MrBeast Scams: Verified Accounts, DeepFakes Used in Impersonations to Promote Fake Giveaways on YouTube and TikTok

</p> <p><strong>MrBeast, the most popular YouTube creator as of October 2023, has been impersonated in a variety of scams on YouTube and TikTok, including a recent deepfake promoting a fake free iPhone 15 giveaway</strong></p> <h2>Background</h2> <p>James Stephen “Jimmy” Donaldson, also known as MrBeast, has been impersonated across various social media platforms including YouTube and TikTok to promote a variety of scams. MrBeast, a content creator with <a href=""><u>over 188 million subscribers on YouTube</u></a> as of October 2023, is known for his lavish stunts and philanthropy. He often gives away cars, large sums of money, electronics and other gifts to subscribers and participants in his YouTube videos. He also runs a charity, <a href=""><u>Beast Philanthropy</u></a>. His philanthropic and charitable nature makes him an ideal person for scammers to impersonate across social media.</p> <p>Over the last year, I’ve tracked a few trends involving impersonations of MrBeast.</p> <h2>Fake MrBeast YouTube Ads</h2> <p>On YouTube, scammers have used MrBeast’s photos as part of YouTube ads. Unlike the <a href=""><u>Elon Musk cryptocurrency giveaway scam ads</u></a> I’ve written about before, the scammers in this instance use <a href=""><u>in-feed video ads</u></a>, which appear via YouTube search results and the YouTube app Home feed.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>These videos instruct users to visit a website, cashtab[.]info. Pinned video comments purportedly posted by MrBeast also provide a direct link to the website and mention an “Official Sponsor” of the giveaway. The YouTube page, SFK Offers, is verified and commented on the video just beneath the pinned comment, stating that terms and conditions apply.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>The comment provides a link to the website</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>The website uses a cartoon likeness of MrBeast and says that over $450,000 has already been given away and that a $500 reward has been reserved for the current page visitor. In order to receive the alleged $500, users are instructed to click on the “CLAIM REWARD” button and complete a survey.</p> <p>Interestingly enough, although the scammers use MrBeast’s likeness in their YouTube advertisements, creating a fake channel associated with MrBeast and having a cartoon likeness of MrBeast on the website, they add a fine print to the website that says that this offer is “Not Affiliated with MrBeast or any public figure.” This statement is part of an effort by the scammers to protect themselves against legal action from MrBeast or other public figures that they may feature in advertisements and websites affiliated with their scams.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <h2>Fake MrBeast TikTok LIVE</h2> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>On TikTok, where MrBeast has over 87 million followers as of October 2023, scammers started impersonating him with fake accounts, going on TikTok LIVE using stolen livestream footage of MrBeast playing the video game “Among Us.”</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>I’ve previously written about <a href=""><u>how scammers used stolen footage as part of TikTok Live scams</u></a> to impersonate a variety of noteworthy individuals, from celebrities to content creators. Just as in past scams, the scammers impersonate MrBeast hoping to collect gifts from unsuspecting viewers. These gifts can be converted into fiat currency, so it provides scammers with another avenue for making money.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <h2>Fake verified MrBeast TikTok accounts</h2> <p>Outside of the fake accounts going live on TikTok, another type of MrBeast impersonation scam happening on TikTok involves verified accounts that do not go live, but Instead comment on trending videos in order to drive traffic back to their accounts.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>The scammers comment on a variety of trending videos on TikTok. These comments can be topical or benign.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>The intention behind commenting, especially with a verified account, is to gather the attention of TikTok users to visit their profile.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>The scammers likely obtain <a href=""><u>verified TikTok accounts</u></a> by stealing them through phishing attacks or purchasing them from someone on the dark web. This is why some of the profiles contain no videos, as they are in the early stages of pivoting to the MrBeast impersonation.