VYPR
researchPublished Oct 7, 2026· Updated Oct 8, 2026· 1 source

YouTube Creators Targeted by Fake Brand Deal Scams Aiming for Google Account Credentials

A sophisticated phishing campaign impersonates legitimate brands to lure YouTube creators into fake collaboration platforms, ultimately stealing their Google account credentials.

Cybercriminals are employing a deceptive social engineering tactic to target YouTube creators, masquerading as legitimate brands to trick them into compromising their Google accounts. This scam, recently observed impersonating the audiovisual equipment manufacturer Hollyland, begins with seemingly personalized sponsorship offers sent via email.

The attackers craft emails that reference specific content from the target creator's YouTube channel, offering a product and the prospect of a long-term collaboration. While the initial contact might appear professional, a critical red flag is the sender's email domain, which is typically unrelated to the purported brand. Once the creator expresses interest and shares their rates, the scammer directs them to a fraudulent collaboration platform, such as joinmatchy[.]com or its variants.

These fake platforms are designed to mimic legitimate services, featuring campaign metrics, corporate logos, and even income calculators to build trust. They request the creator's YouTube channel URL to retrieve public data, further enhancing the illusion of a genuine partnership. This elaborate setup aims to lower the victim's guard before the crucial credential harvesting step.

The scam's climax involves directing the creator to a fake Google sign-in page, ostensibly to verify channel ownership. The familiar "Sign in with Google" button, combined with the preceding elaborate setup, can lead unsuspecting creators to enter their credentials, including any two-factor authentication codes. This allows attackers to gain full control over the creator's Google account.

Once access is secured, attackers can change recovery information, add backup codes, and lock the legitimate owner out. The compromised account can then be used to access other linked services, impersonate the creator to their followers, or spread further malicious links and scams. One victim reported that attackers had replaced their phone number and recovery email, significantly hindering their ability to regain control.

This campaign is described as "modular," with attackers frequently changing the impersonated brands and domains to evade detection. Past impersonations have included major companies like Nike and Spotify, indicating a flexible and persistent threat. The attackers target creators globally, adapting their approach to different regions and languages.

To protect themselves, YouTube creators should exercise extreme caution with unsolicited sponsorship offers. It is crucial to independently verify the legitimacy of the offer and the sender through official channels, scrutinize email domains for any discrepancies, and be wary of requests to log in via unfamiliar platforms. Multi-factor authentication and strong, unique passwords for all accounts remain essential defenses against such credential harvesting attacks.

Synthesized by Vypr AI