Technology

You’re Invited! (No, You’re Not.) It’s the Latest Phishing Scam.

You're Invited! (No, You're Not.) It's the Latest Phishing Scam.

When John Lantigua, a retired journalist in Miami Beach, checked his email one recent morning, he was glad to see an invitation.

“It was like, ‘Come and share an evening with me. Click here for details,’” Mr. Lantigua said.

It appeared to be a Paperless Post invitation from someone he once worked with at The Palm Beach Post, a man who had left Florida for Mississippi and liked to arrange dinners when he was back in town.

Mr. Lantigua, 78, clicked the link. It didn’t open.

He clicked a second time. Still nothing.

He didn’t realize what was going on until a mutual friend who had received the same email told him it wasn’t an invitation at all. It was a scam.

Phishing scams have long tried to frighten people into clicking on links with emails claiming that their bank accounts have been hacked, or that they owe thousands of dollars in fines, or that their pornography viewing habits have been tracked.

The invitation scam is a little more subtle: It preys on the all-too-human desire to be included in social gatherings.

The phishy invitations mimic emails from Paperless Post, Evite and Punchbowl. What appears to be a friendly overture from someone you know is really a digital Trojan horse that gives scammers access to your personal information.

“I thought it was diabolical that they would choose somebody who has sent me a legitimate invitation before,” Mr. Lantigua said. “He’s a friend of mine. If he’s coming to town, I want to see him.”

Rachel Tobac, the chief executive of SocialProof Security, a cybersecurity firm, said she noticed the scam last holiday season.

“Phishing emails are not a new thing,” Ms. Tobac said, “But every six months, we get a new lure that hijacks our amygdala in new ways. There’s such a desire for folks to get together that this lure is interesting to people. They want to go to a party.”

Phishing scams involve “two distinct paths,” Ms. Tobacco added. In one, the recipient is served a link that turns out to be dead, or so it seems. A click activates malware that runs silently as it gleans passwords and other bits of personal information. In all likelihood, this is what happened when Mr. Lantigua clicked on the ersatz invitation link.

Another scam offers a working link. Potential victims who click on it are asked to provide a password. Those who take that next step are a boon to hackers.

“They have complete control of your email and, in turn, your entire digital life,” Ms. Tobacco said. “They can reset your password for your dog’s Instagram account. They can take over your bank account. Change your health insurance.”

Digital invitation platforms are trying to combat the scam by publishing guides on how to spot fake invitations. Paperless Post has also set up an email account — phishing@paperlesspost.com — for users to submit messages for verification. The company sends suspicious links to the Anti-Phishing Working Group, a nonprofit that maintains a database monitored by cybersecurity firms. Flagged links are rendered ineffective.

The scammers’ new strategy of exploiting the desire for connection is infuriating, said Alexa Hirschfeld, a founder of Paperless Post. “Life can be isolating,” Ms. Hirschfeld said. “When it looks like you’re getting an invitation from someone you know, your first instinct is excitement, not skepticism.”

Olivia Pollock, the vice president of brand for Evite, said that fake invitations tended to be generic, promising a birthday party or a celebration of life. Most invitations these days tend to have a specific focus — mahjong gatherings or book club talks, for instance. “The devil is in the details,” Ms. Pollock said.

Because scammers don’t know how close you are with the people in your contact list, fake invitations may also seem random. “They could be from your business school roommate you haven’t spoken to in 10 years,” Ms. Hirschfeld said.

Alyssa Williamson, who works in public relations in New York, was leaving a yoga class recently when she checked her phone and saw an invitation from a college classmate.

“I assumed it was an alumni event,” Ms. Williamson, 30, said. “I clicked on it, and it was like, ‘Enter your email.’ I didn’t even think about it.”

Later that day, she received texts from friends asking her about the party invitation. she had just sent out. Her response: What party?

“The thing is, I host a lot of events,” she said. “Some knew it was fake. Others were like, ‘What’s this? I can’t open it.'”

Andrew Smith, a graduate student in finance who lives in Manhattan, received what looked like a Punchbowl invitation to “a memory making celebration.” It appeared to have come from a woman he had dated in college. He received it when he was having drinks at a bar on a Friday night — “a pretty insidious piece of timing,” he said.

“The choice of sender was super clever,” Mr. Smith, 29, noted. “This was somebody that would probably get a reaction from me.”

Mr. Smith seized on the phrase “memory making celebration” and filled in the blanks. He imagined that someone in his ex-girlfriend’s immediate family had died. Perhaps she wanted to restart contact at this difficult moment.

Something saved him when he clicked a link and tried to tap out his personal information — his inability to remember the password to his email account. The next day, he reached out to his ex, who confirmed that the invitation was fake.

“It didn’t trigger any alarm bells,” Mr. Smith said. “I went right for the click. I went completely animal brain.”

The new scam comes with an unfortunate side effect, a suspicion of invitations altogether. It’s enough to make a person antisocial.

“Don’t invite me to anything,” Mr. Lantigua, the retired journalist, said, only half-joking. “I’m not coming.”

#Youre #Invited #Youre #Latest #Phishing #Scam

Leave a Reply