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>Other MrBeast impersonation accounts are more fleshed out, featuring a collage grid of videos that mention a “World Record Cash Giveaway” which is something that MrBeast might do. These profiles say they’re giving away a specific amount of money and ask users to click on a link in their bio.</p> <h2>Deepfake MrBeast TikTok ads</h2> <p>The culmination of these impersonations now includes a fake TikTok advertisement using a deepfake of MrBeast.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>TikTok ad scams aren’t new. I’ve <a href=""><u>previously documented their prominence on TikTok in 2020</u></a>, when they were used to promote dubious apps, products and services. However, they provide a definitive benefit for scammers: placement on the For You page, the most sought after real estate on TikTok.</p> <p>The deepfake video used in this advertisement includes an overlay of a verified badge claiming to be MrBeast. The footage used to create this deepfake video was <a href=""><u>taken from a documentary on MrBeast from Curiosity Stream</u></a>.</p> <p><!-- The script tag should live in the head of your page if at all possible --><!-- Put this wherever you would like your player to appear --><img decoding="async" class="vidyard-player-embed" data-type="inline" data-uuid="FKCzCGH8ZcPbZTGJ1fNQrp" data-v="4" src="" style="width: 100%; margin: auto; display: block;"/></p> <p>It is unclear which tool was used to create this deepfake, but with the improvements to generative AI over the last year, it isn’t surprising to see deepfakes like this one appearing on social media. And while it’s not perfect, it is put together well enough to trick some users into falling for this scam.</p> <p>The goal behind this deepfake advertisement is to drive users to a website promoting a fake iPhone 15 giveaway. With the launch of Apple’s flagship product, scammers are trying to take advantage of the interest surrounding the new product launch. This is a tried and true method of scams that has been around for over a decade now.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <h2>Survey scams persist</h2> <p>The majority of these impersonations of MrBeast are designed to drive users to websites that ask them to fill out a survey. The scammers claim the survey is easy to complete, instructing users to complete anywhere from one to three deals.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>These intermediary sites are designed to drive traffic to the surveys, which provide more context. For example, while the intermediary sites claim that users only need to complete one to three deals, the sites where these offers need to be completed actually state that users need to complete anywhere from 15 to 20 deals.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>These so-called deals can vary from downloading free or premium apps, completing certain tasks related to those apps, or signing up for trials to services. If users do not read the fine print, they are likely to see recurring charges on their credit or debit cards.</p> <p>In addition to completing these offers, users are asked to share personally identifiable information, including their names, addresses, phone numbers, and more. This information is sold to third parties for marketing purposes.</p> <h2>Free iPhones aren’t free</h2> <p>Even in the case of the supposed free iPhone 15 giveaway, the website users are directed to asks for credit card information in order to “pay for delivery.” If MrBeast can afford to purchase and giveaway 10,000 iPhones, surely he could afford to pay for the delivery costs.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>Users that are directed to these websites may not realize what they are signing up for when providing their credit card information.</p> <p><img decoding="async" referrerpolicy="no-referrer" src=""/></p> <p>Under the Terms and Conditions section of the website, submitting payment card information to the website will result in the immediate charge of $6.95, which may seem like shipping charges. However, as the fine print states, this is a monthly auto-enroll program and this initial charge is called a “Draw enrollment.” While it does state that users will be shipped a “Grand Major Winnerz Draw’ (sic), they do not specify what that is nor do they imply that it is an iPhone. Additionally, users are told that this enrollment is part of a trial and that after 7 days, users will be “charged the full retail price” which is $139.67. This is a recurring charge, which means users will be charged $139.67 every month until they cancel.</p> <h2>Spotting survey and fake giveaways on social media</h2> <p>It’s been well over a decade since I’ve tracked survey and fake giveaway scams on social media platforms. However, one thing has always remained true: <a href=""><u>as new social media apps and services rise in popularity, scammers will flock to these new platforms</u></a> and use many of the same tactics and techniques that have worked for over a decade. Here are a few tips users can use to help spot some of these scams.