A Peruvian journalist who publishes on YouTube gets an email from "Brandi," on the Creator Partnerships team at Hollyland, a maker of wireless transmission and audiovisual equipment. The message mentions specific videos from her channel, offers a free device and floats a possible long-term collaboration. She replies with her rates and receives an invitation to a platform where, she is told, she can verify the stats, the agreement and the payment. The platform exists. The collaboration doesn't. It is the scheme ESET WeLiveSecurity described on October 7, 2026, and its only purpose is to take over the creator's Google account.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

The email: personalized, from a sender that isn't the brand

The hook is a "paid collaboration opportunity" that looks like part of the routine of any channel with a decent audience. What holds the deception together is the personalization: the message mentions real videos from the channel, something anyone can do with public YouTube information. The red flag, according to ESET, was that the sender's domain had nothing to do with Hollyland. The documented example is that journalist's, but ESET found variants using other brands and other domains.

The fake platform: metrics, logos and an income calculator

The link the victim receives points to joinmatchy[.]com/hollyland, a site built to look like an established collaboration platform: campaign metrics, logos of major companies, a calculator estimating how much you would earn, and supposed tools to automate contract negotiation, joint projects and payments. It also asks for the creator's YouTube channel URL. With it, the site pulls the channel's public data and personalizes the page, so the creator sees their own name and their own numbers inside an environment that looks tailor-made for them.

The Google sign-in that isn't Google

The site doesn't ask for a password up front. It redirects to a Google sign-in screen under the pretext of confirming that the creator owns the channel. The step is believable because signing in with Google is a legitimate, familiar mechanism. But the genuine flow, by default, only shares your name, email address and profile picture with the site; and if it asked for channel management permissions, it would allow uploading or deleting videos. The scam's screen is an imitation: it captures the password and the one-time code, and with them the attackers get into the account. A code like that expires quickly, so whoever receives it can use it immediately, while it is still valid.

After the theft: they change the locks

One victim reported that the attackers replaced her phone number and recovery email with their own and added their own backup codes. That step is what makes recovery hard: the recovery details already point to the attacker. From there, the account gives access to Gmail and Google Drive, and lets the attacker impersonate the owner to followers and collaborators, spread malicious links and promote other scams.

A modular scam: Hollyland, Nike, Spotify and "Scouty"

ESET describes a modular scheme: the functionality, favicons, meta descriptions and parts of the source code are reused, and only the brand identity changes. Besides Hollyland, the attackers impersonated Nike and Spotify, and there are several domains named "Scouty." The domains and identities changed repeatedly between June and August, and ESET warns that the same strategy may return under new ones. Hollyland had already publicly warned about the campaign. Known cases include the Peruvian journalist, creators in Japan who reported it in a YouTube support thread, and English-speaking creators who described it on Reddit.

This isn't the first time a fake sponsorship has been used as bait to steal channels. In December 2024, CloudSEK documented a campaign targeting more than 200,000 YouTube creators, with emails titled "Collaboration Proposal" or "Marketing Opportunity" and password-protected archives hosted on OneDrive, disguised as contracts or promotional material. Inside were executables that steal credentials and session cookies or give remote access. The variant ESET describes reaches the same result with no file at all: there is nothing to download, only a sign-in screen. ESET does not publish the exact "Scouty" domains.

What to look for: indicators from this campaign

Don't do this:

Do this:

An unsolicited sponsorship offer has only one verifiable fact: who is really sending it. Everything else (the videos it quotes, the logos, the income calculator) is built from the channel's own public information. And the "Sign in with Google" button can only be trusted when the address of the page showing it is Google's.