TL;DR:
- The fake brand deal email is one of the most durable channel-takeover tactics going. Google has tracked it since 2019 and it is still in circulation.
- The lure changes and the payload does not. Sponsorship offers, copyright strikes, and policy updates are all doors into the same attack.
- The attachment installs infostealer malware that copies your session cookie, which lets an attacker into your account without your password and without your two-factor code.
- The best-known red flag, checking the sender’s address, has already been beaten. One 2025 campaign sent phishing mail from the genuine
no-reply@youtube.com. - Verify every offer through a channel the sender did not give you, and never open a “brief” from an unsolicited email.
- Passkeys, a permissions audit, and Enhanced Safe Browsing close most of the remaining gap.
In the immortal words of one Elvis Presley: Wise men say only fools rush in.
In this case the wise men are not (just) men, they’re Google’s threat analysis team, and what they actually said is that attackers have been using fake sponsorship emails to take over YouTube channels since 2019.
Getting your first real brand deal email is a genuine milestone. Someone with a budget went looking for creators in your niche, found you, and said “yes.” The rate feels reasonable (if it looks too good that’s a clear 🚩), the brand is one you actually recognize, and look! There’s a contract attached.
But rushing to open that contract is how they get you.
The people running these scams know exactly which brands creators in your niche hear from. They impersonate the companies whose outreach would make sense to you.
Two things make this worth your attention even if you consider yourself hard to fool. The standard advice about spotting these emails is partly out of date, and the single most repeated security tip for creators (turn on two-factor authentication) does not stop this particular attack.
The channel you spent years building, the one whose growth you’ve been grinding for, can change hands in the time it takes to open a PDF.
Read on for how the scam actually works, the red flags to watch for, and what to do if you’ve already clicked.
Get an unfair advantage on YouTube
Give your YouTube channel the upper hand and easily optimize for more views, more subs, and more of every metric that matters.
Get Started
Table of contents
A hijacked YouTube channel is a product with a market price. Google’s Threat Analysis Group, which has been tracking these campaigns since 2019, found channels being resold on account-trading markets for anywhere from $3 to $4,000 depending on subscriber count. Bigger channels go for considerably more.
Once they have your channel, they’ll typically rename it, hide your existing videos, and will often run a livestream promoting a some kind of scam — often cryptocurrency-related — to your subscribers. These livestreams will often use deepfakes of a recognizable public figure.
Fake sponsorship emails sent to creators are the most common attack vector because they work so well: a brand deal is the one category of unsolicited mail most creators are actively hoping to receive. So creators let their guard down and open the attached contract to take a look. And the damage is done.
In one campaign that Google disrupted, attackers registered at least 1,011 domains built solely for this purpose and ran roughly 15,000 accounts. Google blocked 1.6 million messages to targets and restored around 4,000 accounts that had already been taken.
How the scam actually works, step by step
The attack chain is consistent, even if the specifics might change:
- The approach. You get an email offering a paid sponsorship, typically from a recognizable brand that already sponsors channels in your niche. VPN companies, audiobook services, browser extensions, and mobile games are all commonly impersonated, because outreach from them is plausible.
- The hook. The message references your actual content, sometimes a specific video. Rates are realistic. Nothing reads as desperate or scammy.
- The payload. You’re asked to review a “creative brief,” “contract,” or “game demo.” It arrives as an PDF, a spreadsheet, a
.zipor.rararchive (often password-protected to hamper antivirus scanners), or cloud-storage link. - The install. Opening the payload runs an infostealer, a class of malware built to harvest saved passwords and browser session data. Google’s researchers named more than a dozen families in use, including RedLine, Vidar, and Raccoon.
- The takeover. The malware copies your browser’s session cookies and sends them to the attacker, who loads them into their own browser and is inside your account. No password prompt. No verification code.

The whole sequence can run in under a minute from the moment you open the file.
Two-factor authentication does help here
“Enable 2FA” is good advice… but this hack is scary because it can get around 2FA.
YouTube 2FA protects the login. When you enter your password, it demands a second proof before it will let you in. But once you are logged in, your browser holds a session cookie: a token that tells Google “this person already proved who they are, let them through.” Every site works this way, otherwise you’d re-authenticate on every page load. Steal that token and you inherit a session that has already cleared the 2FA check. Google’s own term for this is a pass-the-cookie attack.
