This week our scanners caught two phishing emails dressed up as brand sponsorship offers — one impersonating Razer, one impersonating Corsair. Different brands, same script. If you get a "partnership" email that feels a little too good and a little too fast, here's what to look for.
The tell-tale signs we found
- Lookalike domains, not real ones. One email came from razer-brandpartners-offers.xyz — not Razer's actual domain. The .xyz ending combined with extra words like "brandpartners" is a classic impersonation pattern. Real brands email from their real, well-known domains.
- Replies go somewhere else entirely. In the Corsair-style email, the sender address was corsair-creator-offers.top, but replies were routed to brand-payout-service.ru — a completely different domain. That mismatch is a strong sign the "brand" you think you're talking to isn't who actually reads your response.
- A ticking clock. Both emails leaned hard on urgency: "act now," "act immediately," "within 24 hours." Scammers want you moving fast, not thinking clearly. Legitimate sponsors don't rush you to sign a contract before lunch.
- A shortened link hiding the destination. Both messages used bit.ly links instead of a direct, visible URL — in one case leading to what was framed as a "partnership contract." Shorteners aren't inherently evil, but in a cold sponsorship pitch, they're a convenient way to mask a credential-harvesting or malware page until it's too late.
What to actually do
If a sponsorship email shows up out of the blue with a big number attached and a deadline attached to it, slow down on purpose. Here's a quick gut-check:
- Look at the actual sending domain, not just the display name. Hover, don't click.
- Check whether the reply-to address matches the sender. If it doesn't, that's a red flag on its own.
- Never sign a contract or open a document link from a shortened URL you can't verify. Ask the brand to send it directly, or search for the brand's official partnerships contact and confirm through that channel.
- Real brand deals almost never require a signature within hours. Urgency is a pressure tool, not a business norm.
Nothing scary happened here — these two emails were caught before they reached anyone's inbox action. But the pattern is worth knowing, because it's clearly being reused across different "brands." If it happened with Razer and Corsair this month, it can happen with the next big name tomorrow.
A small note from us: this digest is based on real attacker patterns Securoly caught during scans over the past 30 days — not a prediction of what's coming next, just what's already out there.