← Back
Category 14: Channel Security, Account Safety, Phishing & Hack Prevention

An attacker impersonates a creator's talent manager and asks for a verification code during an active sponsorship negotiation.

Problem

An attacker impersonates a creator's talent manager and asks for a verification code during an active sponsorship negotiation.

Solution

Root Cause / Diagnostic:
Threat actors compromise or spoof the email account of a talent manager or agency partner to execute a secondary account takeover. While negotiating a high-value sponsorship, the attacker initiates an account recovery or password reset on the creator's Google account and requests the resulting 2-Step Verification SMS/prompt code under the guise of an agency verification check.

Actionable Fix:
1. Out-of-Band Multi-Channel Verification: Require out-of-band voice or video call confirmation (via phone or Signal) whenever an agency, manager, or partner requests any security confirmation or administrative action.
2. Hardware Token Enforcement: Migrate the Google account to FIDO2 security keys and disable SMS/prompt-based 2-step verification, eliminating interceptable 6-digit codes entirely.
3. Verification Code Secrecy Policy: Establish an unbreakable policy that one-time passwords (OTPs) and 2FA prompts are never shared with anyone under any circumstances, including management.

Pro Tip:
Never give a Google verification code to your manager, agency, or sponsor over email or chat; legitimate talent managers never need your login codes, and sharing that code lets hackers take over your channel.