So the attacker never sees your login screen. They are not guessing your password and they are not intercepting your code, they are stepping into a session you already opened. They don’t need to authenticate… because you already authenticated.
So, consider 2FA as necessary but not sufficient on its own. The only thing that can actually protect you is never opening the file in the first place.
Old advice is good advice… but it’s not enough
Real brands email from @theirowndomain.com scammers email from Gmail or a lookalike domain like @there0wndomain.com. That holds true, but scammers have found a way around that limitation too.
In late February 2025, attackers ran a campaign that sent phishing mail from no-reply@youtube.com. Not a spoof, not a lookalike. The real address.
They did it by abusing YouTube’s own private-video-sharing feature, which generates a notification email from YouTube’s genuine servers. The video claimed to announce changes to monetization policy and featured an AI-generated deepfake of YouTube CEO Neal Mohan delivering the news. Viewers were sent to studio.youtube-plus[.]com to “confirm” the policy change, where the page harvested their credentials, session cookies, and 2FA codes. Security researchers tracking the campaign put the number of creators targeted at more than 200,000, distributed across 340 mail servers.
YouTube’s response was a pinned post on its official community forum, and the rule it states is worth memorizing:
“YouTube and its employees will never attempt to contact you or share information through a private video. If a video is shared privately with you claiming to be from YouTube, the video is a phishing scam.”
Take the general principle rather than just the specific case. A message can pass every surface check, correct domain, correct branding, plausible content, and still be hostile.
The tactics change but the basics don’t
The sponsorship offer is the best-known version of this attack, but it is one of several… and scammers are always innovating their approach. Google’s researchers documented the sponsorship lure back in 2019. The deepfake private-video campaign ran in early 2025. By April 2026, scammers were trying their luck with a copyright strike notice. But it’s the same basic idea: a message that frightens or excites you into opening something before you think.
So let’s look at what remains constant across all of these attacks:
- A message arrives that triggers an emotional reaction.
- It can be positive (e.g. brand deal, offering free product) or negative (e.g. copyright strike, monetization change)
- It asks you to open a file or sign in on a page.
- That step installs an infostealer or harvests your session directly.
- Your cookie is copied and your channel changes hands.
Only step one gets redesigned. Steps two through four have not meaningfully changed in years. So any talk of the specifics of a scam ages badly. But the good habits required to avoid being scammed do not.
🚩 Red flags to watch for
In the message itself
- An attachment you did not ask for, especially
.zip,.rar,.scr,.pdf, .xlsx, .exe. - A password-protected file or archive.
- Timing pressure like “limited slots,” or “campaign closes today,” or “respond within 24 hours.”
- No details like physical address, phone number, or company specifics in the signature block.
- A reply-to address on a different domain than the from address.
In the offer
- Silly money that seems too good to be true. A four-figure rate for a channel with two thousand subscribers is bait, and knowing what your channel should actually charge makes this one easy to catch.
- No specific deliverables. Real sponsorships name the format, the length, the usage rights, and the payment terms in writing.
- A request that you pay for something, including product samples or “processing.”
- Vagueness about what caught their eye, or praise generic enough to have been sent to a thousand people.
In the link
- Hover before clicking, every time. Check the domain the link actually resolves to, not the text displayed.
- Watch for a real brand name sitting in a subdomain of someone else’s domain.
youtube.some-site.comis not YouTube, andstudio.youtube-plus.comis not YouTube either.
Get an unfair advantage on YouTube
Give your YouTube channel the upper hand and easily optimize for more views, more subs, and more of every metric that matters.
Get Started
How to verify a brand deal before you click anything
The verification rule is simple to state and it covers nearly everything: confirm through a route the sender did not give you.
- Do not use the contact details in the email. A phone number or website in a phishing message reaches the attacker.
- Search for the company independently. Go to their real site by typing the address, then find their marketing or partnerships contact there.
- Look up the person on LinkedIn. Check that they list that employer, and that the profile has history behind it.
- Reply asking for the brief in the email body, as plain text rather than an attachment. Legitimate partnership managers will summarize deliverables in writing without hesitation. Scammers need you to open the file.
