For a YouTuber, the approach may look like routine business: a personalized sponsorship email from a global brand and a brief negotiation over rates, followed by an invitation to visit a slick collaboration platform. In some cases, however, the sequence can mask a scam that could part social media content creators from their Google accounts.

One such recent campaign impersonates Hollyland, a legitimate manufacturer of wireless transmission and audiovisual equipment. We’ve traced the scheme from the first contact and the negotiations of a supposed partnership through to the login request. We’ve also spotted several variants where fraudsters repackage the campaign using different brand identities and domains.

Here’s how the ploy works and what to watch for.

The emails

As is so often the case, the scheme begins with a personalized email containing an offer for collaboration. In one case, a journalist in Peru received a “Paid collaboration opportunity” from a sender who introduced herself simply as “Brandi” and claimed to work for Hollyland’s Creator Partnerships team.

The message was customized and contained specific references to videos from the target’s YouTube channel, offering the content creator a device and the prospect of a long-term collaboration.

fraude-youtubers-Hollyland-fake1.
Figure 1. Initial contact

There’s one clear warning sign already, however: the domain is unrelated to Hollyland. At any rate, once the journalist replied to the email with her rates, “Brandi” asked her to proceed to joinmatchy[.]com/hollyland, where the channel’s performance statistics, along with the agreement and payment, would supposedly be verified. All these details added to the legitimacy of the purported offer. 

fraude-youtubers-fake-Hollyland-2.
Figure 2. Second email from the scammer.

No match made in heaven

Unlike many other phishing attacks, this scheme doesn’t immediately ask the user for their password or other sensitive information. Instead, the prospective victim is first taken through a series of plausible-looking steps.

For example, the fraudulent website features campaign metrics, logos of major companies, and other hallmarks of an established platform. It also contains an income calculator to estimate how much a creator could make from the collab, as well as several features designed to automate contract negotiations, joint projects, and payments. The platform also asks for the creator’s YouTube channel URL, which it uses to retrieve public information and generate a seemingly personalized experience.

fraude-youtubers-fake-Hollyland-3.
Figure 3. A variant dubbed Scouty

The stakes go up

The next step takes the social media creator to a Google sign-in page, supposedly to verify their ownership of the YouTube channel. Of course, “Sign in with Google” is a legitimate authentication mechanism used by countless online platforms. That familiarity and the sense of legitimacy built thus far may cause the target to let their guard down and view the request as an identity check or another normal step in the process.

Importantly, the extent of the damage depends on what’s behind the page. By default, the genuine Google sign-in flow shares only a name, email address and profile picture with the site – unless you’re asked for more, such as the permission to manage the YouTube channel that would let attackers upload or delete videos, among other things. An imposter login page, meanwhile, goes further – it captures the password and one-time code, and with them the account itself, including personal information, account recovery methods, and access to services such as Gmail and Google Drive.

fig 4
Figure 4. A page on matchyjoin[.]com (sharing the same functionality as joinmatchy[.]com) retrieves public data from the channel and redirects the victim to a Google login page.

One content creator has described the plight she went through after falling for a version of this attack. Once inside her Google account, the attackers replaced her phone number and recovery email with their own details and added their own backup codes, all to hamper account recovery efforts.

fraude-youtubers-fake-Hollyland-5.
Figure 5. A victim warning about the attack.

A global, modular campaign

Attackers behind the campaign – which Hollyland itself has also warned about – also pose as various other brands, including Nike and Spotify. They also use several domains, including those containing “Scouty”, as seen in Figure 3. This all points to a “modular” scheme that retains certain components while altering the bogus identity used to reel in each creator. The sites have the same general functionality, as well as share favicons, meta descriptions and portions of their source code.

The emails are personalized and directed at specific creators in various parts of the world, including in Peru, Japan, and among English-speaking content creators. The domains and names changed repeatedly between June and August, and the same strategy may well come back under yet more fake identities.

fraude-youtubers-fake-Hollyland-6.
Figure 6. Examples of virtually identical variants, posing as Nike and Spotify.

How to stay safe

If you’re a social media influencer yourself, your Google account can be much more than “just” access to a YouTube channel. The attackers who hijack your account could use it to access other linked services or impersonate them to contact your followers or collaborators. The compromised account can also be misused to spread malicious links and peddle other scams.

Before considering a sponsorship offer, make sure to:

  • Confirm the offer through an official channel: If a brand contacts you to offer a sponsorship, find its official contact details independently and verify both the proposal and the person who sent it.
  • Check the domains: Look closely at the sender’s email address and the domain of any platform you may be directed to. Professional design and familiar branding don’t make a site legitimate.
  • Check before signing in with Google, Apple, Facebook or any other single sign-on (SSO) option, or before granting access. Make sure the sign-in page sits on the provider’s own domain (e.g., accounts.google.com) – a bogus page can look identical to the real one. Then inspect the permissions list – for example, a site that only needs to verify your channel has no reason to manage it. Don’t authorize applications or services you don’t recognize.
  • Use strong and unique passwords, along with two-factor authentication, on all your accounts, and consider using passkeys.

What to do if your account is compromised

It’s crucial to act quickly, because every second counts.

  • Run Google’s Security Checkup, or open Security & sign-in in your Google account, and review recent security events and signed-in devices. Look also at your sign-in methods, recovery information, and third-party connections. Remove devices, apps or access that you don’t recognize. Change your password and turn on two-factor (2FA) authentication if you haven’t already.
  • If you can no longer log in, or spot any other changes that you didn’t make (such as a new phone number, recovery email, or backup codes), use Google’s official account recovery page. Above all, don’t return to the suspicious site to enter your credentials or authorize further access. Once you’re back in, undo whatever the attackers changed in your account.

If you’re a YouTube creator yourself, you realize that your reputation ultimately defines your success. A Google account can then sit at the center of your business: email, files, contacts, and the YouTube channel itself. Once attackers gain control, they can lock you out or exploit the trust attached to the account to target your followers, family and other creators. That alone makes any sponsorship pitch itself worth scrutinizing carefully – from the sender’s domain to the permissions requested before any deal goes further.