Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Fake Hollyland sponsors negotiate rates with YouTube creators before phishing their Google logins

Scammers posing as Hollyland are sending YouTube creators tailored sponsorship offers that end at a fake Google login, WeLiveSecurity reported. That page takes the password and the one-time code, and with them the account that owns the channel.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Fake Hollyland sponsors negotiate rates with YouTube creators before phishing their Google logins
Generated illustration

What happened

  • The first email cites specific videos from the target's own channel and offers a device plus the prospect of a long-term collaboration.
  • After a journalist in Peru replied with her rates, a sender styled "Brandi" from Hollyland's Creator Partnerships team pointed her to joinmatchy[.]com/hollyland.
  • One creator who fell for a version of the scheme described attackers replacing her phone number and recovery email with theirs and adding their own backup codes.
  • Variants of the operation pose as Nike and Spotify and run on several domains, including some that contain the name Scouty.

Why it matters

  • decision Channel teams can stop the chain at the first email by matching the sender's domain to the brand before sending rates; in the Peru case the domain had nothing to do with Hollyland.
  • constraint Authenticator and SMS codes do not protect a channel account against this page, because it asks for the one-time code in the same flow as the password.
  • precedent Taking down one domain or one impersonated brand buys little time, since the operators keep the site template and change only the name and address in front of it.

Nothing sensitive is requested at first contact [6]. By the time a login prompt appears, the creator has quoted a fee and watched the site turn her channel URL into a personalised dashboard built from public data [5][8]. The dashboard sits among campaign metrics, logos of major companies, an income calculator and tools for contracts and payments [7]. The sign-in is presented as a check that she owns the YouTube channel [9]. WeLiveSecurity points out that "Sign in with Google" is a legitimate mechanism used by countless platforms [10].

What the creator loses depends on what sits behind that prompt, according to WeLiveSecurity [11]. A genuine Google flow shares only name, email address and profile picture by default. An operator who also requests permission to manage the channel can upload or delete videos [11]. A counterfeit page goes further, into the account's recovery methods, Gmail and Google Drive [12].

WeLiveSecurity describes the scheme as modular. The components stay the same and the fake identity changes for each creator [19]. The sites share general functionality, favicons, meta descriptions and portions of source code [16]. Domains and persona names changed repeatedly between June and August, a span of about three months [18][21]. The emails went to specific, chosen creators in Peru, Japan and English-speaking markets [17]. Hollyland, a real maker of wireless transmission and audiovisual equipment, has issued its own warning about the campaign [1][14].

The researchers traced one operation from the first email to the login request and found it repackaged under several brand identities [2]. That evidence supports treating a sponsorship pitch that moves to an outside platform and then to a Google sign-in as an established phishing pattern for anyone running a creator or brand channel [2][19]. WeLiveSecurity did not publish victim numbers, say which variants used a counterfeit page, or estimate how much brand-deal email the operation accounts for [2].

What to watch

  • New domains after August that reuse the same favicons, meta descriptions and source code would show the kit is still running under fresh brands.
  • Victim counts from WeLiveSecurity, Hollyland or Google would show whether this is a narrow operation or a broad one against creators.
  • A move from counterfeit login pages to real Google consent requests for channel management would shift the check to the permissions listed on the consent screen.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A recent campaign impersonates Hollyland, a legitimate manufacturer of wireless transmission and audiovisual equipment.

    ReportedSupportedView cited source
  2. [2]

    WeLiveSecurity traced the scheme from first contact and the negotiation of a supposed partnership through to the login request, and spotted several variants that repackage the campaign under different brand identities and domains.

    ReportedSupportedView cited source
  3. [3]

    The email was customised with specific references to videos from the target's YouTube channel and offered the creator a device and the prospect of a long-term collaboration.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. welivesecurity.com

    1 article · October 7, 2026

    Inside a brand deal scam targeting YouTube creators

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories