Skip to content

Product1 publisher2 min readPublished

FTC warns that fake Evite and Paperless Post invitations are phishing for email passwords

FTC warned in May that fake Evite and Paperless Post invitations ask people for their email password, or a phone number and code to RSVP. One reached journalist Eric Umansky's contacts in his own name. Team guidance works best when it targets the request for credentials.

The Product Desk · Product desk

Photograph accompanying FTC warns that fake Evite and Paperless Post invitations are phishing for email passwords
Photo: wired.com

What happened

  • People who knew journalist Eric Umansky got a Paperless Post invite in his name for a "Special Private Dinner Party" at 7 pm on May 2, and he had never sent it.
  • In May, after a rise in reports, the FTC issued a consumer alert about fake messages made to look like invitations from Evite or Paperless Post.
  • According to the FTC, some of the fakes ask for an email username and password before showing event details, while others ask for a phone number and a special code to RSVP.
  • Umansky had two-factor authentication on his email and was still not sure how the invite came to go out under his name.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure Colleagues in an affected person's address book receive the lure under a name they trust, so advice to distrust unfamiliar senders does not protect them.
  • constraint Until someone establishes how the invite went out in Umansky's name, a team cannot tell staff which account setting would have stopped it.
  • decision Invitation guidance now has to choose between asking staff to judge the sender and simply forbidding them to hand over a password or code, because the sender can be someone they know.

Umansky's first response was a status update. He posted on Facebook, LinkedIn and his other social networks to tell people he was not having a party and, more importantly, "don't come to my house" [7].

Recipients wrote to him. While attending his nephew's bar mitzvah on Cape Cod, he woke to an inbox full of people from his past asking whether the party was real [1]. Some were acquaintances he had met in passing 15 years earlier [3]. According to Lara Aknin, a psychology professor at Simon Fraser University, only 30 percent of people check in with an old friend "even when we make doing so as easy as possible by helping them identify a desirable, feasible, and low-risk contact" [10]. With email scams, "people are motivated and willing to reach out to an old friend because the scam provides a legitimate excuse or social cover to do so," Aknin said [11].

Umansky has since reconnected with a handful of old friends and colleagues [12]. "It was so striking to me after it happened that I actually had a thought that I was like, 'Oh, is this a net positive?'" he said [9].

For a team, the friendly name is the problem. Wired calls the use of a relationship between two people to manipulate a victim spear phishing, and counts phishing among the biggest security risks facing both individuals and companies [8]. A warning to distrust unfamiliar senders does nothing for someone looking at an invite from a person they know. Wired did not report whether Umansky's account was taken over or his name was spoofed, or what the RSVP code in the FTC language it quotes unlocks [5][6].

I'd build the team rule around what the message asks for. The name on the invite is the part a recipient cannot verify from inside the inbox. The grid has two axes. One is whether the invite comes from a stranger or from someone the recipient knows. The other is whether it asks for a click or for a credential, meaning a password or a code. Both FTC variants sit on the credential side [5]. Umansky's case shows an invite can sit in the known-sender column [2]. That corner is where the rule goes, and it fits in a line: no invitation needs a password or a code to view it or to RSVP.

The rule has a cost. Staff will message a colleague by chat or phone to ask whether an invite is real, and some of those messages will be awkward. Umansky's contacts sent theirs unprompted [12].

What to watch

  • Any explanation from Paperless Post, Evite or the FTC of how the fake invites go out in real people's names, whether through taken-over accounts or spoofed addresses.
  • Later reporting on what the RSVP code in the FTC's second variant gives the scammer once it is shared.
  • Reports of the invites arriving in work inboxes under a colleague's name.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories