A fake brand deal email is a sponsorship offer that borrows a real company's name to get you to run a malware “brief”, sign in on a fake contract portal, pay a joining fee or refund an overpayment. Treat every unexpected offer as unverified until you have found the brand's contact details yourself and confirmed the person works there, matched the sender's domain to the brand's real one, refused any file you would have to unzip with a password or install, and confirmed that money only ever flows from the brand to you.
How sponsorship scams are put together
The best-documented version targets the business email address creators publish for partnership enquiries. In its write-up of a long-running campaign, Google's Threat Analysis Group describes forged emails that impersonated existing companies and proposed a paid video collaboration, typically for antivirus, VPN, music, photo-editing or game software. Once the creator agreed, the scammers sent a download link, by email or inside a PDF on a cloud drive, that installed cookie-stealing malware, then hijacked the channel to sell it or stream crypto scams. The same post reports that the group identified at least 1,011 domains registered solely for this campaign.
Four patterns recur in creator inboxes:
- The malware brief: a product demo, campaign deck or “tracking tool” you are asked to download and run before filming.
- The fake portal: a link to view or sign the contract that first asks you to log in with your email, Instagram, TikTok or Google account.
- The pay-to-join offer: a fee for onboarding, an ambassador starter kit, shipping, or buying the product yourself on a promise of reimbursement.
- The overpayment: a cheque or transfer for more than the agreed fee, followed by a request to send the difference to a “producer” or back to the brand.
Offer verification checklist
Run these checks in order before replying with anything other than a holding message. The first two take minutes and need nothing but a browser.
- Contact the brand through a channel you found yourself. Scamwatch's phishing guidance says to verify a message by contacting the organisation with details you located on its official website, never the details in the message. Ask the company's published press, partnerships or general address whether the sender works there and whether the campaign exists.
- Read the sender's domain character by character. Compare it with the domain on the brand's real website. Lookalikes add a word such as “partners” or “media”, swap a letter, add a hyphen or use a different ending. A large brand writing from a free webmail account is a warning sign on its own.
- Check when the domain was registered. Registration data from ICANN Lookup can show when a domain was created; an “established” company emailing from a domain created recently deserves suspicion.
- Search the exact wording. Paste distinctive sentences from the email, the sender address and the company name into a search engine with the word scam, as Scamwatch also suggests.
- Ask for the brief in the email body. A real marketer can paste the deliverables, timeline and fee into a reply. Refuse anything you must install, or open with a password, to read.
- Never sign in through a link in the offer. If a contract or dashboard needs a login, open the app or website you already use by typing the address yourself.
- Confirm that no money flows from you. No application fee, shipping fee, product purchase, verification charge or refund of an overpayment.
- Keep account access to yourself. A brand never needs your password, login codes or an admin role on your channel to sponsor a post.
- Get the terms in a written contract from an identifiable company. Our influencer contract template shows what a complete sponsorship agreement contains, which makes a vague one easier to spot.
File-type red flags
YouTube's Secure your YouTube channel page names fake sponsorship and brand deal emails as a malware source and says malware usually arrives as password-protected, zipped files ending in .scr or .exe. Google's threat researchers add that encrypted archives often bypass antivirus scans, which is exactly why scammers lock them.
| What arrives | Why it is risky | What to ask for instead |
|---|---|---|
| An .exe, .scr, .msi or other installer for the “product demo” | It runs code on your computer with your permissions | The product's public store or website listing, which you open yourself |
| A password-protected zip or rar archive sent “for confidentiality” | Encryption can stop security software from scanning the contents | The brief pasted into the email or shared as a plain document |
| A PDF or cloud document whose main content is a download button | The danger is the linked page, not the document itself | A brief that contains the deliverables in its own text |
| A contract that opens only after you sign in with a social or email account | Classic credential harvesting for account takeover | An attached contract, or an e-signature request from a service whose site you navigate to directly |
| A document that asks you to enable editing, macros or extra content first | Those prompts can let a malicious document start running code | A preview you can read without changing any security setting |
| A browser extension or screen recorder to “track campaign performance” | It can read pages you are signed in to | Reporting from the platform's own insights, shared as screenshots |
If you genuinely need to inspect a file, Google's researchers recommend scanning it first with antivirus software or an online scanner and taking browser safety warnings seriously rather than clicking past them.
