Scam database

The fake-sponsorship campaigns hitting creator inboxes

Every entry is a verified campaign pattern: who it impersonates, how it works, and the tells that give it away. Seen one of these? Run it through the checker and it will match.

The fake 'connect your channel' consent page that steals a token, not a password

No malware file at all. The email asks you to log in or authorize a creator dashboard to start the deal, and links to a page that harvests your Google credentials or a broad OAuth token that hands over your YouTube account.

OAuth consent phishing page · last seen 2026-08-24

RedLine and Lumma stealers hidden behind a 'download the brief' link

Instead of attaching anything, the email links to the brief, the contract, or the campaign details on a file host or lookalike domain. The download is a RedLine or Lumma family stealer built to lift your browser cookies and Google session.

Info-stealer brief download link · last seen 2026-08-22

Surfshark partnership domains with extra words bolted on

A Surfshark deal sent from a domain that keeps the real brand name and adds a word like collab, media, partners, or team, such as surfshark-collabs.com or teamsurfshark.com.

Bolted-on-words lookalike domain · last seen 2026-08-21

Real-time 2FA interception pages that relay your login code

A phishing page sits between you and the real Google login, passing your password and one-time code to the attacker as you type them, so a code from SMS, an app, or a push does not stop the theft. It also copies the logged-in session so it can skip 2FA next time.

Adversary-in-the-middle 2FA phishing · last seen 2026-08-21

The move to Telegram

The email steers you off email and onto Telegram or WhatsApp before sharing any real terms, so the deal happens where there is no record and no company mailbox.

Move-to-Telegram handoff · last seen 2026-08-21

Punycode links that read as a real brand domain but are not

A link in the email displays as a familiar brand domain but is built from internationalized characters that encode, in punycode, to a completely different registered domain. The eye sees the brand; the browser goes somewhere else.

Punycode internationalized-domain link · last seen 2026-08-20

The password-protected archive with the password in the email

A fake sponsor attaches an encrypted .zip, .rar, or .7z and types the password right into the email. The encryption exists only to blind your mail scanner and antivirus so you unlock the stealer yourself.

Password-protected archive malware · last seen 2026-08-19

NordVPN typosquat domains that miss the real spelling by one key

A sponsorship offer that looks like it came from NordVPN but was sent from a domain one keystroke off the real nordvpn.com, such as nordvpm.com, norvpn.com, or nrodvpn.com.

One-keystroke typosquat domain · last seen 2026-08-19

The gift-card "processing fee"

A supposed sponsor asks you to buy retail gift cards and send the codes to cover an activation or processing fee. Gift-card codes clear instantly and cannot be recovered, and no real deal is paid this way.

Gift-card advance fee · last seen 2026-08-19

The countdown offer

The offer invents a deadline or a few remaining slots to rush you past the checks that would expose it.

Urgency and limited-slots pressure · last seen 2026-08-19

Fake DocuSign and contract portals that harvest Google logins

A supposed sponsor sends a sponsorship contract to sign through what looks like DocuSign or a branded contract portal. Opening it leads to a fake Google sign-in that captures your channel login.

Fake contract e-signature phishing · last seen 2026-08-18

The USDT payout offer

A cold sponsorship offer promises to pay you in USDT or another cryptocurrency, then either never pays or asks you to send a small fee first to release the money.

Crypto payout sponsorship offer · last seen 2026-08-18

Robinhood emails that hide the real sender behind the display name

A Robinhood-branded offer where the sender's display name reads like the brand or its real domain, but the actual address behind it is on an unrelated domain.

Display-name spoofing · last seen 2026-08-16

The brief.pdf that is really a .lnk shortcut

Inside the attached or downloaded folder sits a file that looks like a document but ends in .lnk, .js, or .vbs. Windows hides the real extension, so brief.pdf.lnk shows as brief.pdf and runs a hidden command when opened.

Shortcut or script disguised as a document · last seen 2026-08-15

The reply-to switch

The visible sender looks corporate while replies are quietly routed to a personal inbox, often through a manager or escrow middleman who handles the money.

Reply-to mismatch to personal inbox · last seen 2026-08-14

The activation fee that unlocks nothing

An offer that looks real adds a catch: pay a refundable registration or activation fee to onboard before the campaign starts. No real brand charges you to be paid, and the fee never comes back.

Advance activation fee · last seen 2026-08-14

Fake YouTube copyright-strike takedown notices

An email dressed up as a YouTube copyright warning tells you a video will be removed and your channel struck unless you dispute the claim right now. The dispute link leads to a fake Google sign-in page that steals your login.

