BlogGuides

How to Spot a Fake Sponsorship Email Before You Open It

Most of this site is about vetting creators before you trust them. This guide is the mirror image: how a creator vets the brand on the other side of a sponsorship email — because a collaboration offer is now one of the most reliable ways to get a channel stolen.

The scale is not speculative. In a January 2025 investigation, threat-intelligence firm CloudSEK found a phishing campaign that had targeted more than 200,000 YouTube creators with fake brand-collaboration proposals. As of December 2024 the operation was running 340 SMTP servers, each pushing roughly 500–1,000 phishing emails, alongside 46 remote-desktop systems and 26 SOCKS5 proxies used to hide the command-and-control traffic. The lure was a polite, well-formatted offer of a 15-second ad read, priced off the recipient’s subscriber count. The “contract” was a malware downloader that delivered Lumma Stealer, an infostealer that harvests saved credentials and session data.

This is not a new tactic, either. Google’s Threat Analysis Group documented the same playbook back in October 2021: a campaign running since late 2019 in which attackers offered creators fake demos of antivirus software, VPNs, music players, photo editors and games, then hijacked their channels to resell or to broadcast crypto scams. Google identified around 15,000 accounts sending the phishing messages and 1,011 domains purpose-built to serve the fake software, and said it had blocked 1.6 million such messages and cut related Gmail phishing volume by 99.6% after May 2021.

Five years apart, the same shape. Here is how to tell a real offer from a lure without opening anything.

Why the attachment is the whole attack

The important mechanical detail: these campaigns are usually after session cookies, not your password. A stealer that lifts an active session token can log in as you without ever seeing your password — which means it walks past two-factor authentication, because you already passed the 2FA check when that session was created. Google’s TAG writeup calls this class of attack cookie theft, or “pass-the-cookie.”

That changes the risk calculus. A phishing page asks you to type something, and you might catch yourself. A phishing attachment asks you to double-click a file called Brand_Brief_Q3.pdf — and by the time anything looks wrong, the session is already gone. This is why the advice below is organised around never reaching the file, rather than around spotting a fake login screen.

Six checks before you reply

1. Read the sending domain character by character. A real brand’s outreach comes from that brand’s own domain. Free-mail addresses — Gmail, Outlook, Proton — are effectively disqualifying for a company big enough to be buying sponsorships. But the more dangerous version isn’t free mail; it’s a domain that nearly matches: an extra hyphen, a swapped letter, a .co where the real one is .com, or the brand name pushed into a subdomain of a domain the attacker owns (nordvpn.partners-mail.co is not NordVPN). Read it right to left: the part immediately before the final dot is the only part that identifies the owner.

2. Confirm the human exists, through a route you found yourself. Look up the named contact independently — on the company’s own site, or their LinkedIn profile as a current employee. If you want to verify, contact the company through a phone number or address you located yourself, never a number, link, or “verification portal” supplied in the email. Every contact detail inside a phishing email is controlled by the phisher, including the ones that look like a way to check.

3. Treat generic praise as a signal. Bulk campaigns can’t reference your work, because they were addressed to two hundred thousand people. Real outreach from a brand that actually wants your audience will name a video, a series, a niche, or a specific reason you fit the campaign. “I love your content and your channel is a great fit for our brand” is a mail-merge field.

4. Never let the offer put a file on your machine. A legitimate brief is a link to a doc, a deck, or a page you can read in the browser without downloading anything. Password-protected archives are the single loudest tell in the CloudSEK campaign — the password exists to defeat the mail provider’s malware scanner, not to protect a secret. Executables dressed as documents (.exe, .scr, .bat, or a .zip that expands into one) are the payload, full stop. And note what the CloudSEK campaign did with hosting: the files sat on OneDrive. A link to a real, reputable cloud host is not evidence of legitimacy — attackers use those services precisely because they look trustworthy and pass domain filters.

5. Check the money for shapes that never occur in real deals. Real sponsorships run on a written agreement and an invoice. They do not require you to pay anything up front, buy the product yourself for a promised reimbursement, accept payment in crypto, or hand over banking details in a first reply. Anything asking you to send value to receive value is a scam regardless of how polished the branding is. Our brand-deal contract guide covers what a real agreement actually contains.

