The Sponsorship Offer Looked Real. It Came From a Known Brand. It Asked for One Thing: Sign In With Google.

YouTube sponsorship scam infographic by Adv Shoeb Hakim showing the fake platform, Google login trap, and account hijack

Key Facts

  • Campaign: A brand-deal scam targeting YouTube creators, identified by ESET
  • Tactic: Attackers impersonate real brands such as Hollyland, Nike, and Spotify and send personalized sponsorship offers
  • The Trap: Fake campaign websites mimic legitimate sponsorship platforms and ask creators to sign in with Google to “check channel” metrics
  • What Is Stolen: Google login credentials and one-time codes, allowing attackers to hijack accounts
  • Consequences: Hijacked accounts lose recovery details; attackers change phone numbers and backup emails; connected services like Gmail and Drive are exposed
  • Domains Used: joinmatchy[.]com, matchyjoin[.]com, and subdomains
  • Brand Warning: Hollyland, the impersonated company, has warned creators about the fraud
  • Protection: Verify sponsorship offers through official channels; check that sign-in pages use the provider’s domain (e.g., accounts.google.com); enable 2FA and passkeys

Direct Answer

YouTube creators are being targeted by a sophisticated phishing campaign that uses fake sponsorship offers to hijack their Google accounts. The attackers impersonate real brands, send personalized emails that reference the creator’s content, and direct them to a fake campaign website that mimics a legitimate sponsorship platform.

The website includes fake campaign metrics, an income calculator, and logos of major companies. It retrieves public data from the creator’s channel and then prompts them to sign in with Google to “check channel” performance. The sign-in page is a phishing page that captures the password and one-time code. Once the attackers have access, they change the account’s recovery details—removing the creator’s phone number and backup email—and replace them with their own.

This locks the creator out and gives the attackers access to connected services like Gmail and Google Drive. The campaign has targeted creators globally, using domains like joinmatchy[.]com and matchyjoin[.]com.

The legitimate “Sign in with Google” flow only shares name, email, and profile picture, but the fake page asks for more. Creators must verify offers through official channels and check the domain of any sign-in page before entering credentials.


In this article:

  • How the Sponsorship Scam Works
  • The Fake Campaign Platform
  • The Google Login Trap
  • The Hijack: What Happens After Credentials Are Stolen
  • Who Is Being Targeted
  • The Legal Framework: IT Act, DPDP Act, and CERT-In
  • What Creators Must Do to Protect Themselves
  • Frequently Asked Questions (FAQ)

By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police forces since 1996.


How the Sponsorship Scam Works

The scam follows a carefully constructed sequence designed to appear legitimate at every step.

Step 1: The personalized email

The attacker sends an email offering a sponsorship deal. The email references the creator’s content and offers a long-term partnership. It appears to come from a known brand, such as Hollyland, Nike, or Spotify.

Step 2: The fake campaign website

The email links to a website that mimics a legitimate sponsorship platform. The site includes fake campaign metrics, logos of major companies, an income calculator, and other features designed to look like an established business.

Step 3: The “check channel” prompt

The website asks the creator to sign in with Google to “check channel” performance and estimate potential revenue. This is the trap.

Step 4: The Google login page

The sign-in page appears to be Google’s login page, but it is a phishing page. It captures the password and the one-time code. In at least one case, the prompt appeared twice.

Step 5: The hijack

Once the attackers have the credentials and the one-time code, they access the Google account. They remove the creator’s phone number and backup email address and replace them with their own. They change the password. The creator is locked out.


The Fake Campaign Platform

The fake platform is designed to look like a real business.

Features observed by ESET:

  • Fake campaign metrics
  • Logos of major companies
  • Income calculator
  • Professional design and branding
  • Public data retrieved from the creator’s channel

The platform appears to be a legitimate sponsorship marketplace. It asks the creator to authenticate to “verify” their channel and estimate earnings. The authentication step is the point of attack.

The domains:

Attackers used joinmatchy[.]com, matchyjoin[.]com, and their subdomains. These domains are not associated with the brands being impersonated. That is the warning sign—if the domain does not match the brand, the offer is not legitimate.


The Google Login Trap

The fake sign-in page mimics Google’s authentication flow.

How it works:

The legitimate “Sign in with Google” flow shares only name, email address, and profile picture with third-party sites, unless the user is asked for more permissions, such as the ability to manage a YouTube channel. Attackers exploit this by creating a fake page that appears to be Google’s login page but is designed to capture the password and one-time code.

The two-step prompt:

In at least one reported case, the prompt appeared twice. The first prompt may have been a legitimate Google sign-in; the second was the phishing page. The victim reported: “I immediately stopped and got into my Google account to check on things and change my password. By that time, they had already gotten into my account and removed my phone number, backup email address, and more, and replaced it with theirs.”

The warning sign:

Before signing in with Google, Apple, Facebook, or any single sign-on provider, check that the sign-in page matches the provider’s domain—for example, accounts.google.com. If the domain is different, it is a phishing page.


The Hijack: What Happens After Credentials Are Stolen

Once the attackers have access, the consequences escalate quickly.

Immediate actions by the attacker:

  • Change the account password
  • Remove the creator’s phone number from recovery options
  • Remove the creator’s backup email address
  • Add the attacker’s own phone number and backup email
  • Change recovery codes
  • Access connected services including Gmail, Google Drive, and YouTube

The impact on the creator:

  • Locked out of their own account
  • Unable to reset password through normal recovery channels
  • Loss of access to emails, documents, and YouTube channel
  • Risk of the channel being used for further scams or monetization by the attacker

For a YouTuber:

Personal sponsorship offers and collaboration platforms are a routine part of business. Attackers weaponize this routine. The scam looks like a normal business opportunity until the account is gone.


