A creator impersonation scam borrows your name before anyone has time to check it. A copied profile announces a prize, a fan is asked to pay a small fee, and by the time your moderators agree on what happened the account has changed its handle and moved on.
A creator impersonation scam does not have to earn anything. It borrows what you already built: the name, the avatar, the writing rhythm, the thread it replies under. A fan reading a notification sees your identity first and the details second, and that order is the whole attack.
A fake giveaway supplies the urgency. The message says the fan has won, that the deadline is short, that one private step remains. A compromised moderator account is harder still to spot, because its age, its shared servers, and its message history are all genuinely real.
On a multi-host show there is a further gap to work with: uncertainty about which person normally handles partnerships, prizes, or private replies. If your audience cannot say which of the persons on the channel would ever message them about a prize, an impersonator does not need to be convincing. Only plausible.
Platform rules define what is reportable. YouTube’s impersonation policy prohibits content meant to impersonate a person or a channel and points to the reporting routes, and Discord’s deceptive-practices explainer covers impersonation, financial scams, and deceptive links. Neither one decides who on your team captures the evidence, warns fans, pauses the campaign, or confirms that recovery is finished. That part is yours to write down.
Give fans a short, stable statement that answers three questions: where official offers appear, what your team will never ask for, and how to check a message that feels wrong. Put it where an attacker cannot bury it. The website, the channel About page, the community rules, and a read-only announcement channel all work, and using several of them means no single deletion removes the answer.
Keep the promise narrow enough to stay true. Do not say the team never sends private messages if a moderator sometimes follows up privately on a safety report. Define instead which kinds of message are possible and which requests are never legitimate, because a promise your own team breaks weekly teaches fans to ignore the whole notice.
For a rotating cast, list roles rather than one shared identity. A host may announce a live event while a producer handles prize delivery and a moderator handles reports. Fans should not have to infer authority from who is most famous.
A giveaway creates a temporary identity and a temporary support system, so treat it as a small operation rather than a promotional post. Write down the official announcement URL, the entry period, the eligibility rules, the selection method, the winner contact route, the prize delivery owner, and the closing notice before anything goes live.
Use one campaign identifier in every legitimate update, and link later posts back to the original terms instead of restating them in replies. If a partner ships the prize, name the partner and say exactly when a winner should expect contact. Collect no more personal data than delivery needs, and do not ask finalists for information before the team has selected and verified a winner.
Decide the cancellation trigger in advance: an official account compromised, a fake account reaching a meaningful part of the audience, or the team no longer able to verify winner messages. A short delay costs less than asking fans to sort real claims from fake ones while you are still working out which is which.
Then close the campaign visibly. Mark the original post closed where editing allows it, publish that winners have been contacted through the stated route, and keep the authenticity notice up after the promotional posts stop circulating. An unclosed giveaway stays useful to an impersonator for months.
Telling fans to report scams is not enough if the reports arrive as cropped screenshots scattered through public replies. Build one intake route and ask for the smallest evidence set that lets a moderator actually act on it.
Ask reporters not to repost the malicious link publicly. A moderator can preserve the exact destination in a restricted case record instead. If a fan paid or exposed credentials, move that conversation to the official support route and give account-security guidance suited to the platform. Do not ask the community to investigate a fan’s financial account.
Record the original URL, the account identifier, the visible name, the timestamps, the message text, and the affected channels before you delete anything locally. A screenshot establishes what fans saw. The identifiers are what lets a platform find the account after the name has changed twice.
Classify the report before you act in public. A suspicious tone on its own does not tell the team which response applies, and the wrong response is expensive in both directions.
A copied identity usually calls for a platform report, link containment, and a fan warning. A compromised identity adds credential recovery, session revocation, a permission review, and a pause on scheduled posts. A misleading affiliate needs the commercial owner to stop the campaign and preserve the agreement. Fan confusion calls for a correction, not an accusation of fraud.
Assign one incident owner. Other moderators can gather reports, but one person decides the classification, the correction text, and the closure criteria. Without that, several hosts publish contradictory messages inside the same hour and the contradiction becomes the story.
