← Back
Category 14: Channel Security, Account Safety, Phishing & Hack Prevention

Attackers use leaked creator schedules to time phishing messages during periods when the normal security approver is absent.

Problem

Attackers use leaked creator schedules to time phishing messages during periods when the normal security approver is absent.

Solution

Root Cause / Diagnostic:
Leaked creator production schedules, shared Google Calendars with permissive visibility, or publicly visible streaming schedules reveal exactly when the creator is engaged in demanding on-camera productions. Attackers leverage these scheduled production windows to execute password resets, dispatch spear-phishing lures, or submit fraudulent ownership requests. Because the primary decision-makers are busy on set, the attack progresses uninhibited through its critical execution phase.

Actionable Fix:
1. Lock down all internal production calendars, setting Google Calendar sharing permissions strictly to "See only free/busy" for general staff and completely private to outside domains.
2. Implement an automated "Production Lockdown" mode where critical account setting changes are administratively blocked during scheduled live shoots and broadcast days.
3. Train studio floor managers and assistants to immediately escalate any security notifications that arrive while the creator is on set rather than waiting for wrap.

Pro Tip:
Maintain an air-gapped emergency alerting mechanism (such as a physical red beacon or dedicated offline pager) on the production soundstage so studio security can notify the creator instantly during a live shoot.