05/30/2026
๐๐๐ถ๐๐ฒ ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐ฆ๐ฐ๐ฎ๐บ
Phishing scams come in many forms, and attackers regularly swap out the bait. The latest version uses fake digital invitations to steal credentials or take over your computer entirely.
The setup is simple. An email or text arrives appearing to come from a legitimate invitation platform. Evite, Paperless Post, and Punchbowl are the most frequently impersonated. A friend's name is listed as the host. The design looks authentic. Security researchers tracked the campaign's infrastructure back to December 2025 and identified around 80 phishing domains and 160 suspicious links, all built to spoof familiar "Sign in with Google" and "Sign in with Microsoft" login screens. The Federal Trade Commission issued a consumer alert on May 26, 2026, flagging it as one of the more widespread phishing efforts currently circulating.
๐ง๐๐ผ ๐ฉ๐ฒ๐ฟ๐๐ถ๐ผ๐ป๐ ๐ถ๐ป ๐๐ถ๐ฟ๐ฐ๐๐น๐ฎ๐๐ถ๐ผ๐ป
๐๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ง๐ต๐ฒ๐ณ๐
Some fake invitations ask you to enter your email username and password to view event details. Others ask for a phone number and a verification code to RSVP. Real invitation platforms do not work this way. Once scammers have your login, they search your email for banking details, initiate password resets, and intercept the login codes sent back to your now-compromised account.
๐ฅ๐ฒ๐บ๐ผ๐๐ฒ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
A second variant goes further. Clicking the link redirects victims to download a file, often named something like RSVPPartyInvitationCard[.]msi. The page auto-triggers the download to reduce hesitation. The file is not an invitation. It installs ScreenConnect, a legitimate remote support tool, silently in the background. Once installed, attackers have the same level of access to the machine as a remote IT technician. The first signs are often unexplained cursor movement, windows opening on their own, or a software process the user does not remember installing.
๐ฅ๐ฒ๐ฑ ๐๐น๐ฎ๐ด๐
- Any invitation asking you to log in before viewing it
- A prompt to enter a phone number and share a verification code to RSVP
- A link delivering a file download to view an invitation
- A sender address not matching the official platform domain
- Unexpected invitations from people you have not been in contact with recently
๐๐ณ ๐ฌ๐ผ๐ ๐๐น๐ถ๐ฐ๐ธ๐ฒ๐ฑ
If you entered credentials, change your email password immediately, enable two-factor authentication, and check your financial accounts. Contact your bank right away if anything looks off.
If you downloaded and opened an attachment, disconnect from the internet and run a full malware scan. ScreenConnect installations persist and give attackers ongoing access, so consider getting professional help to confirm the machine is clean.