Friday Night Threat Watch: Fake Sponsors and Discord Scams
Welcome to the first Friday Night Threat Watch. This is the weekly spot where we break down the scams, phishing, and general internet nonsense aimed straight at streamers and the people who hang out in their communities. If you go live, mod a channel, or just vibe in a Discord server, this one is for you.
Grab a drink. Let's get into the two scams hitting creators the hardest right now.
Scam 1: The fake sponsorship email
You hit a few hundred followers and suddenly your inbox lights up. "Hi, we love your content and want to sponsor you." Feels amazing. It is also one of the most common ways streamers get owned.
Here is how the play usually goes:
- A polite email from a "brand manager" at a company you sort of recognize.
- A generous offer with numbers that feel a little too good.
- An attachment or a download link. A contract PDF, a game build to review, a "brand kit," or a key you need to activate.
- Pressure to move fast before the "campaign slot" closes.
The attachment or download is the trap. Sometimes it is malware that grabs your saved passwords and session tokens. Sometimes the link sends you to a fake login page for Twitch, YouTube, or your email. Either way, the goal is your account, not a partnership.
Red flags worth trusting:
- The sender domain is off. Real companies email from their real domain, not a lookalike and not a random free inbox.
- They rush you. Urgency is a manipulation tactic, not a business practice.
- They want you to run something. No legit sponsor needs you to open a random installer or "add our streaming tool" to get paid.
- The grammar and branding feel copy pasted.
How to stay clean:
- Never open attachments from a first contact. Ask for details in the body of the email instead.
- Verify the company through their official website and reach out to them directly, not to the address that messaged you.
- Hover every link and read the real domain before you click.
- Keep sponsorship work on a separate browser profile, or better yet a separate machine, so one bad click cannot reach your main logins.
- Turn on two factor everywhere, and use an authenticator app instead of text messages.
If a deal is real, it survives you slowing down and checking. If it falls apart the second you ask a question, it was never a deal.
Scam 2: Discord DMs that eat your account
Discord is where a lot of your community lives, which makes it a target. Most of these scams arrive from a friend whose account was already stolen, so the message looks like it is coming from someone you trust.
The greatest hits:
- Free Nitro. A link claims you won or were gifted Nitro. The link goes to a fake Discord login.
- The QR code login trick. Someone asks you to scan a QR code to "vote for their team," "verify," or "get into the beta." That QR is a Discord login request. Scanning it logs the attacker into your account instantly. This one is nasty because it walks right past your password and your two factor.
- "Can you test my game." A supposed indie dev asks you to download and run their project. The project is a token stealer wearing a game costume.
- Fake staff. A message claims to be Discord support or Twitch support warning you about a violation, then asks you to log in or hand over a code.
Red flags worth trusting:
- Any link that leads to a login page. Real logins start from you opening the app, not from a message.
- Anyone asking you to scan a QR code to log in, verify, or vote. There is almost never a good reason for this.
- Urgency and threats. "Your account will be deleted in 24 hours" is bait.
- A close friend suddenly sending links or asking for odd favors. Confirm with them somewhere else first.
How to stay clean:
- Never scan a login QR code that came from a link or a stranger.
- Turn on two factor for Discord and save your backup codes somewhere safe.
- Do not run random downloads, even from friends, unless you both know exactly what it is.
- If a message smells wrong, it is wrong. Slow down and verify.
Quick gut check before you click
Run through this in your head every time something feels off:
- Did I go looking for this, or did it find me?
- Is it rushing me?
- Does it want me to log in, scan, or run something?
- Does the domain actually match the real company?
If more than one of those trips, treat it as hostile until proven otherwise.
Not sure about a link? Send it to !mal_check
Here is the fun part. My Discord has a command called !mal_check built for exactly these moments. If you get a sketchy link in a DM, a sponsor email, or a random channel drop, do not click it. Paste it into !mal_check instead and the bot will check it out and hand you back a verdict. Safe, suspicious, or straight up malicious.
Use it. Abuse it. That is what it is there for. It is a lot cheaper to ask the bot than to rebuild your whole online life after a token theft.
If you are not in the Discord yet, that is the move. Come hang out, drop your sus links, and let the bot take the risk so you do not have to.
See you next Friday
That is the first Friday Night Threat Watch back on the board. Next week we pull apart another one. Until then, verify before you trust, slow down before you click, and keep your accounts locked up.
Stay safe out there, hackers.