- Open anything you must open in a sandbox. Google Drive’s preview or a device that is not signed in to your channel will render a genuine PDF perfectly well and will not execute a Windows binary against your logged-in browser.
- Apply YouTube’s own three-step test: slow it down, spot check, and stop before sending anything.
If the deal survives all of that, it’s probably real, and it’s worth reading the contract properly and negotiating it before you sign.
Lock your channel down
2FA is good but it’s not enough on its own.

Use a passkey, not an SMS code
YouTube’s current official guidance names passkeys as the strongest available second factor, ahead of security keys, Google prompts, authenticator apps, and phone codes in that order. A passkey is bound to the real domain, so it cannot be handed over to a convincing fake login page the way a typed code can. If you’re still on SMS, this is the single highest-value change on the list.
Turn on Enhanced Safe Browsing
In Chrome, this checks downloads and sites against Google’s threat data in real time rather than against a cached list. It’s the protection Google specifically recommends against this campaign, and it costs nothing.
Audit your channel permissions
Every person with access to your channel is another potential chink in your channel’s armor. Editors, thumbnail designers, managers, and the agency you worked with two years ago. Check who has access, remove anyone that doesn’t need access. Ensure anyone with access is taking the proper precautions.
- Give the lowest access level that lets someone do their job. Not everyone needs to be a manager.
- Remove anyone who no longer works with you, on the day they stop.
- Put a recurring reminder in your calendar to review the list quarterly.
Set your recovery options now
Add a current phone number and a backup email to your Google account while you still have access. Recovery information you update after a takeover is recovery information the attacker has already changed.
What to do if you already clicked
Speed matters. So we’ll get straight to the point:
- Get offline and scan the machine. The malware is still running and will re-steal anything you reset while it’s active. Run a full antivirus scan before you change a single password.
- Sign out of all sessions. In your Google account under Security, review your devices and revoke all access. This forces all devices to log in again and invalidates the stolen cookie.
- Change your Google password once you’re sure only you have access, change your password and check that your recovery phone and email are still yours.
- Switch your second factor to a passkey don’t rely on SMS authentication anymore.
- Check YouTube Studio settings for added managers, changed channel names, new or hidden videos, and any live streams you did not start.
- Check your monetization and payment details in AdSense for altered bank information.
- Use Google’s account recovery flow if you’re locked out, and note that the first 48 hours are when recovery is most likely to succeed. YouTube also has a dedicated support path for compromised channels, and there is a separate process for channels that were terminated rather than hijacked.
If your channel was compromised and your audience was impacted, you need to disclose what happened. Viewers who saw a crypto stream on your channel need to know it wasn’t you, and saying so publicly is what stops the damage spreading to the people who trusted you.
Get an unfair advantage on YouTube
Give your YouTube channel the upper hand and easily optimize for more views, more subs, and more of every metric that matters.
Get Started
Small channels are targeted heavily. These campaigns are automated and sent in bulk, so the cost of including you is effectively zero. Smaller channels are often the better target because they are less likely to have passkeys enabled or to have audited their permissions, and Google’s data showed hijacked channels selling for as little as $3, which tells you attackers are not being selective.
No, though you are safer. Two-factor authentication protects the moment you log in. Cookie theft skips that moment entirely by stealing a session that already passed the check. A passkey plus not opening unsolicited attachments is what actually addresses this attack.
Attackers used YouTube’s legitimate private-video-sharing feature, which sends a real notification from YouTube’s servers when someone shares a video with you. The email was genuine, the video it pointed to was the attack. YouTube has since confirmed it never contacts creators or shares information through private videos.
Not reliably. Attackers commonly send password-protected archives specifically so that antivirus software cannot inspect the contents, and infostealers are updated faster than signature databases. If you genuinely need to see a document from an unverified sender, open it in a browser-based preview or on a device that is not signed in to your channel.
That is the point of the impersonation. Attackers choose brands with real, active creator programs precisely because their outreach looks normal. Verify through the company’s own website rather than through anything in the email, and the real brand will confirm it in a day.
Quarterly as a baseline, and immediately whenever someone joins your team, leaves it, changes role, or tells you their own accounts were compromised. A collaborator’s infected laptop is a route into your channel regardless of how well you have secured your own.