How YouTubers Are Getting Hacked

preview_player
Показать описание

▼ Time Stamps: ▼
0:00 - Intro
0:32 - The Scam Streams
3:32 - A Good Thing Indeed
5:27 - Speaking Of Google & YouTube
7:23 - The Malware
8:58 - Fake Sponsorships
9:55 - Scams I've Seen
11:09 - Fake Download Sites
12:26 - Some Tips
14:12 - Final Rant

The prevalence of YouTubers getting hacked is on the rise, leading to channels being hijacked and taken over, leading to fraudulent streams that present scams such as fake cryptocurrency giveaways. Several channels with millions of subscribers have been compromised. Hackers change the channel's name, profile picture, and even the @handle, which changes the channel URL. The hackers use a type of attack called session hijacking or cookie stealing, which means that they can totally bypass 2FA, then lock the YouTuber out of their account and even change their password and remove their 2FA methods. Though the malware responsible for this has various tricks to avoid detection and can affect anyone. The malware gets to the victims through fake sponsorships or emails that include malicious payloads.

▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
Рекомендации по теме
Комментарии
Автор

Hopefully now that it's happening to massive channels like LTT Youtube will be forced to pay more attention :/

thinthle
Автор

Looks like this exact thing just happened to LinusTechTips. And yea, the powerless feeling as a person who cares about a channel is strong. We have to sit back and watch the hacker delist/delete videos and post their scam live stream while we can do nothing. I can't imagine what it would be like to be the channel owner right now.

NerdLFG
Автор

I remember a time when being internet smart boiled down to don't run any .exe or script files from unknown or sketchy sources. Good times.
Now it's that plus relying on multibillion dollar international companies to NOT be completely incompetent in their core business domain.

Seriously? No reauthentication for changing passwords or 2FA settings and no internal process for employees to verify and report hacking and abuse? This is pretty basic stuff that I can't imagine would have significant (if any) costs.

Gamer
Автор

Sounds like Google could easily deal a crippling blow to the hackers just by requiring reauthentication for the password change request, but they don't/won't.

MacTX
Автор

The real messed up part. Some of these people who hijack channels will outright delete videos on a channel. Unless their channel is important enough to be backed up or they have a backup of them. Those videos are gone forever.

Dtr
Автор

This has happened where me and my friend looked up a streaming software and I luckily realised it was fake because it was an ad from Google. Google really needs to stop this

HapYTMC
Автор

Every time I turn on my Smart TV and open YouTube the homepage is invaded by these videos... I believe that YouTube and browsers needs to take more advanced security measures!

WhoKilledRadioStar
Автор

The second you mentioned the scam site's claim of "doubling the crypto you send them", my mind immediately jumped to the RuneScape gold doubling scam. Glad we're on the same page!

Great vid by the way! I've seen this happen to a number of channels I'm subbed to and always wondered how it happened. Great to finally have some background on it!

JetSetDman
Автор

These tesla live hijacks have gotten really common. I am subscribed to a ton of channels old and new. These last couple of years every 3 months or so I see one of these tesla live streams in my subscibtion box. I can usually figure out whose channel it is from either the about section or the community posts, they don't tend to wipe those. You mentioned that these streams can potentially be up for hours before they are dealt with, but actually I've seen some online for days. Even with channels upwards of 500k subs.

fazekasroland
Автор

Thanks for the warning. Yeah, I am getting a ton of the fake sponsorship emails at the moment

AtomicShrimp
Автор

What needs to happen at YouTube to prevent this
1) Channel Name Change requiring another confirmation by 2FA
2) Name change for the account blocks live streaming for 1 day
3) If the changed name involves Tesla SpaceX MrBeast hold the account until someone can look at it

notspm
Автор

Your mention of doubling money in Runescape unlocked a core memory for me. Dude convinced me he had a secret dupe exploit and could dupe any item. I gave him my god staff. He kind of started at me for a minute, perhaps surprised that someone was that damn gullible, and then walked away. I learned a valuable lesson that day.

thebluemarauder
Автор

Three of the LTT channels just got hacked with this. Hopefully when a channel as big as LTT gets targeted, YouTube decides to start paying attention to this.

markpeters
Автор

In the short 2 months of this year I've already seen like 5 channels I'm subscribed to get hacked

nightwingnl
Автор

I had to quickly download OBS a few weeks ago on my laptop and now I'm skeptical about downloading from the right source. Fantastic T-T

ericrodriguez
Автор

i know you probably wont read this thio, but i just gotta say... please never stop making content. I know the views are down, and you probably invest more time than its worth back in monetary gain, but you make some of the best, most consistent high quality tech content ive ever seen. and your core subscriber base knows that, even if a video has 200k views or 2 million views, it's gonna be of the same quality no matter what.

one day youll be one of the greats. road to three mill.

embismusic
Автор

9:00 Before this part, I had a bit of a moment of phobia of digital cookies of any kind, and I thought that's all they needed to hijack you. I was a bit relieved to learn that they didn't become that strong of a threat that not avoiding shady sites and ignoring scam emails can protect you.
For a moment, it was an irrational fear of digital cookies before getting to this part.

MrXemrox
Автор

As a retired computer/Windows IT tech, I'm amazed how many people then and now fall for scams!!!! And, it will only get video Joe!!

eddy
Автор

Hi ThioJoe, there's another scam as well which impersonates the youtuber and tells you to download signal because you have won some type of prize and what they do is tell you to pay for shipping and you get nothing. Of course, it isn't as bad as what you mentioned but they still harass you constantly.

wilfredotorres
Автор

I was hacked a few months ago using this method; they started spamming crypto-shit with Tesla and Elon Musk, obviously. Fortunately, i was able to recover quick and didn't lose any data. Also, lots of my favourite youtubers have been suffering from this in the last few months, in fact, it happened like an hour ago for one of them. Thanks for the video, really instructive and interesting!

BrunoDeGamazoyAbarca