YouTube Creators Hit by Massive Wave of Account Hijacks: Report

The YouTube account hacks said to be the result of hackers use phishing emails to lure victims on fake Google login pages.

Advertisement
By Indo-Asian News Service | Updated: 25 September 2019 12:33 IST

YouTube creators, particularly in the auto-tuning and car review community, have become target of a massive wave of account hijacks, a media report said on Tuesday.

The account hacks are the result of a coordinated campaign where hackers use phishing emails to lure victims on fake Google login pages from where they collect users' account credentials, an investigation by ZDNet found.

Advertisement

Victims of the attacks that have hit the creator community over the weekend include several high-profile car reviewers, the report said.

A YouTube spokesperson, however, told IANS that it has "not seen evidence of an increase in hacking attempts over the weekend."

Advertisement

"We take account security very seriously and regularly notify users when we detect suspicious activity. We encourage users to enable two-factor authentication as part of Google's account Security Checkup, which decreases the risk of hacking. If a user has reason to believe their account was compromised, they can notify our team to secure the account and regain control," the YouTube spokesperson said in a statement.

Twitter, however, is flooded with complaints about missing channels from YouTube. Some users from India have also reported the atttacks.

Advertisement

"I am a subscriber & also a big fan of his work #Musafirakajoshi and Somebody hacked my brother Rahul joshi's YouTube channel #Musafirakajoshi @YouTubeIndia Please get in touch with him as soon as possible. @YouTubeIndia And bring his channel back as soon," wrote one Twitter user.

"The recent phishing attacks on YouTube are an escalation of a classic scheme, in which users are lured to fake login pages, where they enter legitimate credentials. Cybercriminals are always looking for the weakest link in the cybersecurity protecting valuable assets; in this case, it was users," Jonathan Knudsen, Senior Security Strategist at Synopsys Integrity Group, said in statement.

Advertisement

According to a YouTube video from Life of Palos uploaded over the weekend, hackers were capable of bypassing two-factor authentication on users' accounts.

Hackers targeting YouTubers might have used Modlishka, a reverse proxy-based phishing toolkit that can also intercept 2FA SMS codes, he suggested.

The best proactive defence against such attacks is education. With the right knowledge, many fewer users would have fallen victim to these attacks.

"While SMS 2-factor authentication is better than no second factor, this incident is still a reminder of its weaknesses which is why NIST stopped recommending its use back in 2016," said Bill Lummis, Technical Program Manager at HackerOne.

"It is important that the industry moves towards newer tools such as time-based One-time Password (TOTP), which recycles numbers every 30-90 seconds on a physical device, or Universal 2nd Factor (U2F), such as Yubikey, given that attacks like this will only become easier to execute over time," Lummis said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: YouTube, Google
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi Confirms the Redmi K90 Ultra Will Launch in China Soon
  2. 007 First Light Review: Licence to Thrill
  3. Tecno Spark 50 Pro Unveiled With Helio G100 Ultimate, Sony LYT-600 Camera
  4. Redmi Turbo 5 vs Motorola Edge 70 Pro vs Samsung Galaxy A37 5G Compared
  5. Athiradi OTT Release Date: When and Where to Watch it Online?
  6. Redmi Turbo 5 With 7,540mAh Battery Arrives in India at This Price
  7. Oppo Reno 16 Series Bags European Certification, Might Launch Globally Soon
  8. Lenovo Tab Plus Gen 2 Launched With JBL Speaker System
  9. Drishyam 3 OTT Release Date: When and Where to Watch Mohanlal's Crime Thriller Online?
  10. Samsung Galaxy Z Fold 8 Arrives on the US FCC Database With This Chipset
  1. Samsung Galaxy Z Fold 8 Listed on US FCC Database With Snapdragon Chipset
  2. Spotify Upgrades Collaborative Playlists Feature With Emoji-Based Reactions for Tracks
  3. Huawei Patent Document Describes 'Vertical' Trifold Smartphone With Two Hinges
  4. US Regulator Urges FDIC for Better Coordination on Crypto, Blockchain Risks
  5. Lenovo Tab Plus Gen 2 Launched With Dimensity 7400 SoC, JBL Speaker System: Price, Specifications
  6. Commodore Callback 8020 Flip Phone With Sailfish OS Unveiled as 'Digital Detox' Smartphone
  7. WhatsApp Said to Be Developing View-Once Text Messages Feature for iOS App
  8. Oppo Reno 16 Series Key Features Revealed via European Certifications Ahead of Global Debut
  9. Redmi Turbo 5 vs Motorola Edge 70 Pro vs Samsung Galaxy A37 5G: Price in India, Specifications Compared
  10. Pudgy Penguins to Discontinue 'Pudgy Party' Mobile Game in Favour of New Web Based Game
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.