YouTube creators are being targeted by scammers offering attractive brand partnerships that can ultimately lead to stolen Google accounts. According to cybersecurity company ESET, the campaign uses personalized emails and convincing collaboration websites to make fraudulent sponsorship opportunities appear legitimate.

 

 

The attackers impersonate recognizable companies, including Hollyland, Nike, and Spotify. Rather than immediately requesting sensitive information, they approach creators with offers that resemble ordinary business negotiations, sometimes referencing specific videos to make the proposal more convincing.

ESET examined one case involving a journalist in Peru who received an email supposedly from Hollyland’s creator partnerships team. The sender offered a product and potential long-term cooperation, but the email came from a domain unrelated to the company.

After the recipient responded with her rates, the supposed representative directed her to a website where she was asked to verify her YouTube statistics and arrange the partnership.

The fraudulent platform featured professional-looking branding, earnings estimates, and tools supposedly designed to manage contracts and payments. It also retrieved publicly available information from the creator’s YouTube channel, making the experience appear personalized.

According to ESET, the most dangerous stage came when creators were asked to sign in with Google to confirm ownership of their channels.

A genuine Google authorization page may request access to information or permissions that could allow a third-party service to manage a YouTube channel. A fake login page, however, can steal passwords and verification codes, potentially giving criminals control of the entire Google account.

ESET highlighted an account takeover reported by a creator who encountered a version of the scam. The attackers reportedly replaced her recovery phone number and email address and added their own backup codes, making it difficult for her to regain access.

The researchers identified similar websites operating under different names, including variants using “Scouty.” ESET found that these sites shared technical elements despite impersonating different brands, suggesting the scammers could repeatedly adapt the same scheme.

The campaign has targeted creators in multiple countries, including Peru and Japan, with fraudulent domains changing between June and August.

ESET recommends independently verifying sponsorship offers through official company channels and checking website addresses before signing in. Creators should also examine requested Google permissions, avoid granting unnecessary account access, and use strong authentication methods.

Anyone who suspects their account has been compromised should review connected applications, recovery settings, and recent login activity through Google’s official security tools. If access has already been lost, Google’s account recovery process is the appropriate next step.

Leave a Reply