{"id":18717,"date":"2022-04-08T10:10:12","date_gmt":"2022-04-08T18:10:12","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/04\/08\/news-12450\/"},"modified":"2022-04-08T10:10:12","modified_gmt":"2022-04-08T18:10:12","slug":"news-12450","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/08\/news-12450\/","title":{"rendered":"YouTube channels of Taylor Swift, Justin Bieber, Harry Styles, and other musicians compromised"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 08 Apr 2022 17:38:10 +0000<\/strong><\/p>\n<p>Some of the biggest stars around have seen content placed on their YouTube accounts without permission over the last couple of days. Taylor Swift has around 40 million subscribers. Justin Bieber? 68 million. Harry Styles, a respectable 12 million. You can even add Eminem and Michael Jackson to the list of those taken over.<\/p>\n<p>Big names, and even bigger numbers.<\/p>\n<p>The last time I can remember an all-out targeted attack on social media musicians was <a href=\"http:\/\/content.time.com\/time\/business\/article\/0,8599,1683361,00.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">way back in 2007<\/a> during Ye Olde Myspace days. While the threat for mischief there was big, this new attack far surpassed it in terms of people seeing dubious content.<\/p>\n<h2>Using Vevo as a stepping-stone to musician channels<\/h2>\n<p>According to <a href=\"https:\/\/therecord.media\/vevo-announces-investigation-after-youtube-accounts-for-rihanna-justin-beiber-taylor-swift-kanye-and-more-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Record<\/a>, the attack specifically targeted accounts using <a href=\"https:\/\/www.hq.vevo.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Vevo<\/a>. The people behind it didn&#8217;t promote malware links, or spam, or phishing. Instead, they opted to post about a <a href=\"https:\/\/www.businessinsider.es\/justin-bieber-eminem-hackeados-youtube-video-paco-sanz-1039761\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">bizarre scam<\/a> involving a security guard.<\/p>\n<p>The scam involved a man claiming to have &#8220;2,000 tumours&#8221;, sentenced to 2 years in jail for <a href=\"https:\/\/english.alarabiya.net\/variety\/2021\/02\/09\/-2-000-tumor-man-sentenced-to-two-years-in-prison-for-scamming-Spain-donors\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">grabbing around $319,000 in donations<\/a> for his non-existent terminal illness. The group claiming to be behind the compromise demanded he be <a href=\"https:\/\/twitter.com\/lospelaosbro\/status\/1511247793855373314\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">set free<\/a> via their Twitter account.<\/p>\n<p>If you\u2019ve ever watched a music video from a major artist, there\u2019s a good chance you\u2019ll have seen the Vevo logo in the bottom right hand corner. <a href=\"https:\/\/www.youtube.com\/channel\/UC2pmfLm7iq6Ov1UwYrWYkZA\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">This is the Vevo channel<\/a>, where content is uploaded. As <a href=\"https:\/\/therecord.media\/vevo-announces-investigation-after-youtube-accounts-for-rihanna-justin-beiber-taylor-swift-kanye-and-more-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Gizmodo notes<\/a>, videos are merged with the musician\u2019s separate YouTube channel. Existing YouTube accounts can also be merged to create <a href=\"https:\/\/www.hq.vevo.com\/artists\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Official Artist Channels<\/a>.<\/p>\n<p>Speaking to <a href=\"https:\/\/www.theverge.com\/2022\/4\/6\/23012513\/youtube-vevo-hack-lil-nas-x-taylor-swift-michael-jackson\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Verge<\/a>, Vevo said \u201cSome videos were directly uploaded to a small number of Vevo artist channels earlier today by an unauthorized source.\u201d<\/p>\n<p>This is what <a href=\"https:\/\/support.vevo.com\/hc\/en-us\/articles\/1260804431129-How-do-I-access-a-Vevo-Artist-Channel-on-YouTube-\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Vevo\u2019s FAQ page<\/a> has to say on the subject of how uploads work:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>Vevo does not provide access directly to artists. If your music videos have been delivered to Vevo, you must work with your existing Content Provider\/Label who will have access to perform these updates.<\/p>\n<\/blockquote>\n<h2>What about <em>your<\/em> YouTube security?<\/h2>\n<p>You may not be a multi-million album seller signed up to Vevo on YouTube, but you still need to lock down your YouTube account. Any compromise can lead to masses of spam or videos leading users off-site to phishing or malware.<\/p>\n<p>Signing into YouTube requires a Google account. As such, good Google security hygiene means good YouTube security hygiene too. We\u2019ve covered many Google-centric security concerns previously, but here\u2019s some things you can do now to lock down your account:<\/p>\n<ul>\n<li><strong>Create a strong password<\/strong>, and enable two-factor authentication (2FA). Use the Google Auth app for 2FA rather than SMS codes, this will help you avoid the threat of SIM-swap attacks.<\/li>\n<li><strong>Don\u2019t share sign-in information<\/strong> with others. If someone contacts you promising riches beyond your wildest dreams, they may ask for your login details to set up some sort of \u201caffiliate\u201d or partnership status. This is a bad idea, and you shouldn\u2019t do it.<\/li>\n<li><strong>Use <a href=\"https:\/\/myaccount.google.com\/security-checkup\/7?pli=1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google\u2019s security checkup<\/a><\/strong>. This informs you at a glance about recent login activity, device sign-ins, Gmail settings, and more. It\u2019s a handy, focused way to make sense of the sometimes overwhelming range of options available.<\/li>\n<li><strong>Remove sites and apps you don\u2019t need<\/strong> or recognise. As with many social accounts, you\u2019re able to connect to a variety of services. View connected apps <a href=\"https:\/\/www.youtube.com\/account_sharing\" data-rel=\"lightbox-video-0\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">here<\/a>.<\/li>\n<li><strong>Keep an eye on the comments<\/strong> posted to your videos. There\u2019s a lot of spam out there and it may sully your reputation if followers end up in bad places via your content.<\/li>\n<\/ul>\n<p>This should be enough to get your account moving to a place where it\u2019s a lot more secure than before. While the chance of you being hit by an attack like the one above targeting very well known accounts is low, people regularly look to hijack regular YouTube accounts. Let\u2019s not make it easy for them!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/youtube-channels-of-taylor-swift-justin-bieber-harry-styles-and-other-musicians-compromised\/\">YouTube channels of Taylor Swift, Justin Bieber, Harry Styles, and other musicians compromised<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/youtube-channels-of-taylor-swift-justin-bieber-harry-styles-and-other-musicians-compromised\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 08 Apr 2022 17:38:10 +0000<\/strong><\/p>\n<p>We look at a recent takeover of popular musicians&#8217; channels on YouTube, and advise how you can keep your own account safe.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/youtube-channels-of-taylor-swift-justin-bieber-harry-styles-and-other-musicians-compromised\/\">YouTube channels of Taylor Swift, Justin Bieber, Harry Styles, and other musicians compromised<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[18865,4980,25635,10574,25636,2593],"class_list":["post-18717","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-compromise","tag-hack","tag-musician","tag-scams","tag-vevo","tag-youtube"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18717"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18717\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18717"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}