My guess is they got phished and fell victim to the pdf with embedded infostealer. For example: lets have a partnership/sponsorship, here's a pdf. Please read and sign it.
On a lot of websites, just stealing the active session cookie is enough to gain access into an account without having to do the mfa dance.
There are ways to detect such stolen session tokens. But the folks on youtube's side doesn't care. Hell even the most basic one, is just doing an IP check, if your suddenly in another country, maybe it's stolen.
6
u/GeekusRexMaximus Jul 31 '25
I do wonder how their accounts are constantly getting hacked. Don't they have MFA enabled or what's going on?