Skip to content
Residential technology help and small-business ITOwner-led. Clearly scoped. Salem County based. 609-202-2208
Cyber News

Fake YouTube sponsorship offers target creators’ Google accounts

A polished brand offer may lead YouTube creators to a fake collaboration site and a stolen Google account. Verify the company before signing in or granting access.

Published October 8, 2026 Updated October 8, 2026 6 min read
Fake YouTube sponsorship offers target creators’ Google accounts

A polished brand offer may lead YouTube creators to a fake collaboration site and a stolen Google account. Verify the company before signing in or granting access.

In 60 seconds

  • YouTube creators receiving sponsorship offers should check the sender, website, and requested account access.
  • Confirm the proposal through the brand’s official contact details, not through information in the message.
  • Do not enter your Google password or approve access on a site you cannot verify.
  • If you already signed in, use Google’s Security Checkup and review connected services.

Who should care and what to do today

This warning concerns YouTube creators who receive sponsorship offers or use Google accounts tied to their channels. The reported messages offered sponsorships, equipment, or payment and sometimes referred to the recipient’s actual videos.

Check the sender’s full email address and the website address before continuing. Then find the brand’s official contact details yourself and ask whether the offer is real. Do not use contact information supplied in the message.

Do not sign in or approve access while the offer is unconfirmed. Do not treat a familiar logo, polished design, or personalized message as proof that the offer is genuine.

How the reported scam works

ESET described a campaign that began with a personalized email claiming to come from a brand’s creator partnerships team. In one example, the supposed representative used the name Hollyland, a real maker of wireless transmission and audiovisual equipment. ESET also reported versions using the names Nike and Spotify.

The message directed the creator to a collaboration website. The site showed campaign figures, company logos, income estimates, and tools for contracts and payments. It first asked for the creator’s YouTube channel address, which ESET said could be used to display public information and make the site look personal.

The next step asked the creator to sign in with Google to prove ownership of the channel. “Single sign-on” means using an existing account, such as Google, to access another service. It can be legitimate, but a fake sign-in page can copy Google’s appearance and capture a password and one-time code.

Why the sign-in request matters

A real Google sign-in may share basic profile details, such as a name, email address, and profile picture. A separate request to manage a YouTube channel is more powerful. ESET said that permission could allow someone to upload or delete videos.

The reported damage depends on what the page is and what access the creator grants. An imitation login page can capture the password and one-time code, giving the attacker control of the Google account. That can include Gmail, Google Drive, recovery settings, and other connected services.

ESET described one creator whose phone number and recovery email were replaced and whose attackers added their own backup codes. The report also said a stolen account could be used to contact followers or collaborators and spread more scams or harmful links.

General guidance for checking an offer

The following is general guidance for checking an online sponsorship offer. Confirm the proposal through a brand’s official channel, using contact information found independently. Check the sender’s full address and the website address of every site you are asked to visit.

Before approving access, read the permissions list. A site that only needs to check public channel information should not need permission to manage the channel. Do not authorize an application or service you do not recognize.

ESET reported that the campaign changed names and website addresses several times between June and August. Checking only the brand name is not enough; review the exact sender and website address each time.

If you signed in or approved access

If you entered your password, approved access, or see account changes you did not make, open Google’s Security Checkup or the Security and sign-in area of your account. Review recent security events, signed-in devices, recovery information, sign-in methods, and connected services.

Remove devices or services you do not recognize, change your password, and turn on two-factor authentication. This adds a second proof of identity, such as a code or approval on another device. If you cannot log in, or find a new phone number, recovery email, or backup code, use Google’s official account recovery page.

Do not return to the suspicious website to enter more information or approve another request. After regaining access, review the account again and undo changes you did not make.

Does this affect me?

Who may be affected
The alert concerns YouTube creators who receive sponsorship offers or use Google accounts tied to their channels.
How to check
Review the sender’s full address, the website address, and requested permissions; confirm the offer through contact information found on the brand’s official website.
What to do
If you signed in or approved access, use Google’s Security Checkup to review account activity and connected services.
What to avoid
Do not trust familiar branding or personalized details as proof, and do not sign in again through the suspicious website.

Common questions

Does an offer become safe because it mentions my actual videos?

No. ESET said the reported campaign used personalized references to creators’ videos. Confirm the offer through the brand’s official contact channel before continuing.

What should a collaboration site need to verify a YouTube channel?

A site may use public channel information, but be cautious if it asks to manage the channel or grant wider access. Read the permission list and reject requests you do not understand.

What should I do if I entered my Google password on the site?

Use Google’s Security Checkup to review recent events, devices, recovery details, and connected services. Change your password and turn on two-factor authentication. If you are locked out, use Google’s official account recovery page.

Primary source

This article is based on ESET’s report, “Inside a brand deal scam targeting YouTube creators,” published October 7, 2026: https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/. The examples and campaign details below come from that report. Read the complete original source.

Concerned this may affect your computer or account?

Bring the exact alert, device, product, and timeline. Leon will help separate urgent action from noise.

Ask Leon

Article history: Published Oct 8, 2026 at 6:21 am EDT. Updates and corrections are noted here when material facts change.