Outside the Perimeter: The CISO Report on Social & Ad Account Security
Summary:
Spikerz's new report for CISOs, Outside the perimeter, looks at the social media and advertising accounts most security programs never cover. Brands find only about 9% of the fake accounts targeting them on their own. Fake social profiles and video accounts make up 88.9% of executive impersonation alerts. Hijacked ad accounts come with no chargeback, and tools documented in 2026 can get past multifactor authentication on them. The fix doesn't need a new framework: NIST, ISO 27001 and SOC 2 already have the controls, but these accounts were never added to the asset register. The report closes with a 12-step, 30-day plan for Q4 2026.
Outside the perimeter: what our new CISO report found about social and ad account security
Every October, Cybersecurity Awareness Month brings the same advice: strong passwords, multifactor authentication, spot the phishing email, patch your software. It’s good advice, and it was built for a perimeter that attackers have been stepping around for years.
Corporate social accounts and advertising accounts barely feature in that conversation. They sit outside the firewall, outside the identity provider, outside the asset register and outside the security budget. Marketing runs them day to day, and in most organizations nobody on the security team has ever written them down as assets.
That’s the gap our new report, Outside the perimeter: Securing your organization’s digital marketing accounts, sets out to measure. It’s written for CISOs and security and governance leaders, and it pulls together published research, regulatory filings and what we see when we start protecting a new brand.
In a hurry? Here’s the short version.
- Brands find only about 9% of the fake accounts targeting them on their own.1
- Social media and video platforms carry 88.9% of executive impersonation alerts. Lookalike domains, which most brand protection contracts are built around, carry 3.6%.2
- There’s no chargeback on a hijacked ad account.3
- The controls to fix this already exist in NIST, ISO 27001 and SOC 2. The accounts were just never scoped in.
Download the full report or talk to our team to help close your organization's security blind spots.
Two account estates, one blind spot
Almost every organization runs two kinds of externally hosted account that its security team has never inventoried.
The first is the accounts you publish from: corporate profiles on Instagram, LinkedIn, X, Facebook, TikTok and YouTube, plus the regional, product and executive accounts around them. When one is compromised, the attacker inherits an audience that has already decided to believe what it reads there.
The second is the accounts you spend from: Meta Business Manager, Google Ads, TikTok Ads Manager and LinkedIn Campaign Manager. These hold a stored company card and a spending ceiling set by whoever controls the account, and they’re routinely shared with agencies and contractors. When one is compromised, the company pays for the attack directly.
Both estates share the same structural problem. They appear on no asset register, feed no SIEM, fall under no framework scope and have no budget line.

Brand accounts are under attack, and it’s expensive
The attack against a brand account doesn’t need lateral movement or data exfiltration. The account already reaches the audience, so publishing is the exploit.
The financial picture is clear. Losses to fraud originating on social media reached $2.1 billion in 2025, eight times the 2020 figure, and 70% of social media fraud reports involved money actually lost, the highest rate of any contact method tracked.4 Growth has slowed from 202% in 2021 to 11% in 2025, which is worth reading carefully. Social media fraud has settled into a permanent baseline, and baselines rarely attract the emergency budgets that spikes do.
Breach cost data points the same way. The two most expensive ways attackers get in are voice or SMS phishing ($5.29 million on average) and social engineering such as impersonating the help desk ($5.23 million). Exploiting a public-facing application, the scenario most security programs are built around, is the cheapest at $4.68 million.5
Security leaders already know this. In a survey of 200 CISOs, brand impersonation was the second most common attack they’d experienced, at 31%, ahead of ransomware at 22%. Asked to name a single top priority, the same CISOs put external threats seventh out of eight.6
The report walks through three documented incidents, including the January 2024 takeover of the @SECGov account on X. The SEC’s own statement confirmed that multifactor authentication had been switched off on the account six months earlier, at staff request, because of access difficulties.7

Ad accounts are an unguarded payment instrument
Accounts payable will query a $5,000 invoice from an unfamiliar supplier. Nobody queries a $500,000 day in Ads Manager, because nobody in finance is looking at it.
Ad account theft now runs as an industry. The only longitudinal dataset we found recorded 6.4 million email detections tied to attacks on advertising accounts over four years, with the second half of 2025 the heaviest period on record.8 Stolen accounts resell for roughly $15 to $340, and aged accounts with real spend history carry a two to fourfold premium because the platform’s trust in them travels with the account.8
In one documented case, a skincare company in India was billed about $1.5 million over two days against a daily budget of roughly $120 to $180.9 The platform’s daily cap didn’t help, because the attacker controlled the account where the cap is set.
When it goes wrong, the recourse is thin. Card fraud comes with chargebacks and liability caps. Google’s published policy says an advertiser may be eligible for reimbursement, paid as account credit, and only after account recovery is complete and two-step verification is on.3
Multifactor authentication on these accounts is good practice, and it’s no longer enough on its own. Research from the past 12 months documented a browser extension that steals the passcode seeds behind two-factor authentication for Meta Business accounts, and a campaign against TikTok Business accounts that captures live session cookies.10,11 Neither theft triggers a login alert.

Companies don’t find their own impersonators
This is the finding that surprised our team the most. Across their first 90 days of monitoring, brands and their existing suppliers surfaced around 9% of the confirmed fakes targeting them. 94% of brands caught fewer than half, and the median brand caught none at all.1
Where those fakes appear matters too. In a dataset of 43,035 impersonation alerts raised against 270 named executives, fake social media profiles made up 53.8% and fake video platform accounts 35.1%. Lookalike domains made up 3.6%.2 If your brand protection contract is built around domain monitoring, it’s worth checking which surface you’re actually paying to watch.

Why the security stack can’t see any of it
The report sets out six structural reasons these accounts stay invisible. A few of them:
- Identity stops short. LinkedIn Campaign Manager and TikTok Ads Manager support neither SSO nor SCIM provisioning, and federation on the other platforms is optional and rarely extended to agency seats.
- The benchmark measures one channel. The industry’s main phishing benchmark covers 42 million simulations, and every measured result is an email.12
- Nobody owns it. Asked who owns digital risk, the most common answer among 1,138 security and risk leaders was nobody, at 21%.13
- There’s no budget line. Average security budget growth in 2026 was 5%, with a median of zero, and no published budget taxonomy has a category for brand, social or advertising assets.14

The frameworks already cover this
It’s often said that compliance frameworks don’t cover social media. They do. NIST SP 800-53 has a control written specifically for social media and external site use (PL-4(1)). ISO 27001 requires an inventory of information assets (A.5.9) and covers cloud services. SOC 2 asks the organization to identify and manage its information assets.
The gap is a scoping decision made inside the organization, which is good news, because it can be fixed without waiting for anyone to publish anything.

The regulatory gap is about to close
The SEC’s cybersecurity disclosure rule defines information systems as resources “owned or used by the registrant.” A corporate social account fits that definition on a plain reading. In the rule’s first two years, 29 material incident filings were made, and none concerned a brand or advertising account.15
Our forecast, stated as a forecast, is that the first Item 1.05 filing naming a compromised brand channel will arrive within 24 months, most likely from a company that designated that channel for material disclosure under Regulation FD.

A 30-day plan for Q4 2026
The report closes with 12 practical actions that fit inside 30 days. Most of them are unglamorous inventory work that nobody has been asked to do yet. Five of them:
- Inventory both estates: every social, video, advertising and marketing account, every administrator and every agency seat.
- Add them to the asset register under ISO A.5.9 or CSF ID.AM-02.
- Put a financial control on the advertising accounts, with spend alerts that reach finance.
- Address session tokens as well as passwords, with session timeouts and forced reauthentication on admin roles.
- Agree your materiality position for a compromised brand channel before you need it.
The full plan, with all 12 actions and the framework references, is in the report.

Get the full report
This post covers the headlines. The report is built for what comes next, when you need to take this to your team, your auditor or your board and make the case for fixing it.
Inside, you’ll find:
- The full 30-day plan. All 12 actions, with the framework reference for each, so you can assign owners and start this quarter.
- A control-by-control framework map. Exactly where NIST SP 800-53, NIST CSF 2.0, ISO 27001, SOC 2 and PCI DSS already apply to social and ad accounts, ready to hand to your GRC team or auditor.
- The numbers for your budget case. Every chart and figure is sourced and ready to drop into a board paper or risk register entry, including the side-by-side comparison of a corporate card and an ad account that tends to get the CFO’s attention.
- The materiality question, worked through. How the SEC’s definition of information systems reaches brand accounts, and what to decide now if your company uses social channels for disclosure.
- The detail behind the MFA bypasses. How each 2026 technique works, and which controls address session tokens and passcode seeds.
And if you’d like to talk through what your own exposure looks like, including the accounts you hold, the third-party integrations connected to them, and any impersonation running against your brand, book a conversation with our team.

Sources
- Doppel Threat Graph data covering hundreds of brands, April 2025 to March 2026, published in a16z, “Faking a brand is easy. Making it stop is hard,” August 2026.
- Outtake Labs, The 2026 State of Executive Impersonation, June 2026. 43,035 alerts raised against 270 named executives.
- Google Ads Help, unauthorized charges and reimbursement policy.
- Federal Trade Commission, Consumer Protection Data Spotlight, April 2026; Consumer Sentinel Network Data Book.
- IBM, Cost of a Data Breach Report 2026. 602 breached organizations, March 2025 to February 2026.
- BrandShield, 2025 CyberScam Report. Survey of 200 CISOs across the US, UK and EU, September to October 2024.
- US Securities and Exchange Commission, statement on the @SECGov X account compromise, January 2024.
- Mimecast Threat Research, Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud, July 2026. Pricing draws on Zscaler analysis, 2023.
- ETV Bharat, 29 May 2025, and The420.in, on the Hyderabad Google Ads case.
- Socket.dev, malicious Chrome extension stealing Meta Business Manager exports and TOTP seeds, February 2026.
- Push Security and BleepingComputer, TikTok for Business phishing campaign, March 2026.
- KnowBe4, Phishing by Industry Benchmarking Report, 2026 Edition.
- Outtake Labs and Cybersecurity Insiders, 2026 State of Digital Risk Report, June 2026.
- IANS Research and Artico Search, 2026 Security Budget Snapshot Benchmark Report.
- Debevoise & Plimpton, Form 8-K Cybersecurity Incident Disclosure Tracker, two-year update, May 2026.
