Athletes as Brands: Securing 24/7 Public Figures in the Social Media Era

A generation ago, an NFL player’s public exposure was largely limited to Sundays in the fall. Today, that same player might be posting workout videos at 6 AM, launching a merchandise drop by lunch, and doing a sponsored livestream that night…365…

Security Boulevard
威胁情报APT活动网络犯罪钓鱼攻击

A generation ago, an NFL player’s public exposure was largely limited to Sundays in the fall. 

Today, that same player might be posting workout videos at 6 AM, launching a merchandise drop by lunch, and doing a sponsored livestream that night…365 days a year. That shift has quietly created one of the strangest and most demanding categories in corporate security: protecting people who are, in effect, always-on media companies.

In a recent webinar, Kosta Klarianos, EVP and Head of Technology for the San Francisco 49ers, and Christina Murillo, Sr. Director and Head of Information Security for the New York Giants, described what it actually takes to defend athletes’ identities and brands in an environment where impersonation is easy, constant, and increasingly convincing.

In this blog, we’ll look at why athletes have effectively become 24/7 media brands, what that shift means for the teams responsible for protecting them, and why old-school verification habits no longer hold up against AI-generated impersonation.

A real-life Truman Show

Klarianos summed up the shift bluntly: the industry has changed so much that players are now their own businesses, active around the clock on social media building personal brands. 

In his words, it’s become “a real-life Truman Show.” Every moment is public, every post is content, and every account is a potential target.

That visibility is a double-edged sword. It’s what makes athletes marketable and their personal brands valuable. It’s also exactly what makes them easy to impersonate.

The impersonation problem is bigger than it sounds

Murillo pointed out earlier in the conversation that professional sports organizations face a different scale of exposure than most companies because so many people inside them are recognizable public figures, not just the CEO. We’re talking coaches, players, and even some staff. 

Klarianos took that further, noting that fake accounts and deepfake content aimed at star players are now “scary good,” to the point where impersonators can convincingly pose as a specific athlete to target internal staff, not just the public.

That creates two distinct but related problems security teams have to solve simultaneously:

  1. External impersonation: Fake accounts, deepfaked videos, or cloned content used to scam fans, sell counterfeit merchandise, or damage a player’s reputation.
  2. Internal social engineering: Attackers impersonating a well-known player or executive to manipulate employees into taking an action they shouldn’t (approving a payment, sharing credentials, granting access).

Both require round-the-clock monitoring. Klarianos described this as a genuinely 24/7 responsibility. Impersonation attempts, brand misuse, and IP theft don’t clock out at 5 PM, and neither can the teams monitoring for them.

Why the old “eye test” isn’t enough anymore

Historically, spotting a fake was a matter of common sense: an obviously staged photo, a poorly worded scam message, an account with none of the right followers. 

Klarianos was candid that this “eye test” is no longer reliable on its own. AI-generated content has gotten good enough that convincing fakes can fool even careful observers, which means organizations increasingly need to fight AI-generated lures with AI-powered detection tools alongside human review rather than relying on instinct alone.

Murillo echoed this from the human side, emphasizing that verification protocols matter more than ever. If someone claiming to be a player calls a staff member, that staff member needs a way to confirm it’s really them. Phone numbers, voices, and even video can be spoofed. Her team leans on face-to-face communication and pre-established offline channels specifically because digital channels alone can no longer be trusted at face value.

What this means for personal brand protection

A few practical threads emerged from the conversation that apply well beyond football:

Where external monitoring comes in

Everything we just described, from deepfake impersonation to crypto scams riding on a player’s name, happens outside the four walls of a team’s network. Internal security tools, no matter how good, aren’t built to see it. That’s the gap external digital risk protection is designed to close.

At a high level, a digital risk protection platform continuously scans the open web, social platforms, app stores, and the dark web for signs of impersonation: fake accounts posing as a player or executive, cloned domains, counterfeit merchandise listings, and deepfaked video or audio

Instead of waiting for a fan or staff member to spot and report a fake account, security teams get visibility into impersonation attempts as they emerge, which shortens the window between “a fake exists” and “a fake gets taken down.”

That doesn’t replace the internal practices Murillo and Klarianos described: verification protocols, offline confirmation channels, employee education. It complements them. Internal controls stop an attacker from tricking your people; external monitoring stops an attacker from building a convincing presence in the first place. 

Together, they cover both sides of the identity-protection equation that professional sports organizations, and increasingly every brand with a public-facing name, now have to solve.

The bigger picture

Athletes aren’t the only people living this reality. Executives, creators, public officials, and increasingly rank-and-file employees with any online presence are all exposed to some version of the same risk as deepfake tools get cheaper and more convincing. 

Sports organizations, because of how early and how intensely they’ve had to deal with this, are becoming an unlikely proving ground for identity-protection practices that the rest of the corporate world will need to adopt soon enough.

As Klarianos put it, the tools and the threats keep evolving, which means the defense has to be just as adaptable, and just as relentless, as the athletes’ own social media presence.

If you’re evaluating how to get ahead of impersonation, deepfakes, and brand abuse before they reach your fans, employees, or players, see Doppel’s Digital Risk Protection solution in action.