Phishing campaigns impersonate brands to hijack YouTube creators' Google accounts

Attackers are sending personalized sponsorship emails to YouTube creators and directing them to fake collaboration portals. The sites mimic real brands such as Hollyland, Nike, and Spotify, then ask creators to sign in with Google under the guise of verifying channel ownership. ESET says stolen credentials can give intruders access to Gmail, Drive, and the YouTube channel itself.
ESET traced a recent wave in which creators receive tailored sponsorship pitches that cite their own videos. After rate talks, victims are sent to polished portals with campaign stats, brand logos, payment tools, and an earnings calculator. The sites pull public channel data, then request Google login as channel-ownership verification. Variants have used Hollyland, Nike, Spotify, and Maono; portal names include MATCHY, SCOUTY, and TUBIVE. Researchers describe a modular operation reusing code, favicons, and metadata while swapping identities.
AndaSeat separately warned that Creoventura, an agency claiming brand partnerships, is unaffiliated with it. Creoventura’s site lists Hollyland and Maono, but its registered name and business categories differ from its claims, and its social links point to generic platform homepages.
YouTube creators and their teams could lose income, private messages, files, and control of channels if Google accounts are compromised. Audiences may be exposed to fraudulent posts or scams from hijacked channels, while brands named in the campaigns may face reputational confusion. Because sponsorship outreach is common, creators may become more cautious about collaboration emails, potentially slowing legitimate deals. Platforms and advertisers may need stronger verification and account-recovery safeguards, though the immediate harm falls mainly on individual creators and their dependent communities.