How it works

This one is sneaky because the login is real. You click a link in an email offering a brand deal, an analytics dashboard, or an invite from a platform like GRIN, and you land on a genuine Google consent screen. The catch is the app requesting access. It asks for permission to manage your YouTube account or your Google data, and the app name is set to look like a legitimate tool. If you click Allow, Google issues the app a token, and from then on the attacker can act on your channel without your password and without tripping your 2FA, because you authorized it. Changing your password does not revoke it. The access lasts until you remove the app yourself.

Because the consent screen itself is hosted by Google, the usual "check the address bar" advice does not catch this. What catches it is reading the screen: which app is asking, what it wants, and whether you actually started this.

The tell-tale signals

What to do

Approve a Google consent screen only for an app you deliberately went to connect, and read exactly what it asks for before you click Allow. To see and remove apps that already have access, open your Google account permissions page at the third-party access section and revoke anything you do not recognize, then check YouTube Studio under Settings and Permissions for added users. If a marketplace deal is real, start from the platform you already use, not from an email link. Because this route bypasses passwords and 2FA, a passkey will not stop a grant you approve yourself, so the guard here is caution at the Allow button. LegitSponsor can assess the sender and link evidence on the original email before you reach the consent screen.