Hackers Hijack YouTube Channels Through Fake Sponsorship Offers From Major Brands

09.10.2026 7 minutes Author: Newsman

Cybercriminals are targeting YouTube creators on a massive scale, posing as representatives of well-known companies and offering lucrative sponsorship deals. Under the pretense of channel verification, they lure creators to fake websites, steal their Google login credentials, and take control of their accounts.

ESET cybersecurity researchers have warned about a new scam campaign targeting YouTube content creators. Attackers send personalized sponsorship offers on behalf of well-known brands and then direct potential partners to fake platforms for arranging advertising deals. On these websites, creators are asked to verify ownership of their channels through Google, but instead of completing a legitimate authentication process, they risk handing over their passwords and one-time verification codes to scammers.

Unlike traditional phishing attacks, which immediately ask users to enter sensitive information, this scheme is designed to resemble a complete advertising contract process. Scammers use real company names, personalized emails, actual YouTube channel statistics, and convincing website designs. As a result, the offer can appear to be a perfectly legitimate business partnership.

Fake Sponsorship Deals Lead to Google Account Theft

One of the companies whose name is being exploited by the attackers is Hollyland, a manufacturer of wireless video transmission equipment and professional audiovisual technology. Scammers impersonate its employees, offer YouTube creators opportunities to promote products, and discuss the terms of potential partnerships.

One victim shared her experience on Facebook back in July. She received an email offering a sponsorship deal, searched for the company on Google, and confirmed that Hollyland was a legitimate business.

“I received an email offering an influencer sponsorship deal. I Googled the company, and it turned out to be real (Hollyland).”

After clicking the link, the creator was redirected to a website designed to imitate a professional platform connecting influencers with advertisers. The service offered to analyze her YouTube channel, estimate potential earnings, and verify the channel before finalizing a contract. When she clicked the “Check channel” button, the system prompted her to sign in with Google. According to the victim, the login request appeared twice.

At that point, the woman became suspicious and attempted to secure her account, but it was already too late.

“I immediately stopped, went to my Google account to check what was happening and change my password. But by then, they had already accessed my account, removed my phone number, recovery email, and other details, and replaced them with their own,” the victim explained.

According to ESET, the attackers also added their own backup recovery codes to make it more difficult for the legitimate account owner to regain access.

Scammers Use Personalized Emails and Real Channel Statistics

In its research report, ESET described another incident involving a journalist from Peru. She received an email with the subject line “Paid collaboration opportunity” from someone identifying herself as Brandi, who claimed to work in Hollyland’s creator partnerships department.

Fake sponsorship offer. Image provided by ESET.

The email referenced specific videos from her YouTube channel and included an offer for a long-term partnership. The scammers even promised to provide a device for a sponsored review, making the message resemble a legitimate proposal from a technology manufacturer. When the journalist responded with her advertising rates, the fake Hollyland representative directed her to joinmatchy[.]com/hollyland, where she was supposedly able to review her channel statistics, approve the contract, and confirm payment.

The fraudulent platform looked convincing. It featured logos of major companies, advertising campaign statistics, a potential earnings calculator, and tools for managing contracts and payments. The website also requested a link to the creator’s YouTube channel and then retrieved publicly available information about it. This created the impression that the platform was genuinely analyzing the creator’s channel and preparing a personalized offer.

Only after completing these steps were users redirected to a Google sign-in page, supposedly to verify channel ownership. This was the point at which the scammers attempted to steal the credentials needed to take over the account.

Why Signing In With Google Can Become a Trap

Researchers explain that the legitimate Sign in with Google feature is not inherently dangerous. Under normal circumstances, it shares only the user’s name, email address, and profile picture with a third-party service. Additional permissions, such as managing a YouTube channel, require separate authorization.

However, a fraudulent login page can look almost identical to the real one. If users enter their password and one-time verification code on such a page, that information is sent directly to the attackers. Once they gain access to a Google account, the scammers can change the phone number, recovery email address, and account recovery methods, effectively locking out the legitimate owner.

The consequences extend beyond YouTube itself. A Google account is often connected to Gmail, Google Drive, contacts, and other services that may contain personal messages, work documents, and confidential information. A hijacked YouTube channel can also be used to distribute malicious links, promote additional scams, or deceive subscribers who trust the creator.

Fake Advertising Campaigns Impersonate Nike, Spotify, and Other Brands

Hollyland is just one of the brands being impersonated by scammers. The company itself has already warned content creators about fraudulent offers on Instagram. ESET researchers have also identified similar schemes disguised as advertising campaigns from Nike and Spotify.

Fake platform. Image provided by ESET.

Attackers regularly change platform names, domains, and website designs while keeping the core attack mechanism unchanged. Researchers have identified the use of domains such as joinmatchy[.]com, matchyjoin[.]com, and their subdomains. In other variations of the campaign, scammers operated under the name Scouty.

The fraudulent platforms share similar features, design elements, meta descriptions, and portions of their source code. This suggests that the attackers are using a common website template, changing the branding depending on the targeted victim.

According to ESET, personalized emails were sent to content creators in several countries, including Peru and Japan, as well as English-speaking YouTubers. The names and domains of the fraudulent websites changed repeatedly between June and August. Researchers believe the campaign could continue under new names.

One of the clearest warning signs is a website address that has no connection to the company supposedly offering the sponsorship deal. However, even a professional-looking website displaying accurate YouTube channel statistics does not guarantee that the service is legitimate.

How to Protect Your YouTube Channel From Fake Sponsorship Offers

ESET experts recommend that content creators verify all sponsorship offers through the brand’s official communication channels. It is safer to find the company’s contact details independently on its official website rather than relying solely on the email addresses and links provided in the message. Particular attention should be paid to the sender’s domain and the website address they want you to visit.

Before signing in through Google, Apple, Facebook, or another single sign-on service, users should make sure the login page belongs to the legitimate provider. For example, Google’s official sign-in page uses the accounts.google.com domain. It is also important to carefully review the permissions requested by third-party services. If a website claims it only needs to verify a channel, it should not require full access to manage videos and account settings.

If you suspect your Google account has already been compromised, ESET recommends immediately running a Google Security Checkup, reviewing recent security activity, connected devices, sign-in methods, recovery contacts, and third-party app access. Any unfamiliar devices or suspicious connections should be removed, followed by changing the password and enabling two-factor authentication if it is not already active.

If access to the account has already been lost, or scammers have changed the phone number, recovery email, or backup recovery codes, users should visit Google’s official account recovery page. Researchers also recommend using strong, unique passwords, multi-factor authentication, and passkeys. Users should never return to a suspicious website or enter their credentials there again.

For YouTube creators, the consequences of such an attack can be particularly serious. Cybercriminals gain access not only to videos and personal information but also to the creator’s reputation, which they can exploit to deceive subscribers. That is why even an attractive sponsorship offer from a well-known brand should be carefully verified, especially when signing a contract requires authentication through a third-party platform.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