Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

Athletes as Brands: Securing 24/7 Public Figures in the Social Media Era

Athletes are now 24/7 brands, and that makes them prime targets for deepfakes and impersonation. Learn how NFL security leaders are adapting and how digital risk protection helps close the gap.

Athletes as Brands: Securing 24/7 Public Figures in the Social Media Era

A generation ago, an NFL player's public exposure was largely limited to Sundays in the fall.

Today, that same player might be posting workout videos at 6 AM, launching a merchandise drop by lunch, and doing a sponsored livestream that night…365 days a year. That shift has quietly created one of the strangest and most demanding categories in corporate security: protecting people who are, in effect, always-on media companies.

In a recent webinar (opens in new tab), Kosta Klarianos, EVP and Head of Technology for the San Francisco 49ers, and Christina Murillo, Sr. Director and Head of Information Security for the New York Giants, described what it actually takes to defend athletes' identities and brands (opens in new tab) in an environment where impersonation is easy, constant, and increasingly convincing.

In this blog, we'll look at why athletes have effectively become 24/7 media brands, what that shift means for the teams responsible for protecting them, and why old-school verification habits no longer hold up against AI-generated impersonation (opens in new tab).

A real-life Truman Show

Klarianos summed up the shift bluntly: the industry has changed so much that players are now their own businesses, active around the clock on social media building personal brands.

In his words, it's become "a real-life Truman Show.” Every moment is public, every post is content, and every account is a potential target.

That visibility is a double-edged sword. It's what makes athletes marketable and their personal brands valuable. It's also exactly what makes them easy to impersonate.

The impersonation problem is bigger than it sounds

Murillo pointed out earlier in the conversation that professional sports organizations face a different scale of exposure than most companies because so many people inside them are recognizable public figures, not just the CEO. We’re talking coaches, players, and even some staff.

Klarianos took that further, noting that fake accounts and deepfake content (opens in new tab) aimed at star players are now "scary good," to the point where impersonators can convincingly pose as a specific athlete to target internal staff, not just the public.

That creates two distinct but related problems security teams have to solve simultaneously:

  1. External impersonation: Fake accounts, deepfaked videos, or cloned content used to scam fans, sell counterfeit merchandise, or damage a player's reputation.
  2. Internal social engineering: Attackers impersonating a well-known player or executive (opens in new tab) to manipulate employees into taking an action they shouldn't (approving a payment, sharing credentials, granting access).

Both require round-the-clock monitoring. Klarianos described this as a genuinely 24/7 responsibility. Impersonation attempts (opens in new tab), brand misuse, and IP theft don't clock out at 5 PM, and neither can the teams monitoring for them.

Why the old "eye test" isn't enough anymore

Historically, spotting a fake was a matter of common sense: an obviously staged photo, a poorly worded scam message, an account with none of the right followers.

Klarianos was candid that this "eye test" is no longer reliable on its own. AI-generated content has gotten good enough that convincing fakes can fool even careful observers, which means organizations increasingly need to fight AI-generated lures with AI-powered detection tools alongside human review rather than relying on instinct alone.

Murillo echoed this from the human side, emphasizing that verification protocols matter more than ever. If someone claiming to be a player calls a staff member, that staff member needs a way to confirm it's really them. Phone numbers, voices, and even video can be spoofed. Her team leans on face-to-face communication and pre-established offline channels specifically because digital channels (opens in new tab) alone can no longer be trusted at face value.

What this means for personal brand protection

A few practical threads emerged from the conversation that apply well beyond football:

  • Monitor beyond your own house. Klarianos was direct about the need to watch the dark web, social platforms, and even crypto-scam ecosystems for misuse of a player's name, image, or likeness, not just internal systems.
  • Treat identity like currency. His framing was memorable: organizations need to protect their people's identities with the same seriousness they protect their money, "because they are the same thing."
  • Build verification into the culture, not just the tech stack. Multi-channel confirmation (e.g., a callback, a known offline contact, a second form of verification) has to become routine for anyone with the authority to act on a request that claims to come from a high-profile individual.
  • Make brand protection a shared responsibility. IP theft, impersonation, and reputational risk increasingly sit at the intersection of security, marketing, legal, and player relations, not any one department alone.

Where external monitoring comes in

Everything we just described, from deepfake impersonation to crypto scams riding on a player's name, happens outside the four walls of a team's network. Internal security tools, no matter how good, aren't built to see it. That's the gap external digital risk protection (opens in new tab) is designed to close.

At a high level, a digital risk protection platform (opens in new tab) continuously scans the open web, social platforms, app stores, and the dark web for signs of impersonation: fake accounts posing as a player or executive, cloned domains, counterfeit merchandise listings, and deepfaked video or audio (opens in new tab).

Instead of waiting for a fan or staff member to spot and report a fake account, security teams get visibility into impersonation attempts as they emerge, which shortens the window between "a fake exists" and "a fake gets taken down."

That doesn't replace the internal practices Murillo and Klarianos described: verification protocols, offline confirmation channels, employee education. It complements them. Internal controls stop an attacker from tricking your people; external monitoring stops an attacker from building a convincing presence in the first place.

Together, they cover both sides of the identity-protection equation that professional sports organizations, and increasingly every brand with a public-facing name, now have to solve.

The bigger picture

Athletes aren't the only people living this reality. Executives, creators, public officials, and increasingly rank-and-file employees with any online presence are all exposed to some version of the same risk as deepfake tools get cheaper and more convincing.

Sports organizations, because of how early and how intensely they've had to deal with this, are becoming an unlikely proving ground for identity-protection practices that the rest of the corporate world will need to adopt soon enough.

As Klarianos put it, the tools and the threats keep evolving, which means the defense has to be just as adaptable, and just as relentless, as the athletes' own social media presence.

If you're evaluating how to get ahead of impersonation, deepfakes, and brand abuse before they reach your fans, employees, or players, see Doppel's Digital Risk Protection solution in action (opens in new tab).

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.