YouTubers targeted: convincing sponsorship offers lead to hijacked accounts
The fake sponsorship platform appears like a real opportunity to estimate potential revenues.

Scammers targeting YouTubers. Image by Cybernews.
- Scammers impersonate real brands and send personalized sponsorship offers to YouTube creators.
- Fake campaign websites ask creators to sign in with Google and then steal login codes.
- Attackers can hijack accounts, change recovery details, and access connected services like Gmail or Drive.
- Creators should verify sponsorship offers through official contacts and check sign-in pages before entering credentials.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
YouTubers are falling victim to a highly convincing scam scenario: attackers impersonate known brands, prepare personalized sponsorship offers, then ask to prove account ownership before signing up – an action designed to steal credentials and hijack their accounts.
ESET warns of a brand-deal scam campaign targeting YouTube creators. Unlike other phishing tactics, where scammers directly try to steal sensitive information, the sponsorship scam puts a victim through a series of plausible-looking steps.
One of the creators warned about the scam in July.
“I received an email with an influencer sponsorship offer. I Googled the company, and they are legitimate (Hollyland),” a creator said in a post on Facebook.
The personalized offer led to a website that mimicked a platform for securing sponsorships – analyzing the channel and estimating potential revenue before signing up for the deal. The “Check channel” function prompts the user to authenticate with Google, and the victim reported the prompt appearing twice.
I immediately stopped and got into my Google account to check on things and change my password. By that time, they had already gotten into my account and removed my phone number, backup email address, and more, and replaced it with theirs.the content creator said.
ESET’s report mentions another victim – a journalist in Peru who received a “Paid collaboration opportunity” from a scammer who called themselves Brandi and claimed to work with Hollyland.
The personalized email referred to the creator’s content and offered a long-term partnership.
It again led to a fraudulent campaign website featuring fake campaign metrics, logos of major companies, an income calculator, and other hallmarks of an established platform. It even retrieves public data from the channel before redirecting the victim to a Google login page.
By default, the legitimate “Sign in with Google” authentication mechanism flow only shares a name, email address, and picture profile with third-party sites, unless users are asked for more, such as permission to manage the YouTube channel.
The researchers warn that impostor login pages capture passwords and a 1-time code, allowing attackers to hijack the account: access personal information, recovery methods, and other services such as Gmail or Google Drive.
For a YouTuber, personal sponsorship offers and collaboration platforms may look like a routine business, and attackers weaponize this sequence.
Hollyland, the company impersonated by scammers, warned creators about this fraud.
Attackers are constantly changing domains and names, targeting YouTubers across the globe, and repackaging the campaign under other brand identities, such as Nike and Spotify.
The clear warning sign is the domain of the platform, unrelated to the companies. Attackers used joinmatchy[.]com, matchyjoin[.]com, and their subdomains so far.
How to protect yourself?
If you suspect that your Google account got compromised, run Google Security Checkup, review recent security events and signed-in devices, look at sign-in methods, recovery information, or suspicious third-party connections – remove any devices, apps, or access that you don’t recognize.
“Change your password and turn on 2-factor (2FA) authentication if you haven’t already,” ESET said.
“If you can no longer log in, or spot any other changes that you didn’t make (such as a new phone number, recovery email, or backup codes), use Google’s official account recovery page.”
The researchers recommend that YouTubers confirm any sponsorship offers through an official channel – find contact details independently. Scrutinize the email: look closely at the domains involved, the sender's email addresses, and any platforms they might be redirected to.
Before signing in with Google, Apple, Facebook, or any other single sign-on (SSO) platform, make sure that the sign-in page matches the provider's domain, such as accounts.google.com. Bogus pages can be indistinguishable from the real ones.
ESET also repeats the cybersecurity hygiene mantras: use strong, unique passwords with multi-factor authentication on all accounts, consider using passkeys, and never authorize any suspicious applications or services to access your accounts.