YouTube creators targeted by fake sponsorship phishing

YouTube creators targeted by fake sponsorship phishing

Fraudsters are targeting YouTube creators with fake brand sponsorship deals designed to steal their Google accounts, according to ESET.

The scheme starts with a personalized email that mentions the creator's own videos. It then leads them to a polished but fake collaboration platform. Everything looks like an ordinary brand partnership until the creator is asked to sign in with Google.

ESET researchers said one recent campaign impersonates Hollyland, a legitimate maker of wireless audio and video equipment. Almost identical versions have used the Nike and Spotify names to attract creators.

A slow build-up to the login prompt

The attackers do not rush. They first negotiate rates with the creator over email. A second message then points the target to a website that shows campaign metrics, logos of well-known brands, an earnings calculator, and what appear to be tools for managing contracts and payments.

The site also pulls public information from the creator's channel, so the experience feels tailored to them. Only after that does it ask the creator to sign in with Google, presented as a way to confirm they own the channel.

Creators who enter their password and one-time verification code give the attackers the entire account. That includes Gmail, Drive and the YouTube channel.

One victim said the intruders replaced her phone number and recovery email with their own and created new backup codes. These changes made it harder for her to regain access.

Rotating names, shared code

The fake platform changes its name, design and domains regularly. In the cases ESET observed, it appeared as MATCHY (joinmatchy[.]com or matchyjoin[.]com) and SCOUTY (joinscouty[.]com). Other recent reports mention TUBIVE (mytubive[.]com).

"This all points to a 'modular' scheme that retains certain components while altering the bogus identity used to reel in each creator. The sites have the same general functionality, as well as share favicons, meta descriptions and portions of their source code," ESET researchers explained.

The clearest warning sign is the sender's address. The emails claim to come from Hollyland, Nike, Spotify or Maono, but they are sent from addresses with no connection to those companies. The fake platforms are also built to survive a quick look, not a close one. A careful creator will usually find more red flags.

A related case involves AndaSeat, a maker of gaming chairs and desks. The company recently warned about sponsorship offers from an agency called Creoventura (creoventura[.]com).

"Please note: Creoventura is NOT affiliated with AndaSeat in any way. We have no partnership with them," the company said. Creoventura's website lists AndaSeat among the "Brands we work with." Hollyland and Maono appear on that list too, though it is unclear whether this is a coincidence.

The agency's site looks credible at first. It shows a company registration number and a real address. A closer look reveals several problems:

  • The name on the site, Creoventura, does not match the UK's official company register, which lists it as Creoventure.
  • The registered business activities are IT, management and engineering consultancy, not influencer marketing.
  • The social media icons link only to the general homepages of X, LinkedIn, Instagram and TikTok, not to actual company profiles.
  • The client testimonials are credited to people with no visible online presence.
  • The domain was registered through Namecheap in August 2026, for one year only, with hidden ownership details. This pattern is typical of disposable scam sites.

Advice for creators

ESET recommends that creators verify any sponsorship offer on their own before going further. They should not reply to the email or click its links. Instead, they should find the brand's official contact details themselves and ask whether the offer and the sender are real.

Creators should also check the sender's address and the domain of any platform they are sent to. A professional design and familiar logos do not prove a site is genuine.

"Check before signing in with Google, Apple, Facebook or any other single sign-on (SSO) option, or before granting access. Make sure the sign-in page sits on the provider's own domain (e.g., accounts.google.com) - a bogus page can look identical to the real one," ESET advised.

"Then inspect the permissions list - for example, a site that only needs to verify your channel has no reason to manage it. Don't authorize applications or services you don't recognize."

The researchers also recommend strong, unique passwords combined with two-factor authentication or passkeys.

Anyone who suspects a compromise should act quickly. Google's Security Checkup shows recent security events, signed-in devices, recovery details and third-party connections, and lets users remove anything unfamiliar. Victims should change their password and turn on two-factor authentication if it is not already active. Those who are locked out, or who see changes they did not make, can use Google's official account recovery page.

Our Take

This campaign shows how far social engineering aimed at creators has developed. The attackers do not rely on one crude phishing email. They negotiate rates, personalize their pitch and build a site that looks like a real workflow. The login request arrives only after the target has started to trust the process.

Two-factor codes did not stop the attack, because victims typed them directly into the fake page. This is a familiar weakness, also seen when fake ChatGPT and Gemini sites harvested MFA codes from advertisers. Phishing-resistant options such as passkeys could help here, although passkey adoption still lags even among security professionals.

The modular design suggests the operators can swap brands and domains quickly. Blocking individual sites is therefore likely to have limited effect. It is worth watching whether more brands follow AndaSeat and publicly reject agencies that claim them as partners. Free tools such as link-checking services can help with screening. The most reliable defense remains independent verification of any offer before signing in.