How it works
This version carries no attachment and no download. The email invites you to "connect your channel," "verify your analytics," or "log in to our creator dashboard" to unlock the sponsorship, and links to a page that does one of two things. Some pages copy Google's sign-in screen and forward whatever you type, including the 2FA code, in real time. Others run a real but attacker-controlled app through Google's genuine consent flow and ask you to approve broad permissions on your account.
Either way the attacker ends up with access to read and manage your YouTube channel. When it is a granted OAuth token, there is no download for antivirus to catch, and 2FA does not help, because you approved the grant yourself. The lure often claims to be a software sponsor's portal, such as an Opera GX creator dashboard, to make the login request feel expected.
The tell-tale signals
- You are asked to log in or "authorize" access to start the deal
- The login page is not on accounts.google.com
- The visible link text and the real destination are different domains
- A shortener or a punycode lookalike hides the true URL
- Urgency to connect before the offer expires
What to do
Never sign into Google or grant account access to begin a sponsorship. No real brand needs OAuth permission to your channel in order to pay you. Reach the sponsor through the contact on their official site instead, which for Opera GX is opera.com. Review which apps have access at your Google account security page and remove anything unfamiliar. If you approved a grant or entered your login, revoke the app access, sign out of all sessions, and change your password from a clean device right away.