

In the photo, a representative element of the story.
YouTube isn't scamming users; it's quite the opposite. A phishing campaign is targeting creators, businesses, and channel owners, exploiting fake copyright claims, pages that mimic official tools, and even legitimate redirection services linked to YouTube and Google.
Cyber attacks against YouTube channels are becoming increasingly credible and sophisticated. They're no longer limited to poorly written emails or obviously fake pages: today, those attempting to steal an account can construct a path that combines authentic services, professional graphics, and fake security procedures.
This is what we have verified directly in the last few hours through an email that simulated a copyright infringement complaint.
The message did not come from YouTube.
The email was sent by:
Quentin Carmichael
We decided to make the address used in the attack public because it is a concrete element of the phishing campaign we received. It remains possible, of course, that the email address was created specifically, compromised, or used fraudulently; it's impossible to determine this with certainty from the sender address displayed alone.
The point to clarify immediately is fundamental: YouTube is the indirect target of the attack together with its users, not the author of the scam.
Criminals seek to exploit the trust that creators, newspapers, companies, and professionals place in the platform.
The mechanism is simple but well constructed:
false copyright complaint → fear of losing the channel → appeal page → false Google login → possible account theft.
And it is precisely the fear of receiving a strike or losing monetization that makes this type of attack effective.
The message received had the following subject:
“Someone submitted a request about your shared content” , or “Someone has submitted a request about the content you shared”.
In the text, the sender claimed to be working with a company for an alleged report related to the channel.
It was explained that some tools would detect:
“republished segments that demonstrate unauthorized mass duplication of media content.”
Then comes the typical phishing step: urgency.
The recipient is urged to investigate the matter immediately, with the threat of possible consequences on the channel if they do not take action within a few hours or within the next day.
The psychological pressure is clear: someone managing an important channel might click without carrying out further checks.
What makes this attack particularly interesting is the link included in the email.
An unknown domain is not shown immediately.
The link uses a structure similar to this:
https://www.youtube.com/redirect?q=share.google/XXXXXXXXXXXXXXX
We have intentionally obscured the final characters, replacing them with Xs , to prevent the link from being traced directly back to the targeted channel.
The first part, however, is actually linked to youtube.com, the service that allows sharing a link via YouTube, which is completely legal and official. This attack therefore manages to convey the attempt using truly original tools.
And this is where the deception arises.
A person accustomed to quickly checking links might see the YouTube domain and assume the message is authentic.
In reality, the link simply serves to take the user elsewhere.
After the YouTube redirect, an address like this appears:
share.google/XXXXXXXXXXXXXXX
In this case, too, we've obscured the final part. This part, too, can be traced back to Google, and like YouTube, it's a component used to share links using Google's service. Once again, the attack appears real.
The fact that real services linked to Google and YouTube appear along the way makes the scam much more credible.
But it is necessary to distinguish one fundamental thing:
Using a legitimate service as an intermediate step does not mean that Google or YouTube are involved in the attack.
It is the scammer who uses legitimate tools to give greater credibility to the process.
And this is precisely the most dangerous characteristic of this type of phishing.
Once the redirects are passed, the user is taken to a page that simulates a channel check.
The graphics show alleged problems such as:
A button like this also appears:
“Proceed to Appeal”
or “Proceed with the appeal”.
The page is designed to appear credible to those who use YouTube on a daily basis.
There are references to DMCA, Content ID, monetization, and channel status.
But all this does not belong to the official YouTube panel.
After clicking the appeal button, a second screen appears.
A supposed Channel Dashboard is displayed , with fabricated information relating to:
To see all the details you are asked to press:
“Sign in with Google”.
This is where the scam can become truly dangerous. There's no going back. And this is precisely where the attack reveals its true nature. If it were a genuine Google service, you'd likely be already logged in and wouldn't need to sign in, or your login details would already be available. However, since it's a fraudulent system, it requires reauthorization, and so it's at this stage that it steals your data and uses it to "steal" your channel, or worse, your Google account.
If the user enters their Google credentials on a page controlled by a third party, they can deliver their username and password to the attackers.
In the case of an account linked to YouTube, the consequences can be very serious.
An attacker might try to gain access:
In the case analyzed, the path finally led to this domain:
https://dmca-confirmation.xxx/ ( xxx non è reale per evitare che qualcuno possa cliccare sul sito malevolo)
and pages like:
https://dmca-confirmation.xxx/appeal/ ( xxx non è reale per evitare che qualcuno possa cliccare sul sito malevolo)
This is the domain that hosted the fake procedure.
The attack chain can therefore be summarized as follows:
Phishing email → YouTube redirect → Google service → external site → fake copyright procedure → fake Google login.
It's a particularly effective structure because the first steps can seem completely legitimate.
This story demonstrates an important principle.
Just checking the beginning of a web address is no longer enough.
A link can start from:
youtube.com
and end up on a completely different site.
The same can happen using sharing or redirection systems belonging to well-known services.
Control must therefore focus on the final destination.
And it's important to know that both Google and YouTube are victims of the scam and are not responsible for this type of attack. Both the attacked YouTuber and both services are the injured parties.
In our case, no credentials were entered.
The message was reported as phishing and the site was reported to the relevant authorities.
The matter was also brought to the attention of the authorities.
What is worrying is the increasing quality of these campaigns.
We're no longer necessarily talking about emails full of gross errors.
Today a phishing attempt can have:
We have no evidence to suggest that this specific attack was carried out using artificial intelligence tools.
It is clear, however, that AI can significantly reduce the effort required to create credible phishing campaigns, precisely because it can suggest using legitimate and official services inappropriately.
It can be used to produce better text, more natural translations, compelling graphical interfaces, and code to replicate the look and feel of popular platforms.
This means that even the least technically sophisticated scam attempts can increasingly appear more professional.
The main rule is very simple:
Never verify a copyright strike from a link received in a suspicious email. Furthermore, if there is a report, it always comes from official YouTube or Google accounts, which usually have a blue checkmark in your inbox. You can also check your YouTube dashboard for any ongoing issues.
If you receive a message about a violation, strike, monetization suspension, or channel termination, it's best to close the email and go directly to YouTube Studio.
Not through the link received.
By opening the official website independently.
If the dispute is genuine, you can verify it directly from the official tools linked to your account.
This is not a “YouTube” scam.
This is a scam against YouTube users.
Against creators, companies, publishers, and channel managers who may have years of content, thousands of subscribers, and a business built around the platform.
And it is precisely this value that makes the accounts attractive.
The more important a channel, the greater the psychological pressure generated by a false communication announcing a strike, copyright issues, or suspensions.
The lesson from this story is simple:
Even when the first link seems to belong to a known service, you should always check where it actually leads.
Because phishing today isn't just trying to imitate YouTube.
It may attempt to exploit the same legitimate tools as YouTube and Google to target users who trust those platforms.
Luckily, this particular incident had a positive outcome: the YouTuber who reported the incident to us understood in time that it was a scam attempt and immediately blocked the whole thing.
Among boats, alleys, and nets spread out in the sun, Cetara showcases the cuisine of the Amalfi Coast.… Read more
Naples - The alleys of the Spanish Quarter continue to be the scene of a police offensive... Read more
Public competition for one full-time, permanent accounting officer position at the Municipality… Read more
The Carabinieri of the Nola Operations Section arrested Federico Manzi, 27, from Pago… Read more
Secondigliano stopped, motionless and racked by pain. No sound of engines, no activity... Read more
Naples awoke on September 27, 1943, amidst improvised barricades and street battles: a… Read more