The independent agency world โ news, work, people and thinking.
Scam Alert: A Fake Media Brief Is Making the Rounds
An independent agency caught an imposter posing as a GoPro marketing manager, with a lookalike website and 1 file that gave it away.
An independent agency in the Indie Agency News membership received the kind of email new business teams hope for: a marketing manager at GoPro, looking for a media agency. The sender wasnโt from GoPro.
The agency caught it before any harm was done, then shared the details so other independents can recognize the approach.
What the approach looked like
The sender claimed to be a marketing manager at GoPro and wrote from an address at goproproduct[.]com (brackets added so the address canโt be clicked). GoProโs real domain is gopro.com.
The agency described the site at the lookalike address as a convincing duplicate of GoProโs own, with no redirect to the real one. Public WHOIS records show the domain was registered on 26 September 2026 through Cloudflare โ less than two weeks before the agency raised the alarm.
The checks that raised doubts
The agency looked for the contact in ZoomInfo, on GoProโs own channels and through Google. Nothing tied the name to the company.
When the agency raised that, the sender had what it called a clever explanation. The team stayed skeptical.
Next came a link to a portfolio of assets โ still images, videos and logos, well organized and consistent with GoProโs new brand platform. Every file looked legitimate except one.
The file that gave it away
That file ended in .scr, the extension for a Windows screensaver. The agency replied that it couldnโt open the file and asked for a PDF instead.
The sender appeared not to understand the request, then stopped responding.
The file was never opened, so what it contained is unknown. The format is the warning sign: a .scr file is a program, and Windows runs it like any other application.
Why a screensaver file matters
In February, researchers at ReliaQuest documented a phishing campaign built on this file type. Business-themed emails โ an invoice, a project summary โ linked to .scr files hosted on cloud storage.
Opening one installed a remote management tool that gave outsiders ongoing control of the computer, Alexander Culafi reported for Dark Reading. The researchersโ point: many people donโt know a screensaver file can run code, and security tools donโt always treat it with the caution they give a standard program file.
The format runs on Windows, not macOS. Plenty of agencies have both in the building.
Part of a wider pattern
Brand impersonation aimed at marketing people isnโt limited to agencies. On 7 October, Christian Ali Bravo of ESETโs WeLiveSecurity detailed a campaign posing as Nike, Spotify and Hollyland to offer YouTube creators sponsorship deals, with a professional-looking partner site built to capture logins.
The common thread is a real brand name, a credible business reason and a web address that sits close to the real thing. A prospective client with a famous logo is the email an agency most wants to believe.
What agencies can do
- Read the senderโs domain character by character and compare it with the brandโs real one.
- Look up the domainโs registration date with a free WHOIS search. A global brand writing from a domain registered last month is a warning sign.
- Confirm the contact through a route you find yourself โ the brandโs main site, a known contact or a LinkedIn profile with real history.
- Leave unexpected .scr and .exe files unopened, whatever folder they arrive in.
- Brief the people most likely to receive these emails: new business, media and account leads.
If someone has opened a file from a sender like this, disconnect that computer from the network and bring in IT support the same day.
Agencies in the U.S. can report an approach like this to the FBIโs Internet Crime Complaint Center and the Federal Trade Commission.
Learn more
Dark Reading: Windows screensavers used to deliver malware and remote access tools
ReliaQuest: Threat Spotlight on the screensaver campaign
WeLiveSecurity: Inside a brand deal scam aimed at YouTube creators
FBI Internet Crime Complaint Center
FTC ReportFraud