</p> <ol> <li><strong>Generative AI tools will make deepfake videos more convincing, so be skeptical.</strong> If you see a video of one of your favorite celebrities or content creators promoting some type of giveaway on social media, chances are it is a scam. With deepfakes getting more convincing, it is even more important to be skeptical about such giveaways on social media. Make sure you’re viewing the real, verified profile of the celebrity or content creator.</li> <li><strong>Impersonations will always rise up to the surface, so dig deeper:</strong> No matter if it is a fake account or verified fake account, scammers will always create impersonation accounts using a variety of techniques. Even if you see a verified badge, always double and triple check to make sure you are interacting with the real celebrity or content creator and not an impersonator. While most of these scams I encountered were on YouTube and TikTok, platforms like X (formerly known as Twitter) allow users to purchase verified badges for a fee, so the verified badge on some platforms may not be a viable indicator of trust.</li> <li><strong>Completing deals means you have to pay money upfront:</strong> If you are asked to complete a certain number of deals before you receive cash, gift cards or electronic devices, you’re being asked to pay money out of your own pocket for something that is supposed to be free.</li> <li><strong>Always read the fine print.</strong> There are links at the bottom of most of these websites offering deals. Check the fine print and read the terms and conditions, privacy policy and other links to find out how your information may be used or sold to third parties and whether or not you will be charged a recurring fee for services.</li> </ol> <h3>Learn more</h3> <p><b><i>Join <a href=""><u>Tenable’s Security Response Team</u></a><u> on the Tenable Community.</u></i></b></p> </div> <p><script async src="//"></script><br /> <br /><br /> <br /><a href="">Source link </a></p> </div><!-- .entry-content --> <footer class="entry-footer"> <span class="cat-links"> Posted in <a href="" rel="category tag">RSS_Virtulization</a> </span> </footer><!-- .entry-footer --> </article><!-- #post-## --> <nav class="navigation post-navigation" aria-label="Posts"> <h2 class="screen-reader-text">Post navigation</h2> <div class="nav-links"><div class="nav-previous"><a href="" rel="prev">CVE-2023-22515: Zero-Day Vulnerability in Atlassian Confluence Data Center and Server Exploited in the Wild</a></div><div class="nav-next"><a href="" rel="next">Cisco portfolio for transportation: What can we help you solve today?</a></div></div> </nav> </main><!-- #main --> </div><!-- #primary --> <div id="secondary-right" class="widget-area secondary-sidebar f-right clearfix" role="complementary"> <div id="sidebar-section-top" class="widget-area sidebar clearfix"> <aside id="newsletterwidget-10" class="widget widget_newsletterwidget"><h3 class="widget-title"><span>Subscribe For Updates</span></h3><div class="tnp tnp-subscription tnp-widget"> <form method="post" action=""> <input type="hidden" name="nr" value="widget"> <input type="hidden" name="nlang" value=""> <div class="tnp-field tnp-field-firstname"><label for="tnp-1">Name</label> <input class="tnp-name" type="text" name="nn" id="tnp-1" value="" placeholder=""></div> <div class="tnp-field tnp-field-email"><label for="tnp-2">Email</label> <input class="tnp-email" type="email" name="ne" id="tnp-2" value="" placeholder="" required></div> <div class="tnp-field tnp-privacy-field"><label><input type="checkbox" name="ny" required class="tnp-privacy"> Subscribing I accept the privacy rules of this site</label></div><div class="tnp-field tnp-field-button" style="text-align: left"><input class="tnp-submit" type="submit" value="Subscribe Now For Updates" style=""> </div> </form> </div> </aside> </div> <div id="sidebar-section-cat-one" class="widget-area sidebar clearfix"> <div class="widget"> <h2 class="block-title"><span class="bordertitle-red"></span>VMWARE</h2> <div class="featured-post-sidebar"> <figure class="post-thumb clearfix"> <a href="" title="Helping Public Sector Organisations Define Cloud Strategy" ><img post-id="1207" fifu-featured="1" src="" alt="Helping Public Sector Organisations Define Cloud Strategy" title="Helping Public Sector Organisations Define Cloud Strategy" /></a> </figure> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>October 29, 2020</div> <h3><a href="" title="Helping Public Sector Organisations Define Cloud Strategy" >Helping Public Sector Organisations Define Cloud Strategy</a></h3> <p class="side-excerpt">Introduction Cloud computing services have grown exponentially in</p> </div> </div> <div