Fake brand deals are stealing YouTube creators' Google accounts
ESET traced fake Hollyland, Nike and Spotify sponsorships that end in a Google sign-in trap. How the scam runs, and the account checks to do now.
By Yaali. October 11, 2026, 6 min read, Phishing, Identity.
ESET has documented a phishing campaign that sends YouTube creators convincing sponsorship offers from brands that never made them. The main lure impersonates Hollyland, a maker of wireless audio and video gear, and ESET found near-identical variants using Nike and Spotify. After a polite rate negotiation by email, the creator is sent to a polished "collaboration platform" that asks them to sign in with Google to verify channel ownership. The password and one-time code they enter go to the attacker, who then holds the whole Google account: Gmail, Drive and the channel.
This matters beyond individual YouTubers. Brand channels, agency inboxes and company social accounts run on the same Google accounts, and the people who answer partnership emails are often marketers rather than IT staff. ESET published its analysis on October 7, 2026, with victims in Peru, Japan and English-speaking creator communities, and saw the operators rotate domains and brand names between June and August.

How it works
The first email is personalised. In the case ESET walks through, a journalist in Peru heard from "Brandi" on Hollyland's "Creator Partnerships" team, who referred to her videos and offered a device plus a longer collaboration. The sending domain had nothing to do with Hollyland. When she replied with her rates, the scammer moved her to joinmatchy[.]com/hollyland, where her channel statistics, the agreement and payment would supposedly be verified.
The platform is the part that wins trust. ESET describes campaign metrics, brand logos, an income calculator, and tools that claim to automate negotiation, contracts and payment. It asks for the creator's channel URL and pulls public data from the channel, so the page shows the creator their own numbers. Only after several reasonable steps does it ask for a Google sign-in "to verify channel ownership."
That sign-in is where the account goes. On the imposter pages, the creator types their password and then the one-time code from their phone or authenticator app. A one-time code proves you are present at the moment you type it, not which website you typed it into, so a phishing page that collects both can replay them to Google straight away and get a live session. ESET adds that a genuine Google sign-in can also be abused: the app behind it can request permission to manage the YouTube channel, which is why it advises reading the permissions list before approving anything.
ESET found the fake platforms (Matchy at joinmatchy[.]com and matchyjoin[.]com, plus variants branded Scouty) shared website code, favicons and functionality as the names and domains changed. It reads this as one modular operation that can come back under a new name.
What attackers are doing
Once in, the attackers work to keep the account. One creator who signed in on the Matchy site told ESET she lost control of her Google account: the attackers removed her phone number and recovery email, added their own, and generated new backup codes. ESET points out that these are the details Google relies on to recover an account, so replacing them shuts the real owner out of the normal recovery flow.
Hollyland has publicly warned about the campaign, and in a related case the gaming furniture brand AndaSeat said it has no link to an "agency" called Creoventura that listed it as a partner.
ESET does not say how many accounts were taken or what each hijacked channel was used for. For background, Google's Threat Analysis Group described a different method against creators in October 2021: fake sponsorship emails that delivered cookie-stealing malware, so attackers could reuse a browser's signed-in session without a password at all. That was an earlier campaign, but it shows why a "brief" or "contract" file from an unverified sponsor deserves the same suspicion as a sign-in link.
What to do

Before you answer an offer
Find the brand's partnership or press contact yourself, from its official website or verified social accounts, and ask whether the offer is real. Compare the sender's domain and the platform domain with the brand's real one; in ESET's samples, neither matched. Accurate channel statistics and a professional site prove nothing, because the data is public.
Before any "Sign in with Google"
Check the address bar. A real Google sign-in is on accounts.google.com, and a page that looks like Google on any other domain is a phishing page. If a real Google consent screen appears, read what the app is asking for. A sponsor has no reason to ask for permission to manage your channel; cancel if you see that request.
Move the accounts that own channels to passkeys or hardware security keys. Both are tied to the real Google domain, so a lookalike page cannot collect and replay them the way it can a password and SMS or app code. Keep printed backup codes offline.
If someone already signed in on one of these sites
Act from a clean device and go straight to myaccount.google.com, not through any link in the scam emails:
- Open Security & sign-in and review recent security activity. Look for new sign-ins, password changes, and changes to the recovery phone, recovery email or backup codes that you did not make.
- Under Your devices, choose Manage all devices and sign out of every session you do not recognise. This revokes the attacker's live session.
- Change the password, then check that the recovery phone and email are yours and generate new backup codes, which invalidates the old ones.
- Under third-party connections, remove any app you did not knowingly approve, especially one with YouTube access.
- If you are already locked out, use Google's recovery page at accounts.google.com/signin/recovery. Do not go back to the scam site or approve anything else it asks for.
For brand channels and company accounts
Put company channels on a Brand Account, which lets several Google accounts manage one channel without sharing a password. In your Google Account, open the Brand Accounts list, select the account and choose Manage permissions to see every owner and manager. Remove anyone who no longer needs access, keep owners to a small number of named staff on phishing-resistant sign-in, and give agencies and freelancers manager rather than owner roles. Check the list on a schedule, so a new owner nobody added stands out.
Tell the people who answer partnership mail what this scam looks like. They are the ones being targeted, and they are often outside the security team's training lists.
The wider lesson
The weak point here is a business process: a sponsorship deal that ends in a sign-in request. Any workflow where an outside party asks someone to log in to "verify" an account should be treated as a red flag in itself, and the accounts that matter most to the brand should be the first ones moved to passkeys.
Our brand management work covers who holds which company social accounts and how they sign in, and personal account management does the same for creators and executives whose personal accounts carry the brand. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: ESET WeLiveSecurity, Help Net Security, Cybernews, ebizLatam (ESET Latinoamérica), Mallory, Google Threat Analysis Group (2021), Google Account Help: devices, Google Account Help: Brand Accounts, YouTube Help: channel owners and managers.
Read next
- CaptiveCrunch is back: hotel Wi-Fi attacks on travellers resume
- 16 fake Rabby and OKX add-ons stole Firefox seed phrases
- Fake AI ad portals steal ad logins and MFA codes live
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.