A sponsorship portal is not trustworthy just because it shows your channel, a brand logo and a familiar Google sign-in button. Before connecting your YouTube account, confirm the campaign and the intermediary with the brand through a contact you found independently. Check the browser's real address, then inspect any requested permissions. If a pitch falls apart when you decline a surprise sign-in, stop there.
This is a live concern, not a claim that all creator platforms are fraudulent. ESET's September 11 original investigation follows a purported Hollyland collaboration from a personalized email to a polished intermediary site and a Google sign-in step; its October 7 English edition makes the findings accessible to more readers. These are two editions of the same research, not independent cases. PhishEye's September 30 investigation documents a related fake sponsorship platform that drew a counterfeit browser window and, according to its analysis, proxied a real Google login to capture a session. The researchers describe different observed variants; do not assume every suspicious offer uses the same software or that a listed domain's status is unchanged today.
YouTube's creator safety guidance already tells creators to verify an unexpected brand-deal email through the company or a known contact. The recent investigations show why the verification needs to cover the portal and sign-in request, not only the opening message.
How the pitch reaches the login screen
The first email may mention a real video, fit your niche and offer both a product and a fee. None of those details proves the sender works for the brand; a public channel supplies enough information to personalize a pitch. ESET describes an offer that invited a journalist to discuss rates before sending them to an alleged collaboration site. Waiting until after a normal negotiation made the later verification request feel like administration rather than a new security decision.
The site can then present campaign metrics, a contract area, payment language and recognizable logos. A public channel lookup can make its dashboard appear tailored to you. PhishEye observed a site claiming large creator payouts and showing real creators' names as apparent social proof; its report found no evidence that those creators were involved. Treat both the numbers and the displayed endorsements as claims made by the site, not proof about it.
The decisive step is often “verify your channel with Google.” A legitimate service might offer Google sign-in, but that fact alone does not validate the sponsorship. ESET distinguishes a genuine sign-in that shares basic profile details unless additional permissions are requested from an imposter page that captures credentials. PhishEye reports a more specific browser-in-the-browser variant: page content drew a fake window, including an address bar that looked like Google's. Its analysis says the underlying flow could relay credentials and session data through attacker-controlled infrastructure. These are documented mechanisms, not a test a creator should reproduce on a suspicious site.
In a separate October 6 investigation, Island researchers documented fake advertising-assistant sites that drew a Google-looking browser window inside a page to target ad-account operators. That does not establish a link to the creator-sponsorship campaign. It reinforces the practical check: the apparent address bar inside a page can be artwork, while the real browser remains on a different domain.
Check three identities before connecting anything
First, verify the brand. Find its official site yourself, then use a published contact or an existing relationship to ask whether the named campaign, sender and intermediary are real. A reply from the same email thread or a phone number printed on the pitch page is not independent confirmation. Ask who will sign, who will pay and which company operates the portal. OfferVet's general brand-deal scam checklist covers the rest of the offer before you agree to deliverables.
Second, verify the portal. Compare its exact domain with a link supplied by the independently contacted brand. A good design, HTTPS padlock, familiar trademark or prefilled channel name only tells you how the page is presented. Do not search for a listed attack domain, open it to “check,” or test it with a spare account. Attack sites rotate, and a domain that once hosted a lure may later show something else. The useful question is whether the genuine brand confirms this exact service and your exact invitation.
Third, verify the Google step. A real Google sign-in takes place on Google's own domain in the browser's actual address bar or a real separate browser window. A picture of an address bar inside a webpage is not the browser's address bar. Look at the full host, not a logo or page title, and inspect any consent screen's app name and permissions. A request to manage or upload to your channel is much broader than merely reading public channel details. Even if the Google screen is genuine, you can still refuse an unnecessary permission and ask the buyer to explain why it is needed.
Do not send your password, recovery code, backup codes or session data to a sponsor. YouTube says it will not request your password and recommends using channel permissions, rather than sharing Google sign-in details, when a genuine collaborator needs a defined role. A credible brand should be able to confirm a campaign without asking you to surrender account control.
A short reply that keeps the deal moving
You can ask for verification without accusing the sender. For example: “Please confirm the contracting brand and agency, the company operating the portal, its official domain, the scope of any Google access it requests, and an independent brand contact who can verify this campaign. I can review the brief without connecting my channel first.”
That message is a negotiation aid, not a guarantee of safety. A legitimate team may use a third-party platform and still have an unclear process. A scammer may also send polished answers. Verify the answers through an independently sourced channel before visiting the portal. If an agreement requires performance data, you can discuss a dated report or a narrow platform permission separately; our brand-deal performance report guide helps define what data the buyer actually needs.
If you already entered credentials or approved access
Act through Google's own account and YouTube recovery pages, reached independently. Do not return to the pitch link or follow a “recovery” contact in the suspicious message. From a trusted device, review Google's security events, signed-in devices, recovery details, passkeys and connected third-party apps; remove anything you do not recognize, change your password and strengthen sign-in. If you have lost access, use the official recovery route linked from YouTube's safety page. Check channel permissions and published videos after access is restored.
Treat a reported takeover as a report, not proof of the exact technique in every case. PhishEye cites a creator's September 25 Google support report of rapid password and recovery changes, while its own technical analysis concerns the portal it inspected on September 30. The operational lesson is simpler: prompt action matters, and a second factor cannot be assumed to make an attacker-controlled sign-in page safe.
Preserve the suspicious email, the sender domain, any portal URL and screenshots for a report to the platform and the impersonated brand. Do not post a live phishing link for other creators to test. If you have already sent a contract, payment details or unpublished work, tell the real brand and relevant service what was shared so they can assess the exposure.
Where DealShield fits
You can use OfferVet's scam checker to organize a suspicious pitch and surface wording or missing-term signals before you respond. It cannot inspect a remote site's code, confirm that a portal belongs to a brand, validate a Google consent screen, protect an already compromised account, or certify an offer as genuine. The decisive checks happen through the brand's independent contact path and your own account's official security controls.
Pause at the account connection step, even after a convincing conversation. A real campaign can survive a request to confirm its people, domain and access scope. Your channel should never be the price of seeing a brief.
Sources
- ESET WeLiveSecurity, October 7, 2026: investigation of a fake creator collaboration
- ESET WeLiveSecurity, September 11, 2026: original Spanish investigation
- PhishEye Research, September 30, 2026: Matchube investigation and methodology
- Island Research, October 6, 2026: separate fake-browser sign-in campaign targeting ad teams
- YouTube Help: safety tips for creators and brand-deal verification
- TeamYouTube, July 28, 2025: fake brand-deal scam warning
More guides
Creator Content Usage Rights: Organic vs Paid
Learn what organic reposting and paid ad use permit, then check channels, edits, term, renewal and fees before licensing creator content to a brand.
Read itTikTok's The Next Episode: A Creator Deal Checklist
TikTok and Amplify announced a creator-led series initiative. Here is what it says, what it does not promise, and the terms to check before a series deal.
Read it