6. Weigh the pressure. Deadlines that expire in hours, an NDA demanded before you’re told what the campaign even is, or a warning that the slot goes to another creator if you don’t sign today — these are manipulation, not procurement. Brand campaigns have budgets and timelines measured in weeks.

One more structural tell worth knowing: a genuine sponsorship has to be disclosed. The FTC requires that a material connection between a brand and a creator be disclosed clearly and conspicuously. A real brand’s marketing team will raise disclosure language unprompted, because they have compliance obligations too. An offer that never mentions it — or that asks you not to mark the post as sponsored — is either a scam or a client you don’t want.

If you already clicked

Assume session compromise, and act in this order:

  1. Invalidate the sessions before anything else. Changing your password is not sufficient on its own if a stolen cookie is still live — sign out of all other sessions and devices from your account’s security settings, then change the password. On Twitch, the equivalent is disconnecting all sessions in Security and Privacy settings, and resetting your stream key.
  2. Treat the device as compromised. A stealer that ran once has already read whatever the browser had saved. Scan the machine, and change passwords for the accounts stored in that browser — from a different, clean device.
  3. Harden the login. Google’s guidance for creators is to enable 2-Step Verification and to use a passkey as the second factor for the strongest phishing resistance. Passkeys can’t be replayed by an attacker the way a code or a cookie can.
  4. Audit what else has access. Check your channel’s permissions and managers, any brand-account access, and connected third-party apps — a hijacker’s first move is often to add themselves as a manager so they keep access after you fix the password.
  5. Report it. Report the message as phishing in your mail client, report the account on the platform, and file with the FTC at ReportFraud.ftc.gov, which feeds the data used to track these campaigns across platforms. Twitch’s Community Guidelines treat scam and phishing links as a policy violation.

The other kind of fake deal

Not every bad offer is malware. A second category arrives from a real person at a real company and is simply not what it claims: “paid collaboration” that turns out to be gifting only, a brief that quietly assigns the brand perpetual rights to your footage for paid ads, an affiliate arrangement dressed up as a sponsorship fee, or a rate anchored far below what your audience is worth.

Those aren’t security problems, they’re negotiation problems — and the defence is knowing your own numbers before you reply. If you don’t have a rate you can justify, our guides on what to charge for a sponsored post and what belongs in a media kit are the place to start.

Where our checker fits — and where it doesn’t

Being straight about this: our free checker scores creator accounts on YouTube and Twitch. It cannot tell you whether a brand or an agency emailing you is real, and we won’t pretend otherwise.

Where it does help is the other direction — and the reverse case is more common than creators expect. If an “agency” name-drops the creators it supposedly represents, those handles are checkable: run them through the free check and see whether the roster it’s claiming has the audience history a real client roster would. Thin, purchased-looking accounts behind a pitch tell you something about who you’re talking to. If you’re on the brand side of the table, that same check is the first step in vetting a creator before a deal, and the methodology page shows exactly what goes into the score.

The bottom line

A real sponsorship offer survives being slowed down. It comes from the brand’s own domain, names a person you can find independently, references your actual work, links to something you can read in a browser, and never needs money or a downloaded file to move forward. A phishing lure fails at least one of those and usually several — but only if you check before you open the attachment, because the attachment is the attack.

Sources: CloudSEK — How Threat Actors Exploit Brand Collaborations to Target Popular YouTube Channels; Infosecurity Magazine — YouTube Creators Targeted in Major Phishing Campaign; Hackread — Malware Hidden in Fake Business Proposals Hits YouTube Creators; Google Threat Analysis Group — Phishing campaign targets YouTube creators with cookie theft malware; YouTube Help — Channel security tips; YouTube Help — Safety tips and resources for YouTube creators; FTC — Disclosures 101 for Social Media Influencers; Twitch Community Guidelines.

Check a creator now

Free, no login. Get a transparent 0–100 score.

or

Not vetting anyone right now? Get new guides + checker updates by email.