The Kids Are All Right: Investigating the Susceptibility of Teens and Adults to YouTube Giveaway Scams

Elijah Bouma-Sims

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Phishing & Fraud 1 · Phishing & Fraud 1

Overview

This talk, presented by Elijah Bouma-Sims at the NDSS Symposium, delves into the pervasive issue of YouTube giveaway scams and critically examines the long-held assumption that minors are inherently more vulnerable to these deceptive tactics. Online fraud is a persistent and growing problem with significant economic and privacy impacts, often employing the lure of free goods or services to ensnare victims. Previous research has speculated that these scams might disproportionately affect minors, given that they often don't demand upfront payments but instead require tasks like providing sensitive information or downloading apps, ultimately delivering nothing while potentially leading to privacy invasion, spam, or malware.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to YouTube giveaway scams
  2. 1:10 Visualizing how YouTube giveaway scams operate
  3. 2:00 Unveiling the study's central research questions
  4. 4:40 First key finding: high scam recognition rates
  5. 5:20 Teens' vulnerability: exposure vs. inherent susceptibility
  6. 5:50 How teen interests increase scam encounter likelihood
  7. 6:50 Why checking comments for scam legitimacy is risky

The Kids Are All Right: Investigating the Susceptibility of Teens and Adults to YouTube Giveaway Scams

Speakers: Elijah Bouma-Sims

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=IsEbJH9nEyY

Overview

This talk, presented by Elijah Bouma-Sims at the NDSS Symposium, delves into the pervasive issue of YouTube giveaway scams and critically examines the long-held assumption that minors are inherently more vulnerable to these deceptive tactics. Online fraud is a persistent and growing problem with significant economic and privacy impacts, often employing the lure of free goods or services to ensnare victims. Previous research has speculated that these scams might disproportionately affect minors, given that they often don't demand upfront payments but instead require tasks like providing sensitive information or downloading apps, ultimately delivering nothing while potentially leading to privacy invasion, spam, or malware.

Bouma-Sims' research rigorously investigates this hypothesis through a scenario-based experiment designed to mimic the path of victimization. By comparing the responses of teenagers and adults to both legitimate and fraudulent YouTube content, the study aimed to understand how users reason about these scams, whether they recognize them as fraudulent, and what actions they recommend. The findings challenge conventional wisdom, revealing that while most users, regardless of age, are resistant to these scams, teens are significantly more likely to encounter them due to their interests, even if not more vulnerable to falling for them once encountered.

The work is crucial for several reasons: it provides empirical evidence to inform public awareness campaigns, guides platform-level interventions, and highlights the need to address the underlying infrastructure that enables these scams. By dissecting user reasoning and identifying unreliable heuristics, the research offers actionable insights for both individuals and organizations seeking to combat online fraud, emphasizing that the most effective solutions may lie in cracking down on scammers' ability to operate rather than solely relying on user vigilance.

Background

▶ Watch: Introduction to YouTube giveaway scams (0:00)

Online fraud has evolved into a sophisticated and ever-present threat, continually expanding in scale and impact. A common and particularly insidious lure employed by fraudsters is the promise of free goods or services. This tactic manifests across various platforms, from social media posts offering free iPads for completing surveys to the specific focus of this research: YouTube videos purporting to provide free access to premium services or in-game currencies. These giveaway scams typically direct users to external websites where they are asked to complete a series of tasks—such as filling out surveys, downloading apps, or providing personal information—under the guise of "human verification." The ultimate outcome for the user is always the same: no promised reward, only wasted time, potential privacy breaches, subsequent spam, or even the installation of unwanted programs or malware.

Prior work and widespread public concern have often speculated that minors might be particularly susceptible to these types of scams. The reasoning behind this concern is multifaceted: minors may have less disposable income, making the allure of "free" goods more potent; they might possess less experience in navigating complex online environments; and they may have a less developed understanding of the risks associated with providing personal data or downloading unknown applications. However, this speculation largely lacked robust empirical validation. The research presented here sought to fill this gap by conducting a detailed investigation into whether minors genuinely exhibit greater vulnerability compared to adults when confronted with these YouTube giveaway scams. This context sets the stage for a deeper exploration into user reasoning, behavioral differences between age groups, and the broader ecosystem enabling these fraudulent activities.

Key Findings

▶ Watch: Unveiling the study's central research questions (2:00)

The study yielded several critical insights that challenge existing assumptions and provide a nuanced understanding of user susceptibility to YouTube giveaway scams.

Firstly, a significant majority of participants demonstrated resistance to these scams, recognizing them as fraudulent. Across all presented videos, approximately 90% of participants correctly identified the content as a scam. However, the perceived convincingness of the scams varied, with the most convincing scam still fooling 17% of participants, while the least convincing only deceived 2%. This highlights that while general awareness is high, the design and presentation of the scam stimuli play a role in its effectiveness.

Contrary to prior speculation, the research found no evidence that teens were more vulnerable than adults to falling for these scams upon viewing them. Both age groups exhibited similar rates of scam recognition and recommended similar actions. However, a crucial distinction emerged: teens were significantly more likely to report having searched for terms commonly associated with these scams. For instance, 39% of teens reported previously searching for "free Robux," compared to only 6% of adults. This suggests that while teens may not be inherently less discerning, their interests and potential lack of money make them more prone to encountering these scams in the first place.

When asked what action they would recommend to a friend, most participants suggested simply exiting the video and avoiding further interaction. Interestingly, a substantial number of participants, both teens and adults, recommended checking the comments section of the video to verify its legitimacy. This is identified as a potentially unreliable heuristic, as many scam videos feature fake attestations and manipulated comments designed to provide false social proof.

A positive finding was that teens were significantly more likely to recommend reporting the video to YouTube compared to adults, with 21% of teens suggesting this action versus only 4% of adults. The motivation for teens often stemmed from a desire to "protect others from making bad decisions." In contrast, some adults expressed a sense of disenchantment, viewing reporting as "fighting an uphill battle that have little or no effect."

Participants' reasoning for rejecting scams primarily centered on the need to perform tasks (e.g., surveys, app downloads), which many recognized as a common characteristic of fraudulent schemes. Some also cited specific security and privacy risks, such as the danger of downloading random apps leading to viruses. Others disengaged simply because the process seemed like "too much hassle." Finally, aesthetic qualities of the website played a role, with participants often rejecting scams if the website "looks old and clunky," though this too is an unreliable heuristic as sophisticated scammers can create convincing interfaces.

In summary, while most users are scam-resistant, they often rely on potentially flawed reasoning. Teens are not more vulnerable but are more exposed due to their interests. The study underscores the need for proactive measures by platforms and a deeper understanding of the scam ecosystem.

Technical Deep Dive

▶ Watch: First key finding: high scam recognition rates (4:40)

The core of this research involved a meticulously designed scenario-based experiment crafted to simulate the real-world experience of encountering YouTube giveaway scams. This methodology was crucial for ethically studying victimization without exposing participants to actual harm.

Stimuli Collection: The researchers began by identifying both legitimate and fraudulent YouTube videos related to common "free" offers. This was achieved through organic searches on YouTube using terms like "free Spotify Premium" and "free Roblox Robux." This approach ensured that the stimuli presented to participants were representative of what real users would encounter. Each participant was then randomly assigned to view one of six scam videos and one of six legitimate videos on the same topic, allowing for a direct comparison of responses.

Experimental Procedure:

  1. Scenario Introduction: Participants were presented with a scenario where they were with a friend who had just searched for one of the target terms (e.g., "free Spotify Premium").
  2. Video Viewing: They then viewed a full YouTube video, either legitimate or a scam, related to their friend's search.
  3. Action Recommendation: After watching the video, participants were asked to recommend an action to their friend. This open-ended question captured their immediate reaction and understanding.
  4. Website Interaction Simulation: Crucially, for safety and ethical reasons, participants were not directed to the actual scam websites. Instead, they were shown a screen recording of someone navigating the scam website, clicking through the various "human verification" steps, and experiencing the typical endless loop of surveys. This allowed researchers to gauge participants' perceptions of fraud at the second stage of victimization (the website interaction).
  5. Post-Stimuli Questions: After viewing all stimuli, participants were asked directly whether they thought the content was a scam or not. This question was placed at the end to avoid biasing their earlier responses.

