Scam Alert: A Fake Media Brief Is Making the Rounds

An independent agency caught an imposter posing as a GoPro marketing manager, with a lookalike website and 1 file that gave it away.

An independent agency in the Indie Agency News membership received the kind of email new business teams hope for: a marketing manager at GoPro, looking for a media agency. The sender wasnโ€™t from GoPro.

The agency caught it before any harm was done, then shared the details so other independents can recognize the approach.

What the approach looked like

The sender claimed to be a marketing manager at GoPro and wrote from an address at goproproduct[.]com (brackets added so the address canโ€™t be clicked). GoProโ€™s real domain is gopro.com.

The agency described the site at the lookalike address as a convincing duplicate of GoProโ€™s own, with no redirect to the real one. Public WHOIS records show the domain was registered on 26 September 2026 through Cloudflare โ€” less than two weeks before the agency raised the alarm.

The checks that raised doubts

The agency looked for the contact in ZoomInfo, on GoProโ€™s own channels and through Google. Nothing tied the name to the company.

When the agency raised that, the sender had what it called a clever explanation. The team stayed skeptical.

Next came a link to a portfolio of assets โ€” still images, videos and logos, well organized and consistent with GoProโ€™s new brand platform. Every file looked legitimate except one.

The file that gave it away

That file ended in .scr, the extension for a Windows screensaver. The agency replied that it couldnโ€™t open the file and asked for a PDF instead.

The sender appeared not to understand the request, then stopped responding.

The file was never opened, so what it contained is unknown. The format is the warning sign: a .scr file is a program, and Windows runs it like any other application.

Why a screensaver file matters

In February, researchers at ReliaQuest documented a phishing campaign built on this file type. Business-themed emails โ€” an invoice, a project summary โ€” linked to .scr files hosted on cloud storage.

Opening one installed a remote management tool that gave outsiders ongoing control of the computer, Alexander Culafi reported for Dark Reading. The researchersโ€™ point: many people donโ€™t know a screensaver file can run code, and security tools donโ€™t always treat it with the caution they give a standard program file.

The format runs on Windows, not macOS. Plenty of agencies have both in the building.

Part of a wider pattern

Brand impersonation aimed at marketing people isnโ€™t limited to agencies. On 7 October, Christian Ali Bravo of ESETโ€™s WeLiveSecurity detailed a campaign posing as Nike, Spotify and Hollyland to offer YouTube creators sponsorship deals, with a professional-looking partner site built to capture logins.

The common thread is a real brand name, a credible business reason and a web address that sits close to the real thing. A prospective client with a famous logo is the email an agency most wants to believe.

What agencies can do

  • Read the senderโ€™s domain character by character and compare it with the brandโ€™s real one.
  • Look up the domainโ€™s registration date with a free WHOIS search. A global brand writing from a domain registered last month is a warning sign.
  • Confirm the contact through a route you find yourself โ€” the brandโ€™s main site, a known contact or a LinkedIn profile with real history.
  • Leave unexpected .scr and .exe files unopened, whatever folder they arrive in.
  • Brief the people most likely to receive these emails: new business, media and account leads.

If someone has opened a file from a sender like this, disconnect that computer from the network and bring in IT support the same day.

Agencies in the U.S. can report an approach like this to the FBIโ€™s Internet Crime Complaint Center and the Federal Trade Commission.


Learn more

Dark Reading: Windows screensavers used to deliver malware and remote access tools
ReliaQuest: Threat Spotlight on the screensaver campaign
WeLiveSecurity: Inside a brand deal scam aimed at YouTube creators
FBI Internet Crime Complaint Center
FTC ReportFraud

Share your love