Remove malicious links from the surfaces you control, restrict the suspected account where your platform role allows it, and pause automated promotion that points fans into a compromised thread. Use slow mode or temporary posting limits only where they cut repeated scam messages without silencing the reports you still need.
Do not quote the full scam pitch in a large public post. It teaches fans what to avoid, but it also redistributes the handle, the link, and the phone number to everyone who had not seen them yet. Describe the pattern instead: accounts replying to comments with a prize claim and a fee request are not affiliated with the show. Then give the official verification route and the single action a fan should take.
Discord’s Community Guidelines set the platform boundary for fraudulent conduct, but your moderators still need a local rule: remove deceptive links, preserve the evidence privately, restrict the account, and route the platform report to the incident owner. Keep ordinary disagreement and honestly mistaken links out of the fraud workflow unless the evidence supports deceptive intent.
If several persons appear on the channel, name the affected identity precisely. A fake account wearing one host’s face does not mean every account connected to the show is compromised, and saying it loosely is its own kind of false alarm.
Use the platform’s current reporting route and submit a concise package: the impersonated identity, the official profile, the suspected profile, the message or post links, the timestamps, and one sentence explaining the deceptive request. Keep facts separate from assumptions, because a report that overstates is a report that gets closed.
Avoid organising a mass-reporting campaign. It produces duplicate, inconsistent reports, and it sends a crowd of fans to go and interact with the scam. Start with one complete report from the creator or an authorised team member, and let affected fans add their own when the platform asks for them.
If the account copied a real person, let that person or an authorised owner approve the identity claim where practical. On a multi-host channel a producer should not casually assert that a host controls no other accounts unless the host has confirmed it.
Track the case number, the submission time, the owner, and the next review date. Platform action is one part of recovery, not the closure signal by itself.
A correction should be brief, dated, and specific. Say what is fake, which official route fans should trust, what the real team will never ask for, and what an affected fan should do now. Do not promise that nobody was harmed unless you can actually establish it.
Use the website or the established announcement channel as the canonical correction and link every other post to it. Pin the notice near the affected campaign, then remove the redundant warnings once the risk window closes, so the community does not end up living in permanent alarm.
If a legitimate giveaway continues, say whether earlier entries still stand and whether the contact schedule changed. If it stops, close it explicitly. Silence leaves the impersonator room to claim that a late message is still authentic.
Answer affected fans privately through the published support route, and skip the argument about whether someone should have known. Winning that point costs you the reporter. The goal is to make authenticity easier to check next time.
When the genuine account was compromised, stop outbound activity before resuming normal community work. Reset credentials through the platform’s official recovery flow, revoke unfamiliar sessions and connected applications, rotate exposed secrets, and inspect scheduled messages, webhooks, roles, and recovery contacts.
Check the systems next door. A compromised email account may control the password resets. A stolen moderator session may have created a role or an integration that survives the password change. A fake landing page may still be linked from a profile long after the chat messages are gone.
Have a second person verify the recovery from an ordinary fan account: suspicious posts gone, official links leading to the expected domains, moderators holding only the permissions they need, support route working. The person who performed the recovery should not be the only one declaring it complete.
Count the reports received, the time to first containment, the time to the canonical correction, and the number of places that carried conflicting instructions. Those are process measures. They do not prove that every affected fan came forward, and it is worth saying that out loud rather than reading a quiet week as a clean outcome.
Afterwards, update the authenticity contract, the giveaway template, the moderator permissions, and the contact list. If fans repeatedly believed a delivery fee, make the no-fee rule more visible. If moderators could not work out who owned the campaign, put that owner on the launch checklist. If several warnings contradicted each other, narrow who may publish during an incident.
Do not wait for the next copied profile. Publish the authenticity contract, create the single report route, and run a twenty-minute tabletop exercise using a fake giveaway reply as the scenario.
The exercise should end with four things in hand: one evidence record, one containment decision, one named platform-report owner, and one correction drafted and ready for the announcement channel your fans already read. If it ends in a discussion instead, that is the finding, and it is much cheaper to have it today than during the incident.