{"id":2474,"date":"2023-04-20T06:13:20","date_gmt":"2023-04-20T13:13:20","guid":{"rendered":"https:\/\/www.ssls.com\/blog\/?p=2474"},"modified":"2023-09-27T06:16:43","modified_gmt":"2023-09-27T13:16:43","slug":"how-hackers-hijacked-a-popular-tech-youtube-channel","status":"publish","type":"post","link":"https:\/\/www.ssls.com\/blog\/how-hackers-hijacked-a-popular-tech-youtube-channel\/","title":{"rendered":"How hackers hijacked a popular tech YouTube&nbsp;channel"},"content":{"rendered":"\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.ssls.com\/blog\/wp-content\/uploads\/SSL_Blog_tech-YouTube-channel.png\" alt=\"\" class=\"wp-image-2327\"\/><\/figure>\n\n\n\n<p>YouTube channel Linus Tech Tips and two related channels within the same media group were recently taken over by hackers and deleted. For several hours chaos broke out across the Linus Media Group, which has a combined followership of over 25 million people. The hackers did everything from advertising dodgy cryptocurrency to mass deleting videos, eventually resulting in YouTube terminating the channels due to breaching its terms of service.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>&nbsp;Fortunately, the channels are back up and running, and everything\u2019s back to normal. So, what exactly happened, and how was it fixed in the end?&nbsp;<\/p>\n\n\n\n<p>Read on to find out.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What the hackers did<\/h2>\n\n\n\n<p>In a <a href=\"https:\/\/www.youtube.com\/watch?v=yGXaAWbzl5A&amp;ab_channel=LinusTechTips\">video<\/a> explaining the situation, channel owner Linus Sebastian explains that the trouble started just after 3 am when the Linus Tech Tips account was renamed Tesla and started streaming a podcast-style recording of Elon Musk discussing cryptocurrency with several others. The stream linked to a scam website that promised users that for every one bitcoin they spent, the site would return double. To lend an air of legitimacy, the site also featured fake transactions of other users getting huge payouts from the site.&nbsp;<\/p>\n\n\n\n<p>While Linus tried to tackle the issue, his two other related channels, TechLinked and Techquickie, began hosting these fake crypto streams. Eventually, YouTube took down all three channels for violating its terms of service.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How the hack occurred<\/h2>\n\n\n\n<p>The surprising thing about the takeover was that it didn\u2019t occur because of a password breach or dubious 2FA practices but by targeting session tokens. A session token is stored in your browser on your device and allows you to continually access a site via your account once you\u2019ve logged in and your credentials have been validated.&nbsp;<\/p>\n\n\n\n<p>Hackers managed to hijack a session token by targeting an employee with social engineering. A team member downloaded what they thought was a sponsorship offer from a convincing-looking email. They launched the PDF of what they assumed were the terms of the sponsorship deal, but nothing happened. Innocent enough. However, unbeknownst to the team member, the PDF actually downloaded malware to the computer, which then proceeded to access user data from the team member\u2019s web browsers, from cookies to saved passwords and session tokens for every site they were logged into.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How everything was fixed in the end<\/h2>\n\n\n\n<p>Before Linus realised the root of the problem, he started trying to tackle the incident by privating the streams, revoking the stream keys, and resetting the accounts\u2019 credentials. However, the hackers were one step ahead, and not only started the stream again, but also began mass deleting videos. Once he figured out the root cause was the session IDs Linus had some trouble navigating their content management system and figuring out which exact login was the issue. While Google helped them resolve the problem in the end, Linus had some critiques of their support communications practices, which you can hear in full <a href=\"https:\/\/www.youtube.com\/watch?v=yGXaAWbzl5A&amp;ab_channel=LinusTechTips\">in the video<\/a>.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Future prevention<\/h2>\n\n\n\n<p>This sort of takeover has been a recent problem for myriad <a href=\"https:\/\/www.theverge.com\/2022\/9\/7\/23342120\/apple-fake-youtube-live-stream-crypto-scam\">YouTube creators<\/a>. As always, awareness is key, as well as proper training for staff members so they know the signs of social engineering attacks. Linus also highlights the need for YouTube and Google to strengthen their own <a href=\"https:\/\/www.ssls.com\/blog\/can-an-ssl-be-hacked\/\">security<\/a> practices. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>YouTube channel Linus Tech Tips and two related channels within the same media group were recently taken over by hackers and deleted. For several hours chaos broke out across the Linus Media Group, which has a combined followership of over 25 million people. The hackers did everything from advertising dodgy cryptocurrency to mass deleting videos, [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2474","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/2474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/comments?post=2474"}],"version-history":[{"count":2,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/2474\/revisions"}],"predecessor-version":[{"id":2623,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/2474\/revisions\/2623"}],"wp:attachment":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/media?parent=2474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/categories?post=2474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/tags?post=2474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}