A plausible-sounding sponsorship supply may masks an try to compromise your Google account
07 Oct 2026
•
,
6 min. learn

For a YouTuber, the strategy could appear like routine enterprise: a personalised sponsorship electronic mail from a world model and a short negotiation over charges, adopted by an invite to go to a slick collaboration platform. In some instances, nevertheless, the sequence can masks a rip-off that might half social media content material creators from their Google accounts.
One such current marketing campaign impersonates Hollyland, a reputable producer of wi-fi transmission and audiovisual gear. We’ve traced the scheme from the primary contact and the negotiations of a supposed partnership by means of to the login request. We’ve additionally noticed a number of variants the place fraudsters repackage the marketing campaign utilizing totally different model identities and domains.
Right here’s how the ploy works and what to look at for.
The emails
As is so typically the case, the scheme begins with a personalised electronic mail containing a suggestion for collaboration. In a single case, a journalist in Peru acquired a “Paid collaboration alternative” from a sender who launched herself merely as “Brandi” and claimed to work for Hollyland’s Creator Partnerships group.
The message was personalized and contained particular references to movies from the goal’s YouTube channel, providing the content material creator a tool and the prospect of a long-term collaboration.

There’s one clear warning signal already, nevertheless: the area is unrelated to Hollyland. At any charge, as soon as the journalist replied to the e-mail together with her charges, “Brandi” requested her to proceed to joinmatchy[.]com/hollyland, the place the channel’s efficiency statistics, together with the settlement and cost, would supposedly be verified. All these particulars added to the legitimacy of the purported supply.

No match made in heaven
Not like many different phishing assaults, this scheme doesn’t instantly ask the consumer for his or her password or different delicate info. As a substitute, the possible sufferer is first taken by means of a sequence of plausible-looking steps.
For instance, the fraudulent web site options marketing campaign metrics, logos of main corporations, and different hallmarks of a longtime platform. It additionally incorporates an revenue calculator to estimate how a lot a creator may make from the collab, in addition to a number of options designed to automate contract negotiations, joint tasks, and funds. The platform additionally asks for the creator’s YouTube channel URL, which it makes use of to retrieve public info and generate a seemingly personalised expertise.

The stakes go up
The following step takes the social media creator to a Google sign-in web page, supposedly to confirm their possession of the YouTube channel. After all, “Register with Google” is a reputable authentication mechanism utilized by numerous on-line platforms. That familiarity and the sense of legitimacy constructed up to now could trigger the goal to let their guard down and consider the request as an identification verify or one other regular step within the course of.
Importantly, the extent of the harm will depend on what’s behind the web page. By default, the real Google sign-in stream shares solely a reputation, electronic mail deal with and profile image with the location – except you’re requested for extra, such because the permission to handle the YouTube channel that might let attackers add or delete movies, amongst different issues. An imposter login web page, in the meantime, goes additional – it captures the password and one-time code, and with them the account itself, together with private info, account restoration strategies, and entry to providers corresponding to Gmail and Google Drive.
![Figure 4. A page on matchyjoin[.]com (sharing the same functionality as joinmatchy[.]com) retrieves public data from the channel and redirects the victim to a Google login page. fig 4](https://web-assets.esetstatic.com/wls/2026/09-26/fig-4.jpg)
One content material creator has described the plight she went by means of after falling for a model of this assault. As soon as inside her Google account, the attackers changed her cellphone quantity and restoration electronic mail with their very own particulars and added their very own backup codes, all to hamper account restoration efforts.

A worldwide, modular marketing campaign
Attackers behind the marketing campaign – which Hollyland itself has additionally warned about – additionally pose as numerous different manufacturers, together with Nike and Spotify. Additionally they use a number of domains, together with these containing “Scouty”, as seen in Determine 3. This all factors to a “modular” scheme that retains sure parts whereas altering the bogus identification used to reel in every creator. The websites have the identical common performance, in addition to share favicons, meta descriptions and parts of their supply code.
The emails are personalised and directed at particular creators in numerous elements of the world, together with in Peru, Japan, and amongst English-speaking content material creators. The domains and names modified repeatedly between June and August, and the identical technique could effectively come again underneath but extra pretend identities.

How one can keep secure
In case you’re a social media influencer your self, your Google account might be rather more than “simply” entry to a YouTube channel. The attackers who hijack your account may use it to entry different linked providers or impersonate them to contact your followers or collaborators. The compromised account can be misused to unfold malicious hyperlinks and peddle different scams.
Earlier than contemplating a sponsorship supply, be sure to:
- Verify the supply by means of an official channel: If a model contacts you to supply a sponsorship, discover its official contact particulars independently and confirm each the proposal and the one who despatched it.
- Verify the domains: Look intently on the sender’s electronic mail deal with and the area of any platform it’s possible you’ll be directed to. Skilled design and acquainted branding don’t make a web site reputable.
- Verify earlier than signing in with Google, Apple, Fb or another single sign-on (SSO) choice, or earlier than granting entry. Make sure that the sign-in web page sits on the supplier’s personal area (e.g., accounts.google.com) – a bogus web page can look similar to the actual one. Then examine the permissions checklist – for instance, a web site that solely must confirm your channel has no cause to handle it. Don’t authorize purposes or providers you don’t acknowledge.
- Use sturdy and distinctive passwords, together with two-factor authentication, on all of your accounts, and think about utilizing passkeys.
What to do in case your account is compromised
It’s essential to behave shortly, as a result of each second counts.
- Run Google’s Safety Checkup, or open Safety & sign-in in your Google account, and evaluation current safety occasions and signed-in units. Look additionally at your sign-in strategies, restoration info, and third-party connections. Take away units, apps or entry that you just don’t acknowledge. Change your password and activate two-factor (2FA) authentication in case you haven’t already.
- In case you can now not log in, or spot another modifications that you just didn’t make (corresponding to a brand new cellphone quantity, restoration electronic mail, or backup codes), use Google’s official account restoration web page. Above all, don’t return to the suspicious web site to enter your credentials or authorize additional entry. When you’re again in, undo regardless of the attackers modified in your account.
In case you’re a YouTube creator your self, you understand that your repute in the end defines your success. A Google account can then sit on the heart of your enterprise: electronic mail, recordsdata, contacts, and the YouTube channel itself. As soon as attackers achieve management, they’ll lock you out or exploit the belief hooked up to the account to focus on your followers, household and different creators. That alone makes any sponsorship pitch itself price scrutinizing rigorously – from the sender’s area to the permissions requested earlier than any deal goes additional.