Participant Recruitment and Demographics:

  • Teenagers: Recruited through flyers distributed to parents to ensure parental consent, adhering to ethical guidelines for research involving minors.
  • Adults: Recruited from Prolific, a crowd-working platform. The researchers acknowledged that Prolific users, being accustomed to surveys, might have a different perception of such online content, which was considered during analysis.
  • Demographic Data: Before and after the survey, participants completed demographic and behavioral questions, including prior search history for the target terms and household income (though no statistically significant differences were found based on income, partly due to reporting biases and recruitment methods like snowball sampling and broader distribution via Peachjar).

Data Analysis: Statistical testing was performed to assess the effect of age and other variables on the actions participants recommended and their final scam recognition judgment. The researchers looked for statistically significant differences in behavior and reasoning between teens and adults.

Scam Infrastructure and Ecosystem (from Q&A): While the primary study focused on user perception, the Q&A session brought to light a critical technical aspect: the scam ecosystem. The speaker mentioned that these types of scams rely on a sophisticated infrastructure beyond just YouTube. Key components include:

  • Cost-per-action (CPA) advertising providers: These are the monetization backbone for many scams. Scammers earn commissions when users complete tasks (like downloading apps or filling out surveys) through these CPA networks. Some providers are "actively involved" and "know people are committing fraud," suggesting a complicit or negligent role.
  • Service providers: Obvious ones like Cloudflare (for website hosting/protection) and Amazon Web Services (AWS) are used to host the scam websites.
  • Account acquisition: Scammers leverage vast numbers of hijacked or newly created accounts to post fraudulent videos, making it an "uphill battle" for platforms to keep up.

Understanding this technical infrastructure is crucial for developing effective defensive strategies, moving beyond just user education to targeting the systemic enablers of fraud.

Demo / Proof of Concept

▶ Watch: How teen interests increase scam encounter likelihood (5:50)

This research presented a scenario-based experiment rather than a live technical demonstration or a traditional proof of concept. The "demo" aspect was integrated into the study's methodology to ethically simulate the user's journey through a scam.

Instead of directly interacting with live malicious websites, participants were shown screen recordings of someone navigating the fraudulent pages. This approach served as a controlled and safe way to expose participants to the visual and interactive elements of a scam website—such as the "human verification" steps, the requests to download apps, or the endless loop of surveys—without putting them at risk of malware infection, privacy compromise, or actual financial loss. The screen recordings effectively demonstrated how the scam worked from the victim's perspective, allowing researchers to gather data on participant perceptions and reasoning at this crucial second stage of victimization. While not a live "hack," this simulated experience was a core component of the experimental design, enabling the study to investigate user responses to the full victimization path in a secure environment.

Defensive Implications

▶ Watch: Why checking comments for scam legitimacy is risky (6:50)

The findings from this research offer several critical defensive implications for individuals, platforms, and the broader security community.

