How it works

Creators do get real work through marketplaces such as Aspire, GRIN, and similar platforms, which is exactly what makes this convincing. The email claims a named brand added you to a campaign and that a payment or contract is waiting once you log in to accept. The link goes to a clone of the platform's sign-in page, or to a "sign in with Google" step, hosted on a domain that is close to the real one but not the real one. You enter your credentials to see the offer, and they are captured. On real platforms the money and the campaign live inside your existing account, reached by logging in the normal way, not by a link in a cold email.

The domain is the giveaway. Attackers register names that bolt words onto the platform, like the platform name followed by "-payments" or "-creators," or the right name on the wrong ending. Aspire's real address is aspire.io, so a link to aspire-campaigns.com or aspireiq-login.net is not Aspire.

The tell-tale signals

What to do

Do not use the login link. If you already have an account on the platform, open it the way you normally do, by typing the address or using your saved bookmark, and look for the campaign there. If there is no such campaign, the email is a scam. If you do not have an account, a real brand that wants to work with you can confirm the deal from its own company domain. For any platform, verify the exact domain before you sign in, and prefer a passkey so a cloned page cannot capture a reusable password. LegitSponsor flags a lookalike or added-word domain against the platform's real one and shows you the evidence.