www.welivesecurity.com YouTube Creators Targeted by Phishing Scams Posing as Sponsorship Offers
Article Content
- •Scammers impersonate brands to lure YouTube creators into phishing traps.
- •Victims unknowingly provide Google account credentials on fake platforms.
- •The phishing sites are designed to appear legitimate with tailored content.
Scammers are targeting YouTube creators with phishing campaigns that impersonate legitimate brands like Hollyland, Nike, and Spotify. The attackers send personalized emails offering sponsorship opportunities, leading creators to fake collaboration platforms designed to steal their Google account credentials. Victims are tricked into entering their login information on these sites, which appear legitimate due to tailored content and brand logos. Once compromised, attackers can access the creator's entire Google account, including Gmail and YouTube. The schemes have been reported under various names, including MATCHY and SCOUTY, with the domains frequently changing to evade detection. ESET researchers have identified this as a modular scheme, where components remain consistent while the brand identity varies. Creators are advised to be cautious of unsolicited sponsorship offers and verify the legitimacy of any collaboration requests.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Hollyland in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How can YouTube creators protect themselves?
What should I do if I fall victim to this scam?
Are there specific brands being impersonated?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…