  1. Platform-Level Intervention is Paramount: The most significant implication is that relying solely on user vigilance is insufficient. As highlighted by the speaker, the "best solution is to crack down on scammers' ability to post on YouTube." This requires platforms like YouTube to invest more heavily in proactive detection and removal of fraudulent content. This includes improving automated detection systems for scam videos, links, and associated accounts, as well as more robust moderation efforts. The challenge of scammers acquiring "thousands and thousands of accounts" through hijacking or other means underscores the need for continuous innovation in platform security.
  1. Targeting the Scam Ecosystem: The discussion revealed that YouTube giveaway scams are not isolated incidents but part of a larger, interconnected ecosystem. A key defensive strategy involves disrupting this ecosystem by targeting cost-per-action (CPA) advertising providers. These providers are the primary monetization method for many scammers, as they earn commissions when users complete tasks. Identifying and sanctioning CPA networks that knowingly or negligently facilitate fraud could significantly cripple scammers' ability to profit. Furthermore, upstream providers like Cloudflare and Amazon Web Services (AWS), which host scam infrastructure, should be engaged to implement stricter content policies and quicker takedown procedures for verified fraudulent sites.
  1. Refining User Education and Awareness: While most users recognize scams, their reasoning often relies on unreliable heuristics. Defenders need to educate users on these pitfalls:
  • Beware of comments sections: Users should be explicitly warned that scam videos often feature fake attestations and manipulated comments to create false social proof. Relying on comments to verify legitimacy is a dangerous practice.
  • Aesthetics are deceiving: While "old and clunky" websites might be obvious scams, sophisticated fraudsters can create highly convincing and modern-looking interfaces. Users should be taught that a professional-looking website does not equate to legitimacy.
  • Focus on the "task" red flag: The most consistent indicator for participants was the requirement to complete arbitrary tasks (surveys, app downloads) for a promised reward. Emphasizing this as a primary red flag can be highly effective.
  1. Motivating Reporting and Addressing Disenchantment: The study found that teens are significantly more likely to report scams, often driven by altruistic motives. Platforms should explore ways to harness and expand this willingness across all age groups. This could involve making the reporting process simpler, more transparent, and providing feedback to users on the impact of their reports. Addressing the "disenchantment" felt by some adults who believe reporting is ineffective is crucial for increasing reporting rates. Demonstrating that reports lead to tangible actions could re-engage these users.
  1. Addressing Root Causes for Vulnerable Populations: While teens are not more vulnerable to falling for scams, they are more prone to encountering them due to their interests (e.g., "free Robux") and potential lack of disposable income. This suggests a need for broader educational initiatives that go beyond just scam recognition, perhaps addressing financial literacy or safe alternatives for accessing desired content, thereby reducing the initial allure of "free" offers.

In essence, a multi-pronged defensive strategy is required, combining robust platform-level enforcement and ecosystem disruption with targeted, evidence-based user education that addresses specific unreliable reasoning patterns and encourages proactive reporting.

Key Takeaways

  • Teens are not inherently more vulnerable to YouTube giveaway scams than adults when presented with them, demonstrating similar rates of scam recognition.
  • **Teens are significantly more likely to encounter these scams** due to their specific interests (e.g., "free Robux") and desire for free access to content or services.
  • Most users recognize giveaway scams, with approximately 90% identifying them as fraudulent, but the effectiveness varies based on the scam's convincingness.
  • Users often rely on unreliable heuristics like checking comments for social proof or judging a website's legitimacy based on its aesthetic qualities, which can be easily manipulated by scammers.
  • Teens are more inclined to report scam videos to YouTube (21% of teens vs. 4% of adults), often motivated by a desire to protect others, indicating a potential avenue for increasing platform defense.
  • Effective defense requires cracking down on the scam ecosystem, including platform-level content moderation and disrupting the monetization infrastructure provided by cost-per-action advertising providers and other service enablers.

About the Speaker(s)

Elijah Bouma-Sims presented this research at the NDSS Symposium. While his specific title and affiliation were not explicitly stated in the provided transcript or metadata, the nature of the work suggests he is a researcher deeply engaged in the study of online fraud, user behavior, and security vulnerabilities, particularly as they pertain to social platforms and different demographic groups. His presentation demonstrated a keen understanding of both the technical and human factors involved in online deception.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent empirical security research that punctures a common assumption — teens aren't more susceptible to YouTube giveaway scams, just more exposed. The methodology is sound and the findings are honest, but the contribution is narrow and the technical depth is shallow enough that this reads more like a social science conference paper than an NDSS submission.

Heather Calloway (CISO) — WEAK

Solid academic work on a real consumer harm problem, but it never makes the jump from behavioral research to institutional action. The finding that teens aren't more vulnerable than assumed is a useful corrective, but the defensive implications stay at the level of 'platforms should do more' without telling any specific actor what decision to make.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025