Payment-first and overpayment tells
The FTC's advice on job scams is blunt: honest employers will never ask you to pay to get a job, and anyone who does is a scammer. The same logic applies to sponsorship. Its page on fake check scams explains the overpayment trick: banks must make deposited funds available quickly, but a fake cheque can take weeks to be discovered, by which time the money you forwarded is gone and you owe the bank.
- A fee to be considered, onboarded, listed, trained or verified as an ambassador.
- A request to buy the product at a “creator discount” with reimbursement promised after the post.
- Shipping or customs charges for a gifted item.
- Payment arriving before any contract, especially for more than the agreed amount, with a request to pass some of it on.
- Any request to pay or refund using gift cards, cryptocurrency or wire services; the FTC says anyone demanding payment by gift card is always a scammer.
- A small genuine-looking payment first, then a request for bank logins or card details for the “main contract”.
Real sponsorships pay the creator on terms written into the contract, such as a deposit with the balance after delivery. What normal looks like is set out in how influencers get paid for brand deals.
If you opened the file or typed your password
Speed matters, and so does order. Google's researchers describe cookie theft as session hijacking: the malware copies the signed-in sessions stored in your browser, and they suggest its resurgence may be linked to wider use of multi-factor authentication. Changing a password alone may not end a stolen session, so signing out other sessions is part of the fix.
- Stop using the affected computer for logins and take it offline until it is cleaned.
- From a different device you trust, change the password on your main email account first, then on each creator platform, and use each account's security settings to sign out every other session.
- Turn on 2-Step Verification; YouTube's security page recommends a passkey as the strongest protection against phishing.
- Check recovery emails and phone numbers, connected apps, manager or admin roles, and payout details on every account for changes you did not make.
- Clean the device. The FTC's phishing guidance says to update your security software and run a scan; the NCSC's infected device steps add that for phones and tablets the safest solution is a factory reset, and that a computer your antivirus cannot clean needs wiping and reinstalling, with data restored from your last known good backup.
- If you shared card or bank details, call your bank immediately and ask it to stop transactions.
- Follow the platform recovery routes in our Instagram hacked account checklist or OnlyFans hacked account steps if an account was taken over.
- Tell the impersonated brand through its official channels, and warn your audience if your account posted anything while compromised.
Where to report, by country
| Where you live | Report the scam | Recovery help |
|---|---|---|
| Australia | Scamwatch, plus ReportCyber at cyber.gov.au for account compromise | IDCARE on 1800 595 160, as listed in Scamwatch's what to do if you've been scammed page |
| United States | The FTC at ReportFraud.ftc.gov | IdentityTheft.gov if personal or financial details were taken, per the FTC phishing page |
| United Kingdom | Forward the email to report@phishing.gov.uk, the address on the NCSC's report a scam email page | Report Fraud on 0300 123 2040 in England, Wales and Northern Ireland, or Police Scotland on 101, per the same page |
Also report the sender inside the platform where the approach started. TikTok's frauds and scams page advises checking anything doubtful against an official, verified source, such as the brand's website reached through a search engine, rather than a link you were sent.
What a genuine first contact tends to include
Legitimate outreach is not always polished, but it is checkable. Expect a named person whose role you can confirm, a company domain that matches the brand's website, a brief you can read without downloading anything, deliverables and a fee or budget range, and a contract from an identifiable business. When a brand finds you through a platform marketplace, keeping the conversation inside that tool gives you a verified channel; see our guides to Instagram Creator Marketplace and TikTok Creator Marketplace.
Adult-platform creators should check offers that reach their public persona with extra care; the category and disclosure checks in brand deals for OnlyFans creators help separate a real but unsuitable offer from a fake one. Scams that impersonate management agencies rather than brands are covered in OnlyFans agency scams and red flags.
Limits of this checklist
Scam scripts change faster than any checklist, and a convincing impersonation can pass several of these tests, particularly when a real brand employee's mailbox has been compromised. The checks lower your risk; they cannot certify that an offer is safe. Reporting numbers and services named here were correct on the official pages checked on 1 October 2026 and can change.
This is general information, not security or legal advice. If a business account holding income or client data was compromised, or money was lost, involve your bank, the relevant reporting agency and, where needed, an IT security professional rather than relying on self-help steps alone.