Fake YouTube copyright-strike phishing · last seen 2026-08-14

The fake game beta build that ships as a raw .exe

The offer asks you to play and cover an unreleased build and attaches the client directly as an .exe or .scr. There is no game inside, only a loader that installs a stealer on the first double-click.

Fake game beta build executable · last seen 2026-08-12

The offer that is too big

A cold email dangles a flat fee far above your normal rate to switch off your skepticism before the real ask arrives.

Oversized offer bait · last seen 2026-08-12

Coinbase lookalike domains built from swapped characters

An offer or giveaway that appears to be from Coinbase but comes from a domain where letters are replaced with lookalike characters, like a zero standing in for the o in c0inbase, or a non-Latin letter that renders identically to a normal one.

Homoglyph lookalike-character domain · last seen 2026-08-12

OAuth consent screens that grant an app control of your channel

Instead of stealing your password, this scam gets you to approve a real Google consent screen that hands a malicious app ongoing access to your YouTube channel. The app usually poses as a creator marketplace or analytics tool.

Malicious OAuth channel-access grant · last seen 2026-08-09

SoFi emails that look corporate but route replies to a personal inbox

A SoFi-branded offer whose visible sender looks like a company domain, but the reply-to is quietly set to a personal Gmail or Outlook address so your answer never reaches the brand.

Corporate front with freemail reply-to · last seen 2026-08-09

The free beauty box that bills you monthly

A free beauty box needs only a few dollars of shipping, but the checkout enrolls you in a monthly subscription that keeps billing until you cancel. A genuine gifting deal never asks for your card.

Negative-option beauty box · last seen 2026-08-09

ExpressVPN offers sent from a Gmail or Outlook address

A pitch that says it is from ExpressVPN but arrives from a personal free webmail address, like expressvpn.partners@gmail.com or a random Outlook account.

Free-mail address claiming a big brand · last seen 2026-08-05

Pay to release your payout, in crypto

You are told a payout is waiting, but first you must send a verification fee in crypto to release it. Paying to receive money you are owed is an advance-fee scam, and crypto is chosen because it cannot be reversed.

Advance-fee payout release (crypto) · last seen 2026-08-05

Fake AdSense and YouTube payment-update pages

An email warns that your next payout is on hold until you update your AdSense or payment details, then sends you to a fake page that captures your Google login and sometimes your bank information.

Fake AdSense payout-update phishing · last seen 2026-08-05

The .iso attachment that mounts a hidden drive

A supposed game studio asks you to review a new title and attaches it as an .iso or .img disk image. Mounting the image and running the file inside slips the payload past the download warning Windows would normally show.

Disk-image (.iso) attachment smuggling · last seen 2026-08-05

HelloFresh offers from the right name on the wrong domain ending

A HelloFresh sponsorship email where the name is spelled correctly but the domain ends in .co, .net, or another suffix instead of the hellofresh.com the brand actually uses.

Wrong-TLD lookalike domain · last seen 2026-07-30

The media kit that is actually a program

A software or browser sponsor sends a media kit or brand-assets pack that ends in .exe or .scr with a document-looking name. A real media kit is a PDF or a folder of images, never something you run.

Fake media kit executable · last seen 2026-07-30

NDA before the terms

The sender demands you sign an NDA before sharing any terms, which discourages you from checking with other creators and can carry a malicious attachment.

NDA-before-terms pressure · last seen 2026-07-29

Fake monetization-suspension and channel-termination warnings

A message claims your channel has been demonetized or is about to be terminated for a Community Guidelines or Partner Program violation, and pushes you to an appeal form that harvests your Google login.

Fake YouTube suspension appeal phishing · last seen 2026-07-29

The "free product, just cover shipping" box

A supposed brand offers you free product but needs you to pay a small shipping charge on a checkout page that either pockets the fee or captures your card. Real gifting never costs the creator anything.

Cover-the-shipping fee harvest · last seen 2026-07-22

Fake brand-deal marketplace login pages

An email says a brand booked you through a creator marketplace like Aspire and links you to a login page to accept the deal. The page is a copy that steals your marketplace or Google credentials.

Fake creator-marketplace login phishing · last seen 2026-07-15

Prepay the tax to unlock your payment

The deal reads as legitimate until payday, when you are told to prepay a withholding tax to unlock your fee. Taxes are never prepaid to a sponsor to release a payment.

Tax-prepayment advance fee · last seen 2026-06-11

The refundable deposit for a review unit

A high-value review unit is offered if you put down a refundable security deposit to cover it. The unit never ships and the deposit is never returned.

Refundable-deposit advance fee · last seen 2026-05-30