The CyberSignal
  • Latest
  • Trending
  • Cyber Attacks
  • Data Breaches
  • Threat Intelligence
  • Critical Infrastructure
  • Policy & Government
  • Cybersecurity 101
  • Vulnerabilities
  • About Us
  • Weekly Briefing
  • Topics
Identity Theft

Fake YouTube Copyright Alerts Target Creators in Massive Account Hijacking Campaign

Nicholas Robert

Nicholas Robert

16 Apr 2026 — 2 min read
Share
A fishing hook stealing a key from a monitor on an emerald green background, representing the YouTube phishing scam.

A highly sophisticated phishing operation is utilizing hyper-personalized "copyright strike" warnings to bypass security instincts and seize full control of Google accounts and YouTube channels.

MOUNTAIN VIEW, CA — A new and alarmingly convincing phishing campaign is currently targeting YouTube creators, leveraging their greatest fear: the sudden loss of their channel. According to a technical analysis by Malwarebytes, attackers are sending fake copyright infringement notices that do more than just steal passwords — they facilitate a complete takeover of the victim’s Google ecosystem, including Gmail, Drive, and financial data.

The campaign, which operates from the domain dmca-notification[.]info, is noted for its unprecedented level of personalization. Unlike generic spam, these notices include the creator's real branding and specific video data, making the lure nearly indistinguishable from a legitimate YouTube communication.

Red Flag Protective Action
External Login Link Never sign in via an email link. Navigate directly to studio.youtube.com.
Unmovable Pop-up Try to drag the login window outside the browser. If it's stuck inside, it's fake.
Suspicious Domain Check the URL bar for dmca-notification[.]info or other non-Google domains.

The Architecture of the "Scare Page"

The attack begins with an email or message claiming a segment of the creator's latest video has been flagged. When the victim clicks the link, they are directed to a professional-looking "YouTube | Copyright strikes" portal.

The site dynamically pulls the target's actual channel data — including their profile picture, subscriber count, and most recent upload. To add a layer of forensic realism, the page even generates specific, fake timestamps for the alleged infringement based on the actual length of the creator's video. This level of detail makes the notice difficult for even tech-savvy users to dismiss.

The "Browser-in-the-Browser" Trap

The final stage of the theft occurs when the user clicks a "Login via Google" button to contest the strike. Instead of a new tab, the site generates a fake browser window inside the webpage. This window looks exactly like a standard Google sign-in prompt, complete with the correct fonts and UI elements.

However, every keystroke entered into this overlay is sent directly to an attacker-controlled backend server. Because the window is just a clever graphical element, traditional URL verification is bypassed. Once the credentials are harvested, the victim is silently redirected back to the notice page, often without realizing their account has already been compromised.


The CyberSignal Analysis

Signal 01 — The Professionalization of Phishing

This campaign represents the "professionalization" of social engineering. By moving away from bulk spam toward high-detail, data-driven impersonation, threat actors are successfully targeting high-value individuals like influencers and digital entrepreneurs. The "Signal" here is that public data (subscriber counts, handles, video lengths) is now being weaponized in real-time to build trust.

Signal 02 — The Death of the "Visual Check"

For years, users were taught to look for the "Google Sign-In" UI as a mark of safety. The use of the "Browser-in-the-Browser" (BitB) technique renders visual checks obsolete. Creators must pivot to a zero-trust navigation model: never sign in via a link provided in an alert. If a copyright strike is real, it will only appear within the official YouTube Studio dashboard.


Sources

Type Source
Technical Intel Malwarebytes: Technical Analysis of Copyright Phishing
Threat News Security Boulevard: YouTube Creator Alert

Read more

Flat vector illustration of a shielded AI core with a single flat red dot, representing GPT-6 Astra's blocked exploit output.

OpenAI Unveils GPT-6 Astra, Its First 'Critical' Cyber Model to Hit 100% on ExploitBench

OpenAI formally launched GPT-6 Astra, calling it the world's most intelligent and aligned model. It is the first to reach the Critical cyber tier of OpenAI's Preparedness Framework and scored 100% on ExploitBench, yet the shipped version refuses to write proof-of-concept exploits.

04 Sep 2026
Nvidia and Hugging Face logos over a stylized AI model-hub network, marking the $13 billion acquisition.

Nvidia to Buy Hugging Face for $13 Billion: What It Means for the AI Supply Chain

Nvidia is buying Hugging Face, the open-source model and dataset hub, for about $13 billion, with the deal set to close as early as 2027. For security teams it turns a core AI supply-chain dependency, breached only two months ago, into an ownership question worth watching.

04 Sep 2026
Flat white line-art of a data-center network switch with two exposed ports on a deep cyber-navy background, marked by a single flat red dot.

Cisco Nexus 9000 Flaw CVE-2026-20212 (CVSS 9.8) Lets Unauthenticated Attackers Run Code as Root

Cisco disclosed CVE-2026-20212, a CVSS 9.8 flaw that lets an unauthenticated remote attacker run code as root on 10 Silicon One-based Nexus 9000 switches, and shipped an IOS XR hardening release bundling seven CVEs, two rated 9.8, with no workaround for any version.

04 Sep 2026
The Top CVEs of August 2026: Attackers Cashed In on Patches Defenders Already Had

The Top CVEs of August 2026: Attackers Cashed In on Patches Defenders Already Had

August 2026 produced only two true zero-days. Almost everything else CISA flagged as under attack had been patched weeks or months earlier — the month attackers spent cashing in on fixes defenders already had.

04 Sep 2026
The CyberSignal
  • Daily Briefing
  • Weekly Briefing
  • Corrections
  • Privacy Policy
Powered by Ghost