A realistic brand-deal email can contain a polished contract, logo and payment terms while the attached 'brief' installs malware. TeamYouTube warned in 2025 that attackers disguise malicious files as contracts, media kits or proprietary software and may steal browser session cookies. A familiar sender name or a claimed urgent deadline is weak proof of legitimacy. The best check is an independent contact path to the actual brand.
Before you start
Do not open a downloaded executable or grant a browser extension access merely to review an offer. Keep the email, headers and attachment name if you may report it. A PDF or document file is not automatically safe either; verify the sender and avoid enabling macros or permissions you do not need.Do it step by step
- Inspect the full sender address and domain for lookalikes, not just the display name. Compare the offer with the brand's public site and previous campaigns. Treat a generic mailbox or misspelling as a reason to verify, not automatic proof of fraud.
- Contact the brand through a number or address from its own site or an established relationship. Ask whether that named person, campaign and attachment are real. Do not reply to the suspicious email to perform this verification.
- Read the requested actions before downloading. Reject demands to run .exe or .scr files, install a special viewer, disable security software or sign in through a non-Google page. A sponsorship agreement should not require a channel login token or a browser-cookie export.
- For a legitimate file, use an updated operating system and browser, scan downloads and open documents with normal protected-view features. Do not grant macros or administrator privileges to inspect marketing material.
- If you already ran the file, stop using that device for channel administration. From a clean device, review Google security activity and sessions, change credentials, inspect YouTube permissions and scan the affected machine professionally.
- Document the decision with the verified contact route and send the sender a limited response only after authenticity is established. Use YouTube's phishing or abuse reporting options for confirmed malicious material.