Skip to content
“First in Revolution”

COMPUTERS 101: You are cordially invited ... to a scam

The author and her favorite party guest, Louis (who actually did not like martinis)

Table of Contents

I have received Paperless Post invitations in the past for legitimate gatherings, so when one came into my inbox a few weeks ago, I didn't think twice before clicking on it.

Fortunately, as soon as I was asked to log into my email account in order to view the invitation, I knew something was wrong.

It was a phishing scam, ie, an attempt by cybercriminals to steal sensitive information by pretending to be a trustworthy source, and apparently I'm far from the only person receiving one. The FTC issued a warning in May about a wave of fake online party invitations impersonating services such as Paperless Post and Evite. Paperless Post itself has also warned about an increase in these scams.

Here's how it works:

An image that looks like an online party invitation.
An image that looks like an online party invitation.

An invitation arrives in your inbox. It may look like one of the examples above.

The email appears to be from someone you know. It's possible you haven't heard from this person in a while, but that's not terribly unusual. The invitation looks legitimate, so it piques your interest.

What makes this scam particularly effective is that it doesn't necessarily have the usual warning signs. There is no mention of a Nigerian prince, no glaring spelling errors and no bizarre email address claiming to be your bank. What's worse, the invitation may appear to come from someone you actually know.

What happens when you click?

The fake invitation is designed to get you to take one more step.

You may be told that you need to log into your email account to see the invitation. You might see what appears to be a Google or Microsoft login screen. Another variation asks for your phone number and then a verification code.

That's the point at which the scammer gets what they came for.

A legitimate invitation should not require you to enter your email password just to see who's having a party. If you enter your Google or Microsoft username and password into the fake page, you've potentially just handed the keys to your email account to a stranger.

Someone with access to your email could potentially use it to gain access to your other online accounts, read information in your inbox and impersonate you. They can also use your account (and your contact list) to send more convincing invitations.

Now the next person gets a party invitation that appears to be from you, and the scam continues ad nauseam.

It really appears to be from my friend's email address

This is where things get a little confusing. I often tell people to check the sender's email address before trusting a suspicious message. That's still excellent advice, but it isn't foolproof.

Email addresses can sometimes be "spoofed," meaning a scammer manipulates a message so that the From address appears to be someone else's. There's another possibility, though: your friend's email account may actually have been compromised. In that case, the message really can be coming from the account you recognize.

So don't assume an email is legitimate simply because you recognize the sender. Instead, consider whether the message itself makes sense. Would this person normally invite you to something? Does the invitation give you enough information to know what you're being invited to? Does anything about it strike you as odd?

When in doubt, there's an extraordinarily sophisticated piece of cybersecurity technology that I would recommend: Ask your friend.

Do not reply to the suspicious message. Call your friend or send a text message, or create a new email and ask, "Did you just send me an invitation?" Thirty seconds of awkwardness is considerably better than giving away your email password.

How can I tell whether a Paperless Post invitation is real?

Paperless Post gives some very specific guidance. A legitimate invitation will take you to Paperless Post's own website. You do not need to log into your email account or download a file to view it.

Paperless Post says its legitimate invitation links begin with paperlesspost.com, links.paperlesspost.com or pp.events.

That's worth remembering beyond Paperless Post, too.

Before entering a password on any website, look at the address bar at the top of your browser. A page can display a perfect Google logo and still have nothing whatsoever to do with Google.

The website address is one of the best clues to whether you're on a legitimate website or a fake one. Logos are easy to copy. Web addresses are harder to fake.

What if I already clicked?

First, clicking the invitation doesn't necessarily mean you've been hacked. If you clicked but didn't enter any information, close the page. Don't download anything it offers you.

If you entered your email password, however, act quickly.

Go directly to your email provider's website (ie, do not use a link from the invitation) and change your password. Make it a new password that you haven't used elsewhere, and make it as difficult as humanly possible.

Then turn on two-factor authentication if you haven't already. This requires a second form of verification when someone tries to log into your account and provides an important additional layer of protection.

Check your account for unfamiliar activity, too. Look at recent logins and devices connected to the account. Check your Sent folder for messages you didn't send.

And tell your contacts if necessary. If fake invitations have gone out under your name, a quick warning from you may keep somebody else from falling for one.

Most importantly, don't feel dumb. You are not alone. I responded to more than a dozen people who have recently received the invitation and went as far as attempting to log in as instructed. These scammers are appealing to our innate curiosity, and also the fact that we are asked to log in to sites all day long.

New rule: Verify the unexpected

Scammers are getting better at removing the things we've traditionally been taught to look for. The spelling may be perfect. The company logo may be real. The message may know your name. And the sender may appear to be someone you trust.

So perhaps the most useful question isn't, "Does this email look real?" It should now be, "Was I expecting this?"

An unexpected party invitation certainly could be legitimate. People do occasionally invite us to parties, after all. But if clicking that invitation suddenly leads to a request for your Google password, Microsoft password, verification code or other sensitive information, stop.

You can always call your friend to find out whether you're really invited.

And if you're not, at least you don't have to buy a present or make a potluck dish!

Latest