SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Fake Hollyland sponsors negotiate rates with YouTube creators before phishing their Google logins
Scammers posing as Hollyland are sending YouTube creators tailored sponsorship offers that end at a fake Google login, WeLiveSecurity reported. That page takes the password and the one-time code, and with them the account that owns the channel.
The Watch · Security desk

What happened
- The first email cites specific videos from the target's own channel and offers a device plus the prospect of a long-term collaboration.
- After a journalist in Peru replied with her rates, a sender styled "Brandi" from Hollyland's Creator Partnerships team pointed her to joinmatchy[.]com/hollyland.
- One creator who fell for a version of the scheme described attackers replacing her phone number and recovery email with theirs and adding their own backup codes.
- Variants of the operation pose as Nike and Spotify and run on several domains, including some that contain the name Scouty.
Why it matters
- decision Channel teams can stop the chain at the first email by matching the sender's domain to the brand before sending rates; in the Peru case the domain had nothing to do with Hollyland.
- constraint Authenticator and SMS codes do not protect a channel account against this page, because it asks for the one-time code in the same flow as the password.
- precedent Taking down one domain or one impersonated brand buys little time, since the operators keep the site template and change only the name and address in front of it.
Nothing sensitive is requested at first contact [6]. By the time a login prompt appears, the creator has quoted a fee and watched the site turn her channel URL into a personalised dashboard built from public data [5][8]. The dashboard sits among campaign metrics, logos of major companies, an income calculator and tools for contracts and payments [7]. The sign-in is presented as a check that she owns the YouTube channel [9]. WeLiveSecurity points out that "Sign in with Google" is a legitimate mechanism used by countless platforms [10].
What the creator loses depends on what sits behind that prompt, according to WeLiveSecurity [11]. A genuine Google flow shares only name, email address and profile picture by default. An operator who also requests permission to manage the channel can upload or delete videos [11]. A counterfeit page goes further, into the account's recovery methods, Gmail and Google Drive [12].
WeLiveSecurity describes the scheme as modular. The components stay the same and the fake identity changes for each creator [19]. The sites share general functionality, favicons, meta descriptions and portions of source code [16]. Domains and persona names changed repeatedly between June and August, a span of about three months [18][21]. The emails went to specific, chosen creators in Peru, Japan and English-speaking markets [17]. Hollyland, a real maker of wireless transmission and audiovisual equipment, has issued its own warning about the campaign [1][14].
The researchers traced one operation from the first email to the login request and found it repackaged under several brand identities [2]. That evidence supports treating a sponsorship pitch that moves to an outside platform and then to a Google sign-in as an established phishing pattern for anyone running a creator or brand channel [2][19]. WeLiveSecurity did not publish victim numbers, say which variants used a counterfeit page, or estimate how much brand-deal email the operation accounts for [2].
What to watch
- New domains after August that reuse the same favicons, meta descriptions and source code would show the kit is still running under fresh brands.
- Victim counts from WeLiveSecurity, Hollyland or Google would show whether this is a narrow operation or a broad one against creators.
- A move from counterfeit login pages to real Google consent requests for channel management would shift the check to the permissions listed on the consent screen.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A recent campaign impersonates Hollyland, a legitimate manufacturer of wireless transmission and audiovisual equipment.
- [2]
WeLiveSecurity traced the scheme from first contact and the negotiation of a supposed partnership through to the login request, and spotted several variants that repackage the campaign under different brand identities and domains.
- [3]
The email was customised with specific references to videos from the target's YouTube channel and offered the creator a device and the prospect of a long-term collaboration.
- [4]
In the Peru case, the sender's email domain was unrelated to Hollyland, which WeLiveSecurity called a clear warning sign.
- [5]
A journalist in Peru received a 'Paid collaboration opportunity' email from a sender calling herself 'Brandi' of Hollyland's Creator Partnerships team; after she replied with her rates, 'Brandi' asked her to go to joinmatchy[.]com/hollyland, where channel statistics, the agreement and payment would supposedly be verified.
- [6]
The scheme does not immediately ask for a password or other sensitive information; the target is first taken through a series of plausible-looking steps.
- [7]
The fraudulent website features campaign metrics, logos of major companies, an income calculator and features designed to automate contract negotiations, joint projects and payments.
- [8]
The platform asks for the creator's YouTube channel URL and uses it to retrieve public information and generate a seemingly personalised experience.
- [9]
The next step takes the creator to a Google sign-in page, supposedly to verify ownership of the YouTube channel.
- [10]
'Sign in with Google' is a legitimate authentication mechanism used by countless online platforms.
- [11]
The extent of the damage depends on what is behind the page: the genuine Google sign-in flow by default shares only name, email address and profile picture, unless more is requested, such as permission to manage the YouTube channel, which would let attackers upload or delete videos.
- [12]
An imposter login page captures the password and one-time code, and with them the account itself, including personal information, account recovery methods, and access to services such as Gmail and Google Drive.
- [13]
One content creator who fell for a version of the attack described attackers replacing her phone number and recovery email with their own details and adding their own backup codes to hamper account recovery.
- [15]
The attackers also pose as other brands including Nike and Spotify and use several domains, including ones containing 'Scouty'.
- [16]
The sites have the same general functionality and share favicons, meta descriptions and portions of their source code.
- [17]
The emails are personalised and directed at specific creators in various parts of the world, including Peru, Japan and English-speaking content creators.
- [18]
The domains and names changed repeatedly between June and August.
- [19]
WeLiveSecurity describes a 'modular' scheme that retains certain components while altering the bogus identity used to reel in each creator.
- [20]
Code-based two-factor authentication does not stop the imposter page, because the page collects the one-time code along with the password.
- [21]
The rotation of domains and names ran across about three months.
Sources
1 independent publisher whose own reporting we read for this story.
- welivesecurity.comInside a brand deal scam targeting YouTube creators
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.