class="featured-post-sidebar"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>May 18, 2016</div> <h3><a href="" title="How to change the VLAN ID of the Service Console in ESX from the command line/console" >How to change the VLAN ID of the Service Console in ESX from the command line/console</a></h3> </div> </div> <div class="featured-post-sidebar"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>June 09, 2015</div> <h3><a href="" title="Cisco UCS and Vmware Interfaces (Vnics) HA Design Considerations" >Cisco UCS and Vmware Interfaces (Vnics) HA Design Considerations</a></h3> </div> </div> <div class="featured-post-sidebar"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>June 07, 2015</div> <h3><a href="" title="Troubleshooting network and TCP/UDP port connectivity issues on ESX/ESXi(2020669)" >Troubleshooting network and TCP/UDP port connectivity issues on ESX/ESXi(2020669)</a></h3> </div> </div> <div class="featured-post-sidebar"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>May 12, 2015</div> <h3><a href="" title="vSphere Client Parameters" >vSphere Client Parameters</a></h3> </div> </div> <div class="view-all-link"><a href="" title="View All">View All</a></div> </div> </div> <div id="sidebar-section-cat-two" class="widget-area sidebar clearfix"> <div class="widget"> <h2 class="block-title"><span class="bordertitle-red"></span>Configuration Templates</h2> <div class="featured-post-sidebar clearfix"> <figure class="post-thumb clearfix"> </figure> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>February 16, 2015</div> <h3><a href="" title="CUE Licenses" >CUE Licenses</a></h3> <p class="side-excerpt">Note: Useful LINK COPIED FROM OTHER SOURCE FOR REFERENCE INTRODUCTION</p> </div> </div> <div class="featured-post-sidebar clearfix"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>February 02, 2015</div> <h3><a href="" title="Trouble shooting Unity Express with Call Manager Integeration & Operational Issues" >Trouble shooting Unity Express with Call Manager Integeration & Operational Issues</a></h3> </div> </div> <div class="featured-post-sidebar clearfix"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>November 08, 2014</div> <h3><a href="" title="CME Configuration Example: SIP Trunks to Viatalk and" >CME Configuration Example: SIP Trunks to Viatalk and</a></h3> </div> </div> <div class="featured-post-sidebar clearfix"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>November 08, 2014</div> <h3><a href="" title="SIP Phone registration – CME Configuration" >SIP Phone registration – CME Configuration</a></h3> </div> </div> <div class="featured-post-sidebar clearfix"> <div class="post-desc"> <div class="post-date"><i class="fa fa-calendar"></i>November 08, 2014</div> <h3><a href="" title="CUE Voicemail + VPIM networking (CUE to unity)" >CUE Voicemail + VPIM networking (CUE to unity)</a></h3> </div> </div> <div class="view-all-link"><a href="" title="View All">View All</a></div> </div> </div> </div> </div><!-- #content --> </div><!-- content-wrapper--> <footer id="colophon" class="site-footer clearrfix" role="contentinfo"> <div class="wrapper footer-wrapper clearfix"> <div class="top-bottom clearfix"> <div id="footer-top"> </div><!-- #foter-top --> <div id="footer-bottom"> </div><!-- #foter-bottom --> </div><!-- top-bottom--> <div class="footer-copyright border t-center"> <p> Copyright 2016. All rights reserved </p> <div class="site-info"> <a href="">Proudly powered by WordPress</a> <span class="sep"> | </span> Profitmag by <a href="" rel="designer">Rigorous Themes</a> </div><!-- .site-info --> </div> </div><!-- footer-wrapper--> </footer><!-- #colophon --> </div><!-- #page --> <div class="a2a_kit a2a_kit_size_32 a2a_floating_style a2a_default_style" style="bottom:0px;left:0px;background-color:#23d5db"><a class="a2a_button_linkedin" href="" title="LinkedIn" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_facebook" href="" title="Facebook" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_pinterest" href="" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_twitter" href="" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_whatsapp" href="" title="WhatsApp" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_print" href="" title="Print" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_google_gmail" href="" title="Gmail" rel="nofollow noopener" target="_blank"></a><a class="a2a_dd addtoany_share_save addtoany_share" href=""></a></div><div class="mb_supershare_holder"> <div id="openModal" class="mb_supershare_modalDialog"> <div style="background:url( repeat;"> <div class="mb_supershare_ribbon"><div class="mb_supershare_ribbon-stitches-top"></div><strong class="mb_supershare_ribbon-content"><span style="font-size: 24px; line-height: 2;"> Love This Article? Spread It. </span></strong><div class="mb_supershare_ribbon-stitches-bottom"></div></div> <div class="mb_supershare_close">X</div> <!-- facebook need this script --> <div id="fb-root"></div> <script>(function(d, s, id) { var js, fjs = d.getElementsByTagName(s)[0]; if (d.getElementById(id)) return; js = d.createElement(s); = id; js.src = "//"; fjs.parentNode.insertBefore(js, fjs); }(document, 'script', 'facebook-jssdk'));</script> <div class="social_icons_style" style="width:320px; margin-left:25px; margin-top:20px; margin 0 auto; overflow:visible"> <ul> <li style="overflow:hidden; width: 49px;"> <!-- facebook like button --> <div class="fb-like" data-href="" data-width="450" data-height="The pixel height of the plugin" data-colorscheme="light" data-layout="box_count" data-action="like" data-show-faces="false" data-send="false"></div> </li> <li> <!-- G+ button --> <!-- Place this tag where you want the +1 button to render. --> <div class="g-plusone" data-size="tall" data-href=""></div> <!-- Place this tag after the last +1 button tag. --> <script type="text/javascript"> (function() { var po = document.createElement('script'); po.type = 'text/javascript'; po.async = true; po.src = ''; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(po, s); })(); </script> </li> <li> <!-- Twitter button --> <a href="" class="twitter-share-button" data-url="" data-via="" data-lang="en" data-related="anywhereTheJavascriptAPI" data-count="vertical">Tweet</a> <script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);;js.src="";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");</script> </li> <li> <!-- Linkedin button --> <script src="//" type="text/javascript"></script> <script type="IN/Share" data-url="" data-counter="top"></script> </li> <li> <!-- StumbleUpon button --> <!-- Place this tag where you want the su badge to render --> <su:badge layout="5" location=""> </su:badge> <!-- Place this snippet wherever appropriate --> <script type="text/javascript"> (function() { var li = document.createElement('script'); li.type = 'text/javascript'; li.async = true; li.src = ('https:' == document.location.protocol ? 'https:' : 'http:') + '//'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(li, s); })(); </script> </li> </ul> </div> </div> <!--DIV--> </div> <!--modalDialog--> </div> <!--mb_supershare_holder--> <script> jQuery(document).ready(function($) { $is_closed="no"; jQuery(document).scroll(function() { if(jQuery('article').length){ //For typical wordpress templates $afterpost = jQuery("article").position().top + jQuery("article").height()-(jQuery("article").height()/3); } else { //For Thesis framework $afterpost = jQuery(".content").position().top + jQuery(".post_box").height()-(jQuery(".post_box").height()/3); } if(jQuery(window).scrollTop() >= $afterpost && $is_closed=="no"){ jQuery(".mb_supershare_modalDialog").css({"display":"block"}); jQuery(".mb_supershare_modalDialog").animate({opacity:"1"},1000); } else{ jQuery(".mb_supershare_modalDialog").css({"display":"none"}); } }); jQuery(".mb_supershare_close").bind("click", function() { jQuery(".mb_supershare_modalDialog").fadeOut("slow"); $is_closed="yes"; setTimeout(function() { jQuery(".mb_supershare_modalDialog").css({"display":"none"}); }, 2000); }); }); </script> <script type="text/javascript" src="" id="swv-js"></script> <script type="text/javascript" id="contact-form-7-js-extra"> /* <![CDATA[ */ var wpcf7 = {"api":{"root":"https:\/\/\/wp-json\/","namespace":"contact-form-7\/v1"}}; /* ]]> */ </script> <script type="text/javascript" src="" id="contact-form-7-js"></script> <script type="text/javascript" src="" id="bxslider-js"></script> <script type="text/javascript" src="" id="ticker-js"></script> <script type="text/javascript" src="" id="mCustomScrollbar-js"></script> <script type="text/javascript" src="" id="mousewheel-js"></script> <script type="text/javascript" src="" id="profitmag-navigation-js"></script> <script type="text/javascript" src="" id="profitmag-keyboard-navigation-js"></script> <script type="text/javascript" src="" id="profitmag-custom-js"></script> <script type="text/javascript" src="" id="jail-js"></script> <script type="text/javascript" src="" id="scrolling-js-js"></script> <script type="text/javascript" src="" id="jquery-easing-js"></script> <script type="text/javascript" src="" id="slidedeck-library-js-js"></script> <script type="text/javascript" src="" id="slidedeck-public-js"></script> <script type="text/javascript" src="" id="twitter-intent-api-js"></script> <script type="text/javascript" id="fifu-json-ld-js-extra"> /* <![CDATA[ */ var fifuJsonLd = {"url":"https:\/\/\/sites\/default\/files\/styles\/640x360\/public\/images\/articles\/tenable-mrbeast-deepfake-tiktok-live-youtube-ad-scams.jpg?itok=kxcOFvAk"}; /* ]]> */ </script> <script type="text/javascript" src="" id="fifu-json-ld-js"></script> <script type="text/javascript"> var slideDeck2URLPath = ""; var slideDeck2iframeByDefault = false; </script> </body> </html>