Indie developers and internet creators are under siege once again. A newly surfaced phishing campaign is actively making the rounds, this time turning its sights toward musicians and developers on the popular audio platform Bandcamp. If the structure of the attack sounds painfully familiar, it should—it bears an identical operational signature to the massive September 2025 Pixiv phishing scam that famously ensnared several high-profile targets, including the indie development studio Drillimation Systems.
Here is what you need to look out for, how the scam works, and why the internet hasn’t quite learned its lesson from last autumn.
The New Threat: Bandcamp “Verification” Exploits
The current wave of attacks relies heavily on abusing legitimate contact forms to bypass standard email spam filters. Creators are receiving urgent emails coming from noreply@bandcamp.com, which masks the malicious intent because the initial message delivery pipeline is technically authentic.
The emails claim that the platform’s security team has “registered several requests to your account from unknown devices” and demand immediate identity verification to prevent account suspension.
The Red Flag: The email includes a deceptive hyperlink disguised as an account rescue landing page, routing users to external lookalike domains such as
bandcampg.life. Once clicked, users are prompted to enter highly sensitive financial details, including debit card information and account balances.
Tracking the Source: Preliminary investigation into the network headers and associated IP addresses suggests that the campaign may have originated from the United Kingdom. However, cybersecurity experts note that the exact origin remains officially unknown, as the actors are likely routed through proxy systems or virtual private networks (VPNs) to mask their true location.
Echoes of September 2025: The Pixiv Lesson
For those with a short memory in tech security, this exact playbook cost Drillimation Systems a frantic weekend back in September 2025. During that incident, a bad actor impersonating Pixiv’s internal support system targeted the studio’s frontman, the Prophet Driller.
| Feature | The 2025 Pixiv Attack | The 2026 Bandcamp Attack |
| Initial Vector | Direct Messages on Pixiv | Bandcamp Contact Forms |
| The Hook | “Secure account via Multi-Factor Authentication” | “Verify identity due to unknown login attempts” |
| The Payload | Fraudulent external link stealing debit card data | Fraudulent external link (bandcampg.life) stealing banking data |
| The Target | Digital artists and indie game devs | Independent musicians |
In Drillimation’s case, the team luckily managed to lock and close the affected debit card before the hackers could leverage the classified access tools to damage company finances. The close call forced the studio to migrate the majority of its business payment infrastructure strictly over to PayPal to minimize exposure to direct credential theft.
Yet, less than a year later, the threat loop has simply shifted to a new creative marketplace.
How to Protect Your Account
If you are an active developer or musician using online storefronts, remember these absolute rules:
- Check the In-App Warning Banners: Platforms like Bandcamp explicitly add text to contact-form emails stating that the platform will never use this form to contact you directly.
- Never Trust External Links for Verification: If a site legitimately requires security modifications, such as setting up Multi-Factor Authentication (MFA), navigate directly to your account settings by typing the official URL into your browser yourself.
- Inspect the URL Bar: Scammers rely on fast-redirect code blocks and lookalike domains. If the domain doesn’t end strictly in
.bandcamp.com, close the tab immediately.
Have you noticed an uptick in suspicious security notices on your creator profiles lately? Let us know in the comments below.
Discover more from Drillimation Systems
Subscribe to get the latest posts sent to your email.

Very useful
LikeLike