---
title: 'YouTube Hackers Tried to Steal My Channel! Here''s How I Caught Them'
source: 'https://youtube.com/watch?v=gVvhDS5td4Y'
video_id: 'gVvhDS5td4Y'
date: 2026-08-04
duration_sec: 1083
---

# YouTube Hackers Tried to Steal My Channel! Here's How I Caught Them

> Source: [YouTube Hackers Tried to Steal My Channel! Here's How I Caught Them](https://youtube.com/watch?v=gVvhDS5td4Y)

## Summary

In this video, the creator shares a detailed account of a phishing scam targeting YouTube creators, where hackers attempted to steal his channel by impersonating a brand (MSI) and sending malicious links. He breaks down the red flags he identified, including domain age, registrar location, and grammatical errors, and provides actionable advice on how to avoid falling for such scams.

### Key Points

- **Initial Contact via DMs** [00:42] — Scammers often reach out via Twitter/X DMs, but legitimate brands typically use business inquiry emails. The creator notes that 99.99999% of the time, brands don't initiate contact through DMs.
- **The MSI Offer** [01:13] — The scammer claimed to be from MSI, offering a laptop for promotional services in a YouTube video. They provided a list of deliverables, including highlighting key specifications.
- **Grammatical Errors as Red Flag** [02:21] — The email contained grammatical errors, which is a common sign of phishing. The creator emphasizes that legitimate companies usually have polished communications.
- **Docusign Link** [04:51] — The scammer sent a link to a fake Docusign page to sign a contract. The creator notes that the link was not from the real Docusign, and clicking it could lead to credential theft.
- **Two Main Scam Methods** [06:15] — Scammers primarily use two methods: getting people to click on malicious links or sending PDFs that contain malware. The creator advises against both.
- **Fake LinkedIn Page** [07:37] — The scammer had a LinkedIn page that looked legitimate, but the account was created in January 2020 and had no activity for over a year, suggesting it was bought or hacked.
- **Domain Age Check** [09:18] — The domain for the fake Docusign site was registered on March 18, 2025, just a week before the scammer reached out on March 25, 2025. This is a major red flag.
- **Registrar Location** [10:02] — The domain registrar was located in Russia, and the hosting servers were also in high-risk locations like Russia and Latvia, further indicating a scam.
- **Search for Scam Alerts** [11:16] — The creator advises searching for the company name and the scammer's contact to see if others have reported similar phishing attempts. He found warnings about the same company.
- **YouTube Impersonation Scam** [12:29] — Another scam involves emails that appear to come from YouTube, with the subject line indicating a private video shared with you. Clicking the link leads to a fake login page.
- **Fake YouTube Creators Channel** [13:24] — The scam email includes a video from a channel impersonating YouTube Creators, with the CEO's face, but the channel is not official. They ask you to open a document to verify your account.
- **Credential Theft** [14:16] — If you fall for it, the scammers gain access to your Creator Studio, change your password, and take control of your channel, often starting scam live streams.
- **Prevention Tips** [16:21] — Never click links in unsolicited emails. Use Docusign or Adobe Sign for contracts, and if unsure, create your own account and ask for the text to be sent there. Always verify the sender's identity.

### Conclusion

The video serves as a cautionary tale, emphasizing the importance of vigilance against phishing scams targeting content creators. By checking domain age, registrar location, and searching for scam alerts, creators can protect their channels and personal information.

