The Fake Party Invitation That Spreads to Your Contacts
What's happening
The sender is authentic, the servers are authentic, and every security check passes — because the email isn't the trap. The link waiting behind the RSVP is.
In May 2000, a love letter brought the internet to its knees. The ILOVEYOU worm arrived as an email from someone you knew, and opening it mailed a copy to everyone in your Outlook address book. Twenty-six years later, the same trick is back — dressed as a party invitation.
It starts with an invite to a dinner party that looks like it came from Punchbowl, Evite, Paperless Post, or Partiful — and, crucially, appears to be from a real friend. The scam comes in two distinct forms:
- The counterfeit invite — a copycat email that only mimics the platform. The branding is borrowed, but the email actually comes from somewhere other than the platform's real domain, and clicking "view invitation" leads to a fake Google, Microsoft, or Yahoo login page built to steal your email password. Because the sender is fake, this version can be caught by checking the sender's email address and domain.
- The genuine invite, weaponized — a real invitation, created on the legitimate platform itself or sent directly from a friend's real, compromised email account. The sender is authentic, the servers are authentic, and every security check passes — because the email isn't the trap. The link waiting behind the RSVP is, and it leads to the same password-stealing page. This version can't be caught by checking the sender — only by checking with the host.
In Scamwise data we see both forms and this scheme is teetering on the verge of a viral epidemic and impacting all major online invite platforms with Punchbowl leading the pack as the most frequently hijacked brand. Scamwise is not alone, regulators around the country are picking up on the same wave as the FTC issued a consumer warning about fake party-invitation emails, and North Carolina's Department of Justice flagged the pattern in mid-June.
In all variants of this scam, email credentials are the goal. Email credentials can be the most valuable single credential a scammer can steal, because it often gives them a master key to discover other valuable accounts and unlock them through password resets tied to the stolen email account.
While the scammer is mining the stolen account for valuable information and access to other accounts they also propagate their scam to the contact list through more fake invites, giving themselves an ever-expanding trove of compromised users to exploit.
As we watch this trend, we're keeping an eye on the calendar — invitation volume will spike around things like the upcoming wedding season and winter holidays where it may be less strange to get an invite from a long-lost friend.
Second channel checks
When you want to be sure
- 1
Ask the host, not the invite.
You can check to make sure the invite comes from a legitimate domain like mail@mail.punchbowl.com but that will only catch one type of this scam. Better to always text or call the friend who "sent" it on a channel you already have: "Did you send me this?" Real hosts are glad you asked — and if they didn't send it, you've just warned them their account is compromised.
- 2
Never enter your email password to view an invitation.
Real invite platforms open the event right in your browser. Any invitation that takes you to a page appearing as a Google, Microsoft, or Yahoo login page is likely harvesting credentials.
- 3
If you've been hit or think you've been hit.
Immediately change your primary email password and turn on multi-factor authentication. Then change passwords associated with any platform that stores or moves your money and turn on MFA. Check your outbox for an invite that was sent with your compromised credentials and if it was, swallow your pride and send an email to the whole list. Tell them your inbox was compromised and that the invite was a fake and not to click. Don't overthink it, you don't need to say much more, people understand this happens.