Free guide

The Creator’s Guide to Not Getting Hacked

Contents

    The Contents bar stays at the top of your screen, so you can jump to any part at any time.

    Your creator business can be stolen in an afternoon

    You built an audience one post, one issue, one subscriber at a time. A single stolen password can take it all in an afternoon: your list, your channel, your income, your name.

    This guide is the fix. It's free, it's plain English, and it's written for creators, not IT departments. I've spent 20+ years in cybersecurity (CISSP, CISM), and everything here is what I'd tell a friend who just started earning online.

    Start here: take the 5-minute checkup. Answer 10 yes/no questions and get a score plus a list of exactly which sections you need. Then pick your platform track for settings specific to how you publish.

    Prefer to read straight through? Part 1 covers the basics every creator needs. Part 2 has tracks for specific platforms.

    Part IKnow the risk

    Why creators get targeted

    Attackers don't need you to be famous. They need you to be reachable, valuable, and alone. Most creators are all three.

    • You're public. Your email, your sponsors, your tools, and often your schedule are visible to anyone who looks.
    • You're a one-person company. No IT team, no security review, no second set of eyes on a suspicious email.
    • Money moves through you. Sponsorships, payouts, and product sales make your accounts worth stealing.
    • Your audience is an asset. A hijacked account can scam your followers in your voice, or be sold outright.
    • Everything hangs on one inbox. Your email account resets the password on nearly every other account. Lose it, and you lose everything connected to it.
    Coming soon

    Real-world stories: 2–3 short, anonymized cases — a hijacked channel, a drained payout account, a stolen list.

    The good news: most attacks on creators are opportunistic. You don't have to be unhackable. You just have to get the basics right to be safe from the bad guys.

    Your threat map

    Your business runs on six kinds of accounts and devices. Your primary email sits in the middle, because it can reset almost everything else.

    AssetWhat an attacker getsWhy it matters
    Primary emailPassword resets for every other accountThe master key. Protect it first.
    Domain registrarYour domain, website, and business emailA stolen or expired domain can take your email down with it.
    Publishing platforms (newsletter, YouTube, social)Your audience and your voiceScams sent as you, or the account deleted or sold.
    Payment accounts (Stripe, PayPal, Gumroad)Your revenue and payout detailsPayouts redirected to the attacker's bank.
    Cloud storage and password managerFiles, contracts, every saved loginOne breach becomes many.
    Phone and computerSessions, codes, and saved passwordsA stolen or infected device bypasses most defenses.
    222221Attacker gets inPhishing email or reused passwordPrimary emailThe master keyPublishing platformsAudience & voicePayment accountsRevenue & payoutsPassword manager& cloud storagePhone & computerSessions & codesDomain registrarSite & business email
    1 An attacker gets into your inbox. 2 Every account that sends password resets to that inbox falls next.

    The pattern to remember: attackers get one account, then use it to reset the next. The basics below break that chain.

    Part IILock it down

    The essentials

    Do these in order. Level 1 alone stops most attacks on creators, and it takes about 30 minutes. Tick items off as you go — your progress is saved in this browser.

    Level 1: Do today (30 minutes)

    0 of 5 done

    Level 2: Do this week (1–2 hours)

    0 of 7 done

    Level 3: Do this month (half a day)

    0 of 3 done

    Team, VAs, and contractors

    Every person you give access to is another way in. Give each one their own login, only the access they need, and remove it the day they're done.

    • Never share your password. Use team seats or role-based access on your platforms. Where a platform has none, share through your password manager's sharing feature, not in chat or email.
    • Give the least access that works. An editor doesn't need billing. A VA scheduling posts doesn't need account ownership.
    • Keep ownership yourself. You should be the owner of your domain, email, payment, and publishing accounts, never a contractor.
    • Require MFA for anyone with access.
    • Offboard the same day. Remove their seats, revoke shared vault items, and change any password they could have seen.
    Coming soon

    Download: one-page onboarding and offboarding checklist.

    Part IIISpot the scams

    Scam field guide

    Most creator hacks don't start with hacking. They start with a message designed to get you to click, download, or log in.

    ScamWhat it looks likeThe tell
    Fake sponsorshipA brand offers a paid deal and sends a "contract" or "product demo" file.Attachments that are .exe, .scr, zipped, or ask you to "enable content." Real brands use DocuSign or a PDF.
    Fake platform notice"Copyright strike" or "account suspended" email with a link to appeal.The link goes to a lookalike domain. Check notices inside the app, never through the email.
    Collab baitA fellow creator wants to collaborate and needs you to test their app, game, or tool.Pressure to download or log in through their link. Often a hijacked account of someone you know.
    Invoice or payout fraudA sponsor "updates their bank details" or you get an invoice you didn't expect.Any change to where money goes. Confirm by phone or a known channel.
    Login page phishing"Your account needs verification" with a sign-in link.You shouldn't have to log in from an email. Go to the site directly.
    AI impersonationA voice note or video that sounds like a partner, editor, or family member asking for money or access.Urgency plus an unusual request. Call back on a number you already have.

    The one rule that stops most of these: never log in, download, or pay from a link someone sent you. Go to the site yourself.

    Part IVWhen it goes wrong

    I've been hacked: what to do now

    Move fast, work from a clean device, and secure your email first. Everything else depends on it.

    First hour

    1. Call your incident response contact. The person or company you lined up in Level 1. They can guide the steps below while you work.
    2. Switch to a device you trust. If you suspect malware, use a different phone or computer.
    3. Secure your primary email. Change the password, sign out all other sessions, and check forwarding rules and recovery info for anything you didn't add.
    4. Change your password manager password if you think it's exposed, and turn on MFA if it isn't already.
    5. Lock down money. Check payment accounts for changed bank details or new payouts. Contact the platform's support immediately if anything moved.

    First day

    1. Work outward from email. Reset passwords and sign out sessions on your domain registrar, publishing platforms, and cloud storage.
    2. Use the official recovery process for any account you can't get into. Coming soonLinks to each platform's recovery page — platform tracks cover the specifics.
    3. Warn your audience if the attacker posted or emailed as you. A short, calm note from a backup channel protects your followers and your reputation.
    4. Document everything. Screenshots, times, and emails. Platforms and banks will ask.

    First week

    1. Find how they got in — a phishing link, a reused password, a malicious file — and close that door.
    2. Finish Level 1 and 2 of the essentials if you hadn't.
    3. Update your recovery plan with what you learned.
    Coming soon

    "Still locked out or not sure what happened? Contact me."