Who Is Being Targeted

The campaign targets YouTube creators globally.

Known targets:

  • A creator who received a fake offer from “Hollyland”
  • A journalist in Peru who received a “Paid collaboration opportunity” from a scammer calling themselves Brandi

Brands impersonated:

  • Hollyland
  • Nike
  • Spotify

The targeting pattern:

Attackers are constantly changing domains and names, repackaging the campaign under different brand identities. They target creators across the globe. The common thread is a personalized offer that references the creator’s content and directs them to a fake platform.


The Legal Framework: IT Act, DPDP Act, and CERT-In

The scam engages several provisions of Indian law.

Information Technology Act, 2000

  • Section 66C: Identity theft—fraudulently or dishonestly making use of another person’s electronic signature, password, or unique identification feature. Punishable with imprisonment up to three years and fine up to ₹1 lakh.
  • Section 66D: Cheating by personation using a computer resource or communication device. Punishable with imprisonment up to three years and fine up to ₹1 lakh.

Digital Personal Data Protection Act, 2023

If the hijacked account contains personal data of the creator or third parties, the breach may trigger obligations under the DPDP Act. The creator, as a Data Fiduciary for their own data and possibly that of others, must implement reasonable security safeguards and report breaches.

CERT-In Directions

Specified cyber incidents must be reported to CERT-In within six hours of noticing the incident or being informed about it. Account hijacking may qualify as a reportable incident.

The practical reality:

The attackers are often outside Indian jurisdiction. Recovery depends on the platform—Google’s account recovery process—and on the speed of reporting.


What Creators Must Do to Protect Themselves

1. Verify sponsorship offers through official channels

Find the brand’s contact details independently. Do not use the contact information in the email. Contact the brand directly through its official website or social media.

2. Check the domain of the sign-in page

Before entering credentials, check that the sign-in page matches the provider’s domain. For Google, it should be accounts.google.com. For Apple, it should be appleid.apple.com.

3. Never sign in with Google to “check channel” metrics

Legitimate platforms do not require you to sign in with Google to check your own channel. If a website asks you to do this, it is a red flag.

4. Enable two-factor authentication (2FA) or passkeys

Even if the password is stolen, 2FA can prevent access. Passkeys are even stronger. Enable them on all accounts.

5. Use strong, unique passwords

Do not reuse passwords across services. Use a password manager.

6. Review Google Security Checkup

If you suspect your account was compromised, run Google Security Checkup. Review recent security events, signed-in devices, sign-in methods, recovery information, and third-party connections. Remove any devices, apps, or access you do not recognize.

7. Change your password immediately

If you suspect compromise, change your password. If you can no longer log in, use Google’s official account recovery page.

8. Report the incident

Report the phishing email to the brand being impersonated and to Google. If you are in India, report to CERT-In and the National Cyber Crime Reporting Portal.


Frequently Asked Questions (FAQ)

What is the YouTube sponsorship scam?

A phishing campaign where attackers impersonate real brands, send personalized sponsorship offers, and direct creators to fake campaign websites that steal Google login credentials.

How do the attackers steal credentials?

The fake website prompts the creator to sign in with Google to “check channel” metrics. The sign-in page is a phishing page that captures the password and one-time code.

What happens after the credentials are stolen?

The attackers change the account password, remove the creator’s recovery phone number and backup email, and replace them with their own. The creator is locked out.

What brands are being impersonated?

Hollyland, Nike, and Spotify have been identified. Attackers constantly change brands and domains.

What are the warning signs?

The domain of the platform does not match the brand. The sign-in page may not be on the provider’s official domain. The offer asks you to sign in with Google to check your own channel metrics.

What should creators do if they suspect compromise?

Run Google Security Checkup. Review recent security events and signed-in devices. Change your password. If locked out, use Google’s official account recovery page.

What legal provisions apply in India?

Section 66C (identity theft) and Section 66D (cheating by personation) of the IT Act, 2000. The DPDP Act may apply if personal data is breached. CERT-In reporting may be required.

How can creators verify a sponsorship offer?

Find the brand’s contact details independently. Do not use the contact information in the email. Contact the brand through its official website or social media.

What is the safest way to sign in with Google?

Check that the sign-in page uses accounts.google.com. If the domain is different, do not enter credentials.

What security measures should creators enable?

Two-factor authentication, passkeys, strong unique passwords, and regular security checkups.


Explore More:

Read my blog

Book Now

Contact

Careers


Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.

#AdvShoebHakim #YouTubeScam #Phishing #AccountHijacking #ESET #CyberSecurity #DigitalForensics #LegalDefense #Compliance #ITAct

Additional Page Metadata

Author:
Adv. Shoeb Hakim

Author Bio:
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police forces since 1996. Provides expert commentary on cybercrime, phishing, and digital fraud.

Article Publisher:
Adv. Shoeb Hakim

Article Section:
Cybercrime | Phishing | Digital Fraud | Data Protection

Article Tags:
YouTube sponsorship scam, phishing, Google account hijack, ESET, Hollyland, Nike, Spotify, joinmatchy, IT Act Section 66C, DPDP Act, CERT-In, Adv Shoeb Hakim

Leave a Reply

Your email address will not be published. Required fields are marked *

Find