Safe collaboration

Avoid impersonation and advance-payment scams in creator deals

A verification and incident checklist for suspicious sponsorship contacts, hidden links, credential requests, advance payments, evidence preservation, and reporting.

A professional logo, familiar display name, or copied campaign brief does not prove who sent a sponsorship offer. Scammers can imitate brands, agencies, creators, platforms, and government organizations. Slow the process down, verify through an independent route, protect account credentials, and preserve evidence when a message asks for money or access.

Recognize high-risk requests

Stop when a contact demands a fee to unlock a sponsorship, asks for gift cards or cryptocurrency, sends a check and asks you to return part of it, wants you to receive and forward money, or says you must pay shipping through a specific unknown service. Passwords, one-time codes, recovery codes, and remote access are never needed to evaluate a campaign.

Inspect identity independently

Do not use the phone number or verification link supplied in the suspicious message. Find the official brand or agency website independently, check the exact email domain, and contact a published business channel. Ask a named employee to confirm the campaign and agency relationship. Display names and social badges can be copied or compromised.

Handle links and files cautiously

Preview the real link destination and be wary of shortened or misspelled domains. Do not enable macros, install a viewer, run an executable, or sign in through an unexpected attachment workflow. Navigate to Danchuu, YouTube, or the relevant service directly rather than through a login link in the message. Keep devices and browsers updated and use phishing-resistant account protection where available.

Verify the commercial story

A credible proposal should identify the product, objective, deliverables, schedule, compensation, rights, disclosure, and responsible parties. Compare the contact with the official company and campaign information. Artificial urgency, secrecy, threats, and a refusal to provide a written scope are warning signs even when no money has been requested yet.

Preserve and report evidence

Save the sender address, full message headers when available, account name, URLs, attachments without opening them, payment instructions, timestamps, and screenshots. Report through the platform and the impersonated organization. If credentials were entered, change them from a trusted device, revoke sessions, and contact the account provider. If money moved, contact the payment provider or bank immediately and follow local reporting guidance.

Protect normal collaboration records

Keep final identity checks, scope, payment destination, and every approved change in one record. Confirm any change of bank details through a previously verified channel. Limit private analytics and personal data to what the collaboration genuinely needs. A platform report can help moderation, but it cannot promise identity, recovery, or a legal outcome.

Official sources and limits

CISA describes common phishing warning signs and recommends resisting pressure, reporting the attempt, and deleting it after reporting. YouTube explains the normal Creator Partnerships flow in which creators and brands negotiate and arrange payment directly. Use official routes to compare an unexpected request with the legitimate process.

Reviewed September 13, 2026. This is general safety information, not identity verification or legal advice. In an urgent account or financial incident, contact the relevant provider, financial institution, and local authority promptly.

A 15-minute verification sequence

Following a link or telephone number inside the original message keeps the verification inside a path an attacker may control. Use independent information before opening a link or file.

  1. Minutes 0–3: expand the full sender and reply-to addresses, then mark lookalike spelling or a mismatched domain.
  2. Minutes 3–6: type the official brand domain into the address bar instead of using a search advertisement or message link, then find its published contact route.
  3. Minutes 6–9: ask the official contact only whether the named person and campaign sent the proposal. Do not forward the suspicious link or payment details.
  4. Minutes 9–12: stop if the sender requests a product purchase, deposit, gift card, authentication code, password, or remote-control application.
  5. Minutes 12–15: preserve the sender, time, request, and message headers, then report through the platform and any appropriate authority.
Incident record: received time / display name / actual sender / reply-to / claimed company / requested action / whether anything was opened or paid / independent verification route / report destination and time. Never record the password or authentication code itself.

If a password or authentication code was entered, type the official service address yourself and review the password and active sessions. Contact the financial institution immediately when payment data or a transfer is involved. Use the Danchuu contact page for Danchuu reports, but not as a substitute for urgent loss response.