Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

ESET ties fake YouTube sponsorship portals to one modular scheme that swaps brand disguises

Scammers posing as Hollyland, Nike and Spotify lure YouTube creators to fake brand-deal portals that take Google passwords and one-time codes, ESET found. One sign-in hands over Gmail, Drive and the channel itself.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying ESET ties fake YouTube sponsorship portals to one modular scheme that swaps brand disguises
Generated illustration

What happened

  • The opening emails are personalized and reference videos from the target creator's own channel.
  • Rates are negotiated by email before a second message points the creator to a polished portal with campaign metrics, brand logos, an earnings calculator and contract and payment tools.
  • The portal pulls public data from the creator's channel, then asks for a Google sign-in presented as proof of channel ownership.
  • One creator who lost her account said the intruders added their own phone number and recovery email and generated new backup codes.
  • The emails come from addresses with no connection to Hollyland, Nike, Spotify or Maono, the plainest sign the offers are fake.

Why it matters

  • exposure Channels guarded by one-time codes alone are still exposed, because the creator types the code into the attacker's page during the same sign-in.
  • cost Victims start recovery locked out of their own recovery routes, since the phone number, recovery email and backup codes are now controlled by the attacker.
  • constraint Blocklisting the known domains buys little because the fronts rotate; the favicons, meta descriptions and code the sites share are the steadier thing to filter on.
  • decision Under ESET's advice, every sponsorship offer gets confirmed through contacts the brand itself publishes before anyone signs in to a partner portal.

The portals rotate. Their name, look and domains change regularly, according to Help Net Security's account of ESET's findings [8]. In the cases ESET saw, the platform was called MATCHY, at `joinmatchy.com` or `matchyjoin.com`, or SCOUTY, at `joinscouty.com` [8]. Other recent reports point to a third name, TUBIVE, at `mytubive.com` [9]. "This all points to a 'modular' scheme that retains certain components while altering the bogus identity used to reel in each creator. The sites have the same general functionality, as well as share favicons, meta descriptions and portions of their source code," ESET researchers said [10].

Counting Maono, which also turns up as a claimed sender [11], the reporting names four impersonated brands and three portal names [22]. Hollyland, the brand in the recent campaign, is a real maker of wireless audio and video gear [3]. Nike and Spotify appeared in near-identical variants [3]. By ESET's account, the brands are interchangeable fronts on one reused scheme [10].

Help Net Security reported a similar case from the brand side. AndaSeat, which makes gaming chairs and desks, warned creators about sponsorship offers from an agency called Creoventura at `creoventura.com` [13]. "Please note: Creoventura is NOT affiliated with AndaSeat in any way. We have no partnership with them," the company said [13]. Creoventura's "Brands we work with" list includes AndaSeat, and Help Net Security wrote: "Coincidentally or not, Hollyland and Maono are also listed." [14]

The agency site gives a company registration number and an address that exists [15]. The UK register spells the firm Creoventure, though, and lists IT, management and engineering consultancy as its business [15]. Its social media icons go to the generic homepages of X, LinkedIn, Instagram and TikTok [16]. The domain was registered in August 2026 through Namecheap for one year, with ownership hidden [17].

The targets in the reporting are individual YouTube creators [1]. The reporting does not show company-run brand channels being targeted. Brands appear as the disguise, and AndaSeat's public denial is the only documented cost to one of them so far [13]. Help Net Security wrote that the fake pages are mainly built to pass a cursory inspection, not a deeper one [12].

What to watch

  • Any attribution of the MATCHY, SCOUTY and TUBIVE portals to a named operator by ESET or Google.
  • A report of a company-run brand channel, not an individual creator, taken over through the same sponsorship flow.
  • Warnings like AndaSeat's from Hollyland, Nike, Spotify or Maono about offers sent in their names.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Scammers are going after YouTube creators' Google accounts by posing as a brand looking for sponsorship partners.

    ReportedSupportedView cited source
  2. [2]

    The scammers send personalized emails that reference a creator's own videos and direct targeted creators to a fake collaboration platform.

    ReportedSupportedView cited source
  3. [3]

    According to ESET researchers, one recent campaign impersonates Hollyland, a legitimate manufacturer of wireless audio and video gear, while near-identical variants have used the names of Nike and Spotify.

    ReportedSupportedSource: ESET researchers, via Help Net SecurityView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. helpnetsecurity.com

    1 article · October 8, 2026

    YouTubers targeted with fake sponsorships and “channel verification” phishing

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories