53.8% and fake video platform accounts 35.1%. Lookalike domains made up 3.6%.2 If your brand protection contract is built around domain monitoring, it’s worth checking which surface you’re actually paying to watch.

Grid of 100 squares with 9 highlighted, showing that brands and their existing suppliers found 9% of confirmed fake accounts, while the monitoring vendor found the other 91%.
In their first 90 days of monitoring, brands found just 9% of the fake accounts targeting them.

Why the security stack can’t see any of it

The report sets out six structural reasons these accounts stay invisible. A few of them:

  • Identity stops short. LinkedIn Campaign Manager and TikTok Ads Manager support neither SSO nor SCIM provisioning, and federation on the other platforms is optional and rarely extended to agency seats.
  • The benchmark measures one channel. The industry’s main phishing benchmark covers 42 million simulations, and every measured result is an email.12
  • Nobody owns it. Asked who owns digital risk, the most common answer among 1,138 security and risk leaders was nobody, at 21%.13
  • There’s no budget line. Average security budget growth in 2026 was 5%, with a median of zero, and no published budget taxonomy has a category for brand, social or advertising assets.14
Table of SSO and SCIM support by platform. Google Ads supports both through a Google account, Meta Business Manager supports both through Work Accounts, and LinkedIn Campaign Manager and TikTok Ads Manager support neither.
Two of the four major ad platforms support neither single sign-on nor automated provisioning.

The frameworks already cover this

It’s often said that compliance frameworks don’t cover social media. They do. NIST SP 800-53 has a control written specifically for social media and external site use (PL-4(1)). ISO 27001 requires an inventory of information assets (A.5.9) and covers cloud services. SOC 2 asks the organization to identify and manage its information assets.

The gap is a scoping decision made inside the organization, which is good news, because it can be fixed without waiting for anyone to publish anything.

Excerpt of a table mapping NIST SP 800-53, NIST CSF 2.0 and ISO/IEC 27001:2022 to social and ad accounts, showing the relevant control IDs, including PL-4(1), ID.AM-02 and A.5.9, and where the gap sits for each framework.
The controls already exist in the frameworks you're audited against. The accounts were just never scoped in.

The regulatory gap is about to close

The SEC’s cybersecurity disclosure rule defines information systems as resources “owned or used by the registrant.” A corporate social account fits that definition on a plain reading. In the rule’s first two years, 29 material incident filings were made, and none concerned a brand or advertising account.15

Our forecast, stated as a forecast, is that the first Item 1.05 filing naming a compromised brand channel will arrive within 24 months, most likely from a company that designated that channel for material disclosure under Regulation FD.

Timeline from December 2023 to July 2026 showing the SEC disclosure rule, the @SECGov account takeover, the FTC impersonation rule, the Nasdaq account incident, the PCI DSS requirements becoming mandatory and the Robinhood CEO account takeover, followed by a forecast of the first Item 1.05 filing naming a compromised brand channel within 24 months.
We expect the first SEC filing naming a compromised brand channel within 24 months.

A 30-day plan for Q4 2026

The report closes with 12 practical actions that fit inside 30 days. Most of them are unglamorous inventory work that nobody has been asked to do yet. Five of them:

  1. Inventory both estates: every social, video, advertising and marketing account, every administrator and every agency seat.
  2. Add them to the asset register under ISO A.5.9 or CSF ID.AM-02.
  3. Put a financial control on the advertising accounts, with spend alerts that reach finance.
  4. Address session tokens as well as passwords, with session timeouts and forced reauthentication on admin roles.
  5. Agree your materiality position for a compromised brand channel before you need it.

The full plan, with all 12 actions and the framework references, is in the report.

Checklist from the 30-day plan: inventory both estates, add them to the asset register, check what your brand protection contract covers, put a financial control on the advertising accounts, and audit third-party access and browser extensions.
The first five of the 12 actions in the report's 30-day plan. The full plan, with framework references, is in the report.

Get the full report

This post covers the headlines. The report is built for what comes next, when you need to take this to your team, your auditor or your board and make the case for fixing it.