## Transcript

all across the globe, and they almost got me. and it's just a devastating experience and you just don't have all of your YouTube stuff anymore,
through the channels that they hack, So by the time you're finished with this video, when it comes to people reaching out to you for anything
And you're gonna know about some really sneaky things So grab your notepad if you have one (static crackling)
that tried to get me through Twitter, or X, DMs. is because brands typically don't reach out via DMs So, for example, if I tweet at somebody,
then, in that case, they might reach back out, but 99.99999% of the time, which is why we have those business inquiry email addresses
I'm reaching out on behalf of MSI Would you be interested in discussing this further: Two is that they're reaching out from a company
And that contact was through a creator friend of mine, if they wanted to reach out for something. But just in case, and to entertain this conversation,
but since I live in Thailand, it made it challenging. and a Thai distributor ghosted me. and I am sharing that with them
But then they said, "Nice to meet you. Therefore, we will be able to easily deliver I'd like to introduce you to a collaboration offer with MSI
"Through this partnership, you will receive the laptop for your promotional services. at one of your upcoming YouTube videos."
is grammatical errors when you are reading through emails But they continued to say, "The advertising integration
You will have three months from the date So typically when it comes to things like this, and then it'll usually be within a 30-day window or less.
if they're doing some type of campaign, when it comes to this sort of thing. But they gave me a list of the deliverables, which are:
highlighting its key specifications. Now I'm gonna pause right here, of nothing else is gonna happen
In terms of they're not letting me know anything else or something like that, then it's like, okay, well, maybe. to where they're not gonna give me
But they continue to say that "The laptop during the integration to ensure its features Beyond these core requirements,
in a way that feels authentic to your content style. regarding the compensation, timeline, or requirements, Please let me know if you're interested in the offer,
in terms of "Here's what we have going on. that they're not gonna let me know anything about the laptop I could make a video about editing
How does that sound?" that you take the time to review the details you can proceed with signing the contract."
I'll arrange the shipment of the laptop to you In this chat, we will be available to assist you I will now send a request to our legal department
regarding the promotional integration." I didn't really give a proposal at all. (laughs) And then, you know, I can do it in this way."
coming from me in any way, shape, or form. They followed up with, "Hello, And then I did reply, and I said, "That sounds good to me."
and the red flags just start falling from the sky. in the corporate Docusign fast application. not put that link here because I don't want anybody
I'm gonna blur it out. to gain access to the contract, as a partner of our company."
Then they say, "Once on the site, After clicking "Edit Offline," of the contract in the Docusign application.
that I didn't want you to see, it's not from Docusign; And I'm gonna tell you how all of that came together and let me know if you are ready to sign the contract."
and it was crystal clear to me So I decided, for the sake of making this video, and just see how far we can go with this.
I don't click on links out of DMs. If you don't have a Docusign account, Their reply: "Of course, I understand.
to prepare the contract for you in a PDF format. So there's two main ways One is getting people to click on links,
Two is by sending you PDFs. then they also put something into your computer, So for fun, I replied with,
Then we can do a Docusign; no need for a PDF. and send it over once we agree on the terms. And from there, I haven't heard back since.
but no reply, of course. is, in addition to not replying back to me, before making this video, and now their posts are protected.
now the posts are protected to where, for whatever reason, you can't see their posts anymore. and how easy it can be to fall for this sort of thing.
it has a LinkedIn page on it. it looks like it might be legitimate. which they don't.
So they bought a bunch of followers for their X account. that almost makes them look legitimate. But there's one place where this clearly falls apart.
when one of those hackers watches this video, so you're gonna have to be extra vigilant about this. and you go to their LinkedIn account,
is I'm looking at the hover. and I see here that it does say that it is LinkedIn.
and it looks like it might be legitimate, because if we go to the account creation, then we see that in over a year, but they joined back in January of 2020.
and I'm not sure if they actually hacked this particular account or if they buy them somewhere online,
But when you looked at it initially, and it seemed like it was legitimate. And we see that eight months ago, you know,
So this side of it looked legitimate, they worked with and that sort of thing. the URL from the supposed Docusign
and then I hit search. you can see information about the website. for when they got this domain name
is March 18th of 2025. Now, they reached out to me on March 25th of 2025. So this right here is the biggest red flag
but this particular one is the "I gotcha" moment this particular person as a scammer. is right here, if you look at the registrar URL,
So if we go here, then we can see that this is a place However, if we look this up, that some of them are in Russia.
So because of that, that's just another red flag, at least it was for me, because there are a lot of hackers, that are operating out of Russia.
then we can also see here that they say that internet service provider. But then if we come down here which point to servers hosting in high-risk services,
we can see that Russia is dominating, and then Latvia, and then 1% in the United States. you know, company itself is shady or anything like that,
it can really start to paint a nice picture for you is when you do get shady things like that, if this is legit or not."
and then you can paste the actual link You don't wanna put it up in the address bar and then you put the website name there,
with the one that they reached out to me with, also put out a warning about this particular company. saying, "Hey, there's like this phishing scam going on here
And you start to see all of these things Same exact thing here where we have Pirate PR, or pr_pirate, And they have the same person that reached out to me
of the same exact thing and essentially the same information to look for these types of things as well,
about those companies, to where it might show you a scam with AI and everything; But this is just a lead on things that you can do
Now, let's talk about another scam because it's coming directly from YouTube. however, it's not.
in your subject line of your email, what you're gonna see Now, in this particular case, you can see that 13 hours ago, and then they sent me another one two hours ago as well.
this is gonna be different for everyone that they're doing, but basically what happens is this comes from YouTube. that this is directly from YouTube, so it looks legit.
"Like, I wonder what's going on there." because all of those quick checks that you do so it seems like it's real.
But what happens is when you click on this particular video, which is YouTube's CEO, and the channel is YouTube Creators,
so you know it's not legitimate there. what they're doing is they're trying to get you So here it's saying, "Before proceeding,
So the reason they want you to do this that you are logged into your Creator Studio So because of that,
And then as they are going through this, please open the document," so on and so forth, And they want you to click on this document.
then that gives them everything that they need. in order to take full control of your YouTube channel. it happens so quickly
they've already changed your password, and they've already got a live stream that is either running where they are gonna start scamming people.
and it's the CEO of YouTube here, YouTube does not send these out. that a private video is shared with you,
Unless, let's say that you have and they send you videos for feedback that it's coming from that particular channel.
And you can do that by looking in this area right here Now, again, in this particular case, and they know that it seems trustworthy for people.
But in your case, if you ever get one of these emails, unless you're expecting somebody to send you something. these are still gonna be coming your way.
that it is from a channel that you already know you wanna make sure, in that case, They're not doing this yet,
is you see what this looks like here? So as they're sending these out, you know, you look up here so it must be legit."
to start sending out emails as well to where it looks like this, but it's not from YouTube. to where they're gonna try to trick people that way.
just remotely even looks like this, So make sure that you never click on links. but they're getting savvy there,
So you just gotta be super careful there. Docusign is legitimate. If they reach out to you tell them, "Hey, just drop the text here
and just put all the texts in the email." Never accept a PDF unless it is from a person as a legitimate person
make sure that you are looking into that person and that you just try to run everything, either Docusign or Adobe's signing tool that they have
don't want to do that, then make an account yourself and tell them to send you the text, put it in a Docusign, Then that way you're creating these walls and these barriers
and get access to your YouTube channel. because they are coming for you. and you're trying to take things to the next level,
I'm gonna put a link it right here; go and watch that video. how you can get people watching longer, and I will see you over there.
I'll see you next time.
