How to find social media threats to your brand with CompassDRP

In today’s hyperconnected world, a single misleading LinkedIn or X post gone viral can cause problems for the most well established brand in a matter of minutes. Digital Risk Protection plays a vital role in uncovering and neutralizing these hidden dangers before they escalate.

We’ll run through some real-world examples with Outpost24’s CompassDRP solution to show how you can proactively monitor for social media threats before they damage your brand.

Find leaked credentials linked to your domain in minutes.

Protecting your VIPs’ social media reputations

Monitoring the online reputation of executives and public figures is critical. The CompassDRP platform allows you to detect and respond to harmful or misleading content across social media platforms. 

As an example, we’ll show you how we set up monitoring for Amancio Ortega, the founder of Inditex, one of Spain’s largest multinational clothing companies. We’ve chosen him purely as an example of a high-profile businessman and want to make it clear the screenshots highlighted in this article have been flagged by our tool as fake or potentially malicious. For example, below is a Facebook post that could be potentially damaging to his reputation.

Facebook post about Amancio Ortega
Facebook post regarding Amancio Ortega

How to monitor VIP reputation in CompassDRP

  1. Add a seed to define the monitoring scope 
    • Navigate to the DRP platform and go to Settings > Scope. 
    • Create a new Seed with the name: Amancio Ortega.
    • This tells the system to monitor public content on social platforms that mention or relate to this name.
Settings menu in CompassDRP, with 'Scope' highlighted
The Scope option within the Settings dropdown
Seeds option in CompassDRP
Option to Add Seed
Input field for adding seed name, which here reads 'Amancio Ortega'
Adding the name to monitor for
Newly created Amancio Ortega seed listed in DRP platform
Newly created seed
  1. Collect and review results
    • The platform will now fetch relevant mentions from X, Instagram, Facebook, Mastodon, and other supported networks. 
    • To keep things organized, create a custom Label called VIP reputation in the menu Settings > Tags. 
    • When reviewing a result that seems reputationally sensitive, click the item and apply the label. 
Settings menu highlighting 'Tags' option
Tags option within Settings
Screenshot of fields for creating a 'VIP reputation' tag. Fields are Label: VIP reputation, Color: #FF0000 and Description: 'Negative comments or other publications impacting the reputation of the VIP'.
Creating a ‘VIP reputation’ Tag
  1. Annotate and assess impact
    • Click on a result to open it. 
    • Use the Annotation field to add context or a quick analysis. For example: “This tweet contains negative comments on Ortega’s management style, shared by an account with moderate influence.” 
Screenshot of adding a 'VIP reputation' tag.
Selecting your tag in CompassDRP
Screenshot of a summary of a social media post that could affect a VIP's reputation, with fields including 'seed', 'URL', 'title' and 'tags'
Summary of the post that could impact a VIP’s reputation
  1. Dismiss irrelevant results
    • For content that doesn’t pose a risk (e.g., neutral mentions or spam), you can mark them as “Dismissed”. 
    • To do this, select the result, click Dismiss, and optionally leave a note like: “Generic news mention, no risk.” 
    • You can also bulk dismiss multiple items: select several posts, click the Actions dropdown, and choose Bulk Dismiss. 
Screenshot of a pop up reading 'you are dismissing 1 social media'. A text field beneath it reads 'the publication was dismissing because it is a purely informative video'.
Dismissing a post as non-damaging
  1. Follow up on potentially damaging posts
    • Below are some examples of posts that were flagged as potentially reputationally damaging and would be worth looking into further. In this example, the posts included:
      • A Mastodon post containing criticism towards Ortega’s business practices
      • X posts including negative commentary on his personal wealth, accusations of tax evasion, and satirical content
      • An Instagram image with hostile imagery
List of potentially damaging social media posts found by CompassDRP, with 'VIP reputation' tags
List of potentially damaging social media posts uncovered by CompassDRP
Asset discovery + threat intelligence powered DRP.

Spotting deepfake social media profiles and impersonation

Another common use case for CompassDRP is identifying and flagging fake social media accounts that impersonate individuals or brands. These can damage trust and mislead the public. The use of deepfake technology to impersonate relevant executives can be highly convincing, and even if eventually proven to be fake, can have a serious negative impact. For example, this deepfake of Spanish businessman Juan Roig after recent flooding in Valencia.  

Below are also two examples of fake Facebook profiles we found pretending to be Amancio Ortega or affiliated with him. The first appears to be an unofficial foundation page and the second is a fake profile.

Screenshot of a fake Facebook page called 'Amancio Ortega FFoundation' with 5.6 million likes
Unofficial Facebook foundation page
Screenshot of a fake Facebook profile called 'Amancio Ortega'.
Fake Facebook profile of Amancio

The below X accounts also appear to impersonate Amancio Ortega and could mislead followers or promote fraudulent content. Such profiles should be documented, tagged, and reported for takedown where appropriate. 

Screenshot of a fake X profile for Amancio Ortega with 8,094 followers
Fake X profile with over 8,000 followers
Screenshot of a fake X profile for Amancio Ortega with 445 followers
Unofficial X account posting negative comments

How to find and tag fake profiles with CompassDRP 

  1. Add names and aliases to Scope 
    • Go to Scope settings. 
    • Add variations of the person’s name: e.g., Amancio Ortega, AmancioOrtega, A Ortega. 
  2. Review suspicious profiles
    • Open each result and evaluate based on: 
      • Username 
      • Profile photo (does it reuse official media?) 
      • Bio or claims (e.g., “Official page”) 
      • Content posted (reposts, scams, or spam?)
  3. Label and comment 
    • Apply the label VIP fake profile. 
    • Add an Annotation if needed. For example: “Fake charity foundation impersonating Amancio Ortega, likely for scam purposes.” 
Screenshot showing how to label a profile as likely fake in CompassDRP platform. The tag reads 'VIP fake profile'.
Labelling a profile as a likely fake

Discovering social media boycotts against your brand

CompassDRP’s social media module also allows you to follow keywords tracking posts threatening your brand’s reputation by promoting a boycott against your products and services. For example, the influential hacktivist group Anonymous with 5.3 million followers’ recently advocated for the boycott of Tesla due to political reasons. Users can identify and tag accounts promoting boycotts, as well as view their engagement metrics.

Screenshot of how to identify and tag an account pushing a boycott in CompassDRP platform
Identifying and tagging an account pushing a boycott

Detecting social media scams

The CompassDRP platform can also detect social media scams that involve impersonation, phishing, or fraudulent content tied to your organization or its representatives. An example we’ve uncovered shows the use of the Mistral AI name to promote a scam scheme in the Philippines through Facebook and Telegram.

Our tool helps to identify social media groups promoting the scam, summarizing and translating the posts within. It’s possible to initiate a further scam investigation from the initial information retrieved by the platform, and collect more information from regions where scams are widespread. 

Facebook post in a group called 'Legit Investment Platform | Ingat guys MA MISTRAL AI' showing screenshots of Mistral AI scam.
Screenshots of Mistral AI scam from Facebook and Telegram
Screenshot of Mistral AI scam flagged in CompassDRP platform
Mistral AI scam flagged within CompassDRP

How to identify and handle scam posts

  1. Monitor for suspicious behavior 
    • You can search through results that include suspicious terms like “click here to donate”, “urgent help”, “official crypto giveaway”, or “prize”. 
    • Combined with fake profiles, these are clear red flags. 
Screenshot of potential scams listed by CompassDRP platform
CompassDRP listing potential scams
  1. Review the flagged content 
    • Examine the full post and user history if possible. 
    • Look for links to unknown domains, urgency tactics, or impersonation of brands/people.
  2. Label and annotate 
    • Tag the post as a Scam. 
    • For example, the below Mastodon post was flagged as a scam running a fake prize targeting Mercadona customers.
    • Add an annotation describing the potential scam – in this example, it could be: “News sharing a scam affecting Mercadona”. 
Screenshot of Mastodon post flagged as a scam, which reads 'Copian a Mercadona con un sorteo falso de 729 euros de premios a los clientes. La cadena de supermercados española aclara en su página web que no organiza sorteos, promociones ni regala vales de compra.
Mastodon post flagged as a scam
Screenshot demonstrating adding a 'scam' tag in CompassDRP
Adding a ‘Scam’ Tag within CompassDRP
Screenshot of a pop-up box that says 'add annotation', with a text field reading 'News sharing a scam affecting Mercadona'
Adding an annotation within CompassDRP
Screenshot of Mercadona scam summary in CompassDRP, with fields including 'seed', 'URL', 'title', 'tags' and 'summary'.
Summary of the Mercadona scam

Try Outpost24’s unified EASM + DRP Platform

By combining the new Social Media module with the existing Data Leakage, Leaked Credentials and Dark Web integrations, Outpost24’s CompassDRP delivers a holistic view of an organization’s external risk landscape. This unified approach empowers security teams to:

  1. Discover all external exposures (from credentials to social profiles).
  2. Prioritize based on threat intelligence severity and context.
  3. React swiftly through automated alerts and actionable insights.

CompassDRP helps organizations to protect their reputation, reduce phishing and fraud risk, and safeguard sensitive assets before attackers can exploit them. Book a live demo.

Find leaked credentials linked to your domain in minutes.

About the Author

Marcus White Cybersecurity Specialist, Outpost24

Marcus is an Outpost24 cybersecurity specialist based in the UK, with 8+ years experience in the tech and cyber sectors. He writes about attack surface management, application security, threat intelligence, and compliance.