Inside, you’ll find:

  • The full 30-day plan. All 12 actions, with the framework reference for each, so you can assign owners and start this quarter.
  • A control-by-control framework map. Exactly where NIST SP 800-53, NIST CSF 2.0, ISO 27001, SOC 2 and PCI DSS already apply to social and ad accounts, ready to hand to your GRC team or auditor.
  • The numbers for your budget case. Every chart and figure is sourced and ready to drop into a board paper or risk register entry, including the side-by-side comparison of a corporate card and an ad account that tends to get the CFO’s attention.
  • The materiality question, worked through. How the SEC’s definition of information systems reaches brand accounts, and what to decide now if your company uses social channels for disclosure.
  • The detail behind the MFA bypasses. How each 2026 technique works, and which controls address session tokens and passcode seeds.

Download the report here

And if you’d like to talk through what your own exposure looks like, including the accounts you hold, the third-party integrations connected to them, and any impersonation running against your brand, book a conversation with our team.

Cover of the Spikerz report "Outside the perimeter: Securing your organization's digital marketing accounts", with the key findings page behind it.
Outside the perimeter: 30 pages, 41 sources and a 12-step plan for Q4 2026.

Sources

  1. Doppel Threat Graph data covering hundreds of brands, April 2025 to March 2026, published in a16z, “Faking a brand is easy. Making it stop is hard,” August 2026.
  2. Outtake Labs, The 2026 State of Executive Impersonation, June 2026. 43,035 alerts raised against 270 named executives.
  3. Google Ads Help, unauthorized charges and reimbursement policy.
  4. Federal Trade Commission, Consumer Protection Data Spotlight, April 2026; Consumer Sentinel Network Data Book.
  5. IBM, Cost of a Data Breach Report 2026. 602 breached organizations, March 2025 to February 2026.
  6. BrandShield, 2025 CyberScam Report. Survey of 200 CISOs across the US, UK and EU, September to October 2024.
  7. US Securities and Exchange Commission, statement on the @SECGov X account compromise, January 2024.
  8. Mimecast Threat Research, Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud, July 2026. Pricing draws on Zscaler analysis, 2023.
  9. ETV Bharat, 29 May 2025, and The420.in, on the Hyderabad Google Ads case.
  10. Socket.dev, malicious Chrome extension stealing Meta Business Manager exports and TOTP seeds, February 2026.
  11. Push Security and BleepingComputer, TikTok for Business phishing campaign, March 2026.
  12. KnowBe4, Phishing by Industry Benchmarking Report, 2026 Edition.
  13. Outtake Labs and Cybersecurity Insiders, 2026 State of Digital Risk Report, June 2026.
  14. IANS Research and Artico Search, 2026 Security Budget Snapshot Benchmark Report.
  15. Debevoise & Plimpton, Form 8-K Cybersecurity Incident Disclosure Tracker, two-year update, May 2026.

Written by:

Naveh Ben Dror

Naveh Ben Dror is the CEO and Co-Founder of Spikerz. Coming from a background in digital marketing, Naveh founded Spikerz after seeing firsthand how damaging a social media account hack can be and realizing brands had few effective ways to protect themselves. Since then, he has worked with hundreds of brands to secure their digital marketing assets and has spent years on the front line of social media security.

Find out where your brand is exposed

Schedule a free social media security review and we'll uncover your biggest blind spots across your accounts.

FAQs

Who is the report for?

CISOs, deputy CISOs, heads of GRC and risk, and anyone responsible for how their organization protects its brand, social and advertising accounts. Marketing leaders will find it useful too, especially the chapters on ad accounts and ownership.

Is the report free?

Yes. You’ll just need to share a few details to download it.

Where does the data come from?

From published industry research, regulatory filings and enforcement records, platform documentation and the frameworks themselves. All 41 sources are listed in the report, with notes on the limits of each dataset.

Does it cover ad accounts as well as social accounts?

Yes. A full chapter covers advertising accounts as a payment instrument, including theft, resale, recourse and the multifactor authentication bypasses documented in 2026.

Is this only relevant to public companies?

No. The regulatory chapter focuses on SEC disclosure, but the account inventory, framework scoping and 30-day plan apply to any organization with brand and ad accounts.