← Back
Category 14: Channel Security, Account Safety, Phishing & Hack Prevention

Fake media kits or campaign briefs contain links to malicious cloud documents.

Problem

Fake media kits or campaign briefs contain links to malicious cloud documents.

Solution

Root Cause / Diagnostic:
Threat actors masquerade as prospective sponsors sharing campaign briefs or creative assets hosted on cloud platforms (e.g., fake OneDrive, Google Drive, or Dropbox pages). Opening the document displays a simulated error message ("File encrypted - authenticate to view") that harvests creator login credentials.

Actionable Fix:
1. Native Cloud Preview Inspection: View all shared cloud documents strictly within the native cloud provider's preview mode; never enter credentials to "unlock" a viewed document.
2. URL Redirection Inspection: Inspect cloud document share links using security analysis tools (e.g., URLScan.io) to detect intermediate phishing redirects before clicking.
3. Dedicated Untrusted Media Machine: Mandate that prospective sponsor briefs and external campaign materials are reviewed on an isolated, non-production device.

Pro Tip:
A real brand agreement or media kit is just a plain PDF. If opening a sponsor's document pops up a window asking you to log into Google or Microsoft to view the file, close it immediately—it's a credential trap.