New Phishing Attack Uses Event Invitations to Steal Login Credentials
New Phishing Attack Uses Event Invitations to Steal Login Credentials
Cyber criminals are more and more often using fake event invitations to trick people into giving away their login details or installing software that gives attackers access to their devices. These scams are being used against organizations across the United States, including universities, banks, healthcare providers, government agencies, and technology companies.
Unlike older phishing emails that often looked suspicious, these messages can appear genuine and professional. They may invite you to a party, conference, networking event, or celebration. The goal is to make the invitation seem normal enough that you click without thinking twice.
How the Scam Works
The attack usually starts with an email or message containing a link to an event invitation website.
After clicking the link, users may see:
- A CAPTCHA or “I’m not a robot” check
- A professional-looking event page
- A sign-in request using a familiar email provider such as Google or Microsoft
Because these steps look legitimate, many people do not realize they are interacting with a phishing site.
Once a user enters their login details, attackers may:
- Steal usernames and passwords
- Capture one-time passcodes or multi-factor authentication (MFA) codes
- Install remote access software that allows attackers to control a computer remotely
In some cases, the fake website may even claim the password was entered incorrectly to encourage the user to type it again.
Why Universities Are at Risk
Educational institutions are common targets because they rely heavily on:
- Email and cloud services
- Shared online systems
- Remote access tools
- Large numbers of staff and students
A single compromised account can give attackers access to sensitive information, research data, or internal systems.
Warning Signs to Watch For
Be cautious if you receive:
- Unexpected invitations to events or celebrations
- Emails asking you to sign in before viewing event details
- Links that redirect you through multiple pages before login
- Requests to install software to join or access an event
- Messages creating urgency or excitement to encourage quick action
Even if a page looks polished or includes CAPTCHA verification, it may still be fraudulent.
How to Protect Yourself
To stay safe:
- Do not click links in unexpected invitations
- Verify event invitations with the sender through another method
- Check website addresses carefully before signing in
- Never enter MFA or one-time passcodes on suspicious websites
- Avoid downloading software unless it is approved by your IT department
- Report suspicious emails or websites to your university IT security team
What To Do If You Clicked a Suspicious Link
If you believe you may have interacted with a phishing site:
- Change your password immediately
- Enable or review multi-factor authentication settings
- Contact the Technology Solutions security team at security@uic.edu