SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
ESET ties fake YouTube sponsorship portals to one modular scheme that swaps brand disguises
Scammers posing as Hollyland, Nike and Spotify lure YouTube creators to fake brand-deal portals that take Google passwords and one-time codes, ESET found. One sign-in hands over Gmail, Drive and the channel itself.
The Watch · Security desk

What happened
- The opening emails are personalized and reference videos from the target creator's own channel.
- Rates are negotiated by email before a second message points the creator to a polished portal with campaign metrics, brand logos, an earnings calculator and contract and payment tools.
- The portal pulls public data from the creator's channel, then asks for a Google sign-in presented as proof of channel ownership.
- One creator who lost her account said the intruders added their own phone number and recovery email and generated new backup codes.
- The emails come from addresses with no connection to Hollyland, Nike, Spotify or Maono, the plainest sign the offers are fake.
Why it matters
- exposure Channels guarded by one-time codes alone are still exposed, because the creator types the code into the attacker's page during the same sign-in.
- cost Victims start recovery locked out of their own recovery routes, since the phone number, recovery email and backup codes are now controlled by the attacker.
- constraint Blocklisting the known domains buys little because the fronts rotate; the favicons, meta descriptions and code the sites share are the steadier thing to filter on.
- decision Under ESET's advice, every sponsorship offer gets confirmed through contacts the brand itself publishes before anyone signs in to a partner portal.
The portals rotate. Their name, look and domains change regularly, according to Help Net Security's account of ESET's findings [8]. In the cases ESET saw, the platform was called MATCHY, at `joinmatchy.com` or `matchyjoin.com`, or SCOUTY, at `joinscouty.com` [8]. Other recent reports point to a third name, TUBIVE, at `mytubive.com` [9]. "This all points to a 'modular' scheme that retains certain components while altering the bogus identity used to reel in each creator. The sites have the same general functionality, as well as share favicons, meta descriptions and portions of their source code," ESET researchers said [10].
Counting Maono, which also turns up as a claimed sender [11], the reporting names four impersonated brands and three portal names [22]. Hollyland, the brand in the recent campaign, is a real maker of wireless audio and video gear [3]. Nike and Spotify appeared in near-identical variants [3]. By ESET's account, the brands are interchangeable fronts on one reused scheme [10].
Help Net Security reported a similar case from the brand side. AndaSeat, which makes gaming chairs and desks, warned creators about sponsorship offers from an agency called Creoventura at `creoventura.com` [13]. "Please note: Creoventura is NOT affiliated with AndaSeat in any way. We have no partnership with them," the company said [13]. Creoventura's "Brands we work with" list includes AndaSeat, and Help Net Security wrote: "Coincidentally or not, Hollyland and Maono are also listed." [14]
The agency site gives a company registration number and an address that exists [15]. The UK register spells the firm Creoventure, though, and lists IT, management and engineering consultancy as its business [15]. Its social media icons go to the generic homepages of X, LinkedIn, Instagram and TikTok [16]. The domain was registered in August 2026 through Namecheap for one year, with ownership hidden [17].
The targets in the reporting are individual YouTube creators [1]. The reporting does not show company-run brand channels being targeted. Brands appear as the disguise, and AndaSeat's public denial is the only documented cost to one of them so far [13]. Help Net Security wrote that the fake pages are mainly built to pass a cursory inspection, not a deeper one [12].
What to watch
- Any attribution of the MATCHY, SCOUTY and TUBIVE portals to a named operator by ESET or Google.
- A report of a company-run brand channel, not an individual creator, taken over through the same sponsorship flow.
- Warnings like AndaSeat's from Hollyland, Nike, Spotify or Maono about offers sent in their names.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Scammers are going after YouTube creators' Google accounts by posing as a brand looking for sponsorship partners.
- [2]
The scammers send personalized emails that reference a creator's own videos and direct targeted creators to a fake collaboration platform.
- [3]
According to ESET researchers, one recent campaign impersonates Hollyland, a legitimate manufacturer of wireless audio and video gear, while near-identical variants have used the names of Nike and Spotify.
- [4]
The fraudsters first negotiate rates by email, then send the creator to a polished site with campaign metrics, big-brand logos, an earnings calculator and supposed tools for handling contracts and payments; a second email points to the fake platform.
- [5]
The site pulls public data from the creator's channel and only then prompts a Google sign-in, framed as a step to verify channel ownership.
- [6]
Entering the password and the one-time verification code hands attackers the whole account, from Gmail and Drive to the YouTube channel itself.
- [7]
One creator who fell victim said the intruders swapped in their own phone number and recovery email and generated new backup codes, making it harder for her to get back in.
- [8]
The name, look and domains hosting the fake collaboration platform are changed regularly; in the cases spotted by ESET it was called MATCHY (joinmatchy.com or matchyjoin.com) or SCOUTY (joinscouty.com).
- [9]
Other recent reported scam attempts point to a platform called TUBIVE at mytubive.com.
- [10]
"This all points to a 'modular' scheme that retains certain components while altering the bogus identity used to reel in each creator. The sites have the same general functionality, as well as share favicons, meta descriptions and portions of their source code," ESET researchers said.
- [11]
The most obvious indicator that the emails were not sent by Hollyland, Nike, Spotify or Maono is that the originating email address has nothing to do with those companies.
- [12]
The fake collaboration pages are mainly focused on passing a cursory inspection, not a deeper one, Help Net Security wrote.
- [13]
AndaSeat, a brand that designs and manufactures gaming chairs and desks, warned about sponsorship offers involving an agency called Creoventura (creoventura.com), saying: "Please note: Creoventura is NOT affiliated with AndaSeat in any way. We have no partnership with them."
- [14]
Help Net Security presented Creoventura as a similar example; the agency's 'Brands we work with' list includes AndaSeat, and Help Net Security wrote: "Coincidentally or not, Hollyland and Maono are also listed."
- [15]
Creoventura's website provides a company registration number and an existing address, but the UK's official register spells the name Creoventure and lists IT, management and engineering consultancy as its business activities.
- [16]
The social media icons on the Creoventura site lead only to the generic homepages of X, LinkedIn, Instagram and TikTok instead of company profiles.
- [17]
The Creoventura domain was registered in August 2026 through Namecheap for one year, with ownership information hidden.
- [18]
ESET advises creators who receive a sponsorship offer to verify it independently, looking up the brand's official contact details themselves instead of replying to the email or clicking its links.
- [19]
One-time-code two-step verification does not stop this flow, because the creator enters the code into the attacker's portal during the same sign-in as the password.
- [20]
With the phone number, recovery email and backup codes replaced, the account's recovery routes are controlled by the attacker.
- [21]
Because portal names and domains rotate regularly while favicons, meta descriptions and source code are shared across sites, the shared components are a steadier filtering signal than any single domain.
- [22]
The reporting names four impersonated brands (Hollyland, Nike, Spotify, Maono) and three portal names (MATCHY, SCOUTY, TUBIVE).
Sources
1 independent publisher whose own reporting we read for this story.
- helpnetsecurity.comYouTubers targeted with fake sponsorships and “channel verification” phishing
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Creator economy securityFollow
- Brand ImpersonationFollow
- PhishingFollow
- Account TakeoverFollow