Skip to content
YouTubers targeted with fake sponsorships and "channel verification" phishing

YouTubers targeted with fake sponsorships and "channel verification" phishing

Helpnetsecurity • October 8, 2026

Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners.

According to researchers at ESET, one recent campaign impersonates Hollyland, a legitimate manufacturer of wireless audio and video gear, while near-identical variants have used the names of Nike and Spotify to lure creators.

The trap behind the “verification” step

The fraudsters take the time to trick their targets into entering their Google account credentials: they first negotiate rates by email, then send the creator to a polished site complete with campaign metrics, big-brand logos, an earnings calculator, and supposed tools for handling contracts and payments.

The second email, pointing to the fake collaboration plaftorm (Source: ESET)

The site even pulls public data from the creator’s channel to make the experience feel tailored, and only then does it prompt a Google sign-in, framed as a step to verify channel ownership.

The “Sign in with Google” request (Source: ESET)

Unfortunately for the victims, entering their password and the one-time verification code means handing attackers the whole account, from Gmail and Drive to the YouTube channel itself.

One creator who fell victim said the intruders swapped in their own phone number and recovery email and generated new backup codes, all to make it harder for her to get back in.

The name, look and domains hosting the fake collaboration platform are changed regularly.

In the cases spotted by ESET, it’s called MATCHY (at joinmatchy[.]com or matchyjoin[.]com ) or SCOUTY (at joinscouty[.]com ). Other recent reported scam attempts point to TUBIVE (at mytubive[.]com ).

“This all points to a ‘modular’ scheme that retains certain components while altering the bogus identity used to reel in each creator. The sites have the same general functionality, as well as favicons, meta descriptions and portions of their source code,” ESET researchers explained.

The most obvious indicator that these emails haven’t been sent by Hollyland (or Nike, or Spotify, or Maono ) is that the originating email address has nothing to do with those companies.

But users who take the time to analyze the “collaboration platform” to which they were directed are sure to spot other red flags, as these pages are mainly focused on passing a cursory inspection, not a deeper one.

Here’s a similar example: AndaSeat, a brand that designs and manufactures gaming chairs and desks, recently warned sponsorship offers involving an agency called Creoventura (at creoventura[.]com ).

“Please note: Creoventura is NOT affiliated with AndaSeat in any way. We have no partnership with them,” the company said , expressly contradicting the “Brands we work with” list on the Creoventura agency’s website. (Coincidentally or not, Hollyland and Maono are also listed.)

At first glance, the agency’s website looks legitimate – it even provides a company registration number and an existing address – but there are things that point to it being something other than what it claims.

For example, the company name on the site, Creoventura, doesn’t quite match the one in the UK’s official register, which spells it Creoventure, and the business activities listed there are IT, management and engineering consultancy rather than influencer marketing.

The social media icons on the site lead only to the generic homepages of X, , Instagram and TikTok instead of actual company profiles

The client testimionals on the site are attributed to professionals that don’t have an online footprint ( account, social media, etc.)

The domain was registered in August 2026 through Namecheap for just one year and its ownership information is hidden, which is all typical of throwaway sites used in scam campaigns.

How creators can protect themselves

ESET’s advice to creators who receive a sponsorship offer is to verify it independently before going any further. Rather than replying to the email or clicking its links, they should look up the brand’s official details themselves and ask whether the offer and the person who sent it are genuine.

They should also scrutinize the sender’s email address and the domain of any platform they are pointed to, because a professional design and familiar logos don’t make a site legitimate (as the fake collaboration platforms show).

“Check before signing in with Google, Apple, or any other single sign-on (SSO) option, or before granting access. Make sure the sign-in page sits on the provider’s own domain (e.g., accounts.google.com ) – a bogus page can look identical to the real one,” ESET advised .

“Then inspect the permissions list – for example, a site that only needs to verify your channel has no reason to manage it. Don’t authorize applications or services you don’t recognize.”

Finally, they urge creators to protect their accounts with strong, unique passwords and two-factor authentication or passkeys.

Creators who suspect their account has already been compromised should act fast.

Running Google’s Security Checkup lets users review recent security events, signed-in devices, recovery information and third-party connections, and remove anything they don’t recognize. They should also change their password and turn on two-factor authentication if it isn’t already enabled.

For those who have been locked out of their accounts or have noticed changes they didn’t make, there’s Google’s official account recovery page .

Extracted Entities