As the calendar turns to summer, many of us are getting texts and emails inviting us to end-of-school gatherings, graduations, retirements, and pool parties. These convenient digital invites make it easy to connect with friends and family, school classmates, or coworkers, but they also come with a risk this year: a phishing scam.
“You’re Invited” has become the latest phishing scam, according to the Federal Trade Commission. The scam is designed to trick partygoers into opening the fake invitations, which are used to gain access to their login credentials, passwords and personal information. Eventually, the access gives hackers a chance to gather data and access credit cards and banking information.
Let’s examine this new phishing threat and how you can avoid getting tricked this summer.
Anatomy of the Scam
The main features of this phishing scam include an invitation that arrives on your device via text or email. How exciting! It’s an invitation to a party that starts “You’re Invited!” What could be better than an invitation from a friend to attend a party?
Sadly, this scam has a copycat component that mimics the platforms users are accustomed to receiving invitations from, like Evite or Paperless Post. The copycat branding can immediately trick users into thinking they are dealing with a legitimate vendor. Since party invitations are often unexpected, this scam relies on the fact that users will get the invite and immediately open it to see what the event is. Some subject lines may include the name of someone you know or an organization you are affiliated with, thereby lending credibility to the message.
The second component of this phishing scam is the Fake Login Screen. Again, it may look similar to previous logins you have used for these online sites, but rather than accepting your current login credentials, it asks you to reset your account information, thus giving the hackers the ability to log into your email account and then send the same text/email to everyone in your contact list. Once a hacker has made their way into your account, they can use the information to drain your bank accounts or utilize your credit cards.
Red Flags: Spotting the Fake Invite Before Clicking
To avoid falling victim to this scam, look for the following red flags that could prevent you from giving away vital login credentials.
- Visual clues such as mismatched or pixilated logos
- Fonts that look out of place or change sizes halfway through the message
- Awkward text alignments or weird, uneven spacing
Be on the lookout for invitations from people you don’t know or unexpected invitations from friends who have not talked about hosting, as well as actions such as being asked for a password/code to RSVP. If you click a link and cannot see the party details, that is also a red flag to delete the invite and go directly to the sender for information. If a password reset is requested, think before you type. Did you really forget your password, or are you being tricked?
Immediate Action Steps: What to Do If You Already Fell for It
If you have already fallen for this trick, immediately change your passwords and login credentials to something strong. You should also alert the people on your contact list so they know not to open any invites you send. Additionally, check your financial and bank accounts for unauthorized transactions and report the incident to IdentityTheft.gov and ReportFraud.ftc.gov.
This latest phishing scam is a social engineering attack that uses digital invitations sent via text or email, often disguised with copycat branding from legitimate platforms like Evite or Paperless Post. To ensure your business and personal accounts are protected from sophisticated phishing and other cyber threats, contact Spectra Networks for expert cybersecurity guidance and proactive defense strategies.
Visit the Spectra Networks site or call us at 978.219.9752 today to discuss tailored security solutions for your organization.
