Scam of the week: You're invited!
A few weeks ago, an invitation landed in my inbox from a friend:
I opened it. I knew the sender, and the email was even marked “important” in my inbox. Inside was a Punchbowl invitation. I didn’t know what it was for, but friends send me invitations like this all the time.
I clicked “Open invitation.”
The next page asked me to verify I wasn’t a robot. If I had done that, a Google login page would have appeared asking me to sign in. If I had entered my credentials, my Gmail account would have been compromised. And if my account had been compromised, similar phishing emails would have been sent to my friends and colleagues.
Luckily, a warning popped up from our AntiScam app before I got that far. The “verify you’re human” step was there to lower my guard and to hide the fake page from traditional security filters. And that page was hosted by onyzforbidden.com, not google.com.
This simple scam has been around forever, but it still works. It uses compromised accounts to gain trust and compromise more accounts, spreading virally until the scammer has access to thousands of accounts. From there, the scammer either abuses that access for profit or sells the credentials to the highest bidder on the dark web.
What you can do to stay safe
1. Enable Multi-Factor Authentication (MFA) and Use Passkeys
MFA ensures that after entering your password, you must verify your identity, typically via a mobile app notification or a temporary code. It is a critical security upgrade over a password alone, and you should enable it on every account that supports it.
While MFA is stronger than passwords alone, sophisticated scammers have found ways to intercept standard SMS or app codes as well. Passkeys offer stronger protection. A passkey is stored securely on your laptop or phone, and unlocks instantly with your face, fingerprint, or device PIN. Because it is cryptographically tied to the legitimate website, a fake phishing page literally cannot steal or use it. Major platforms like Google and Apple fully support passkeys, and they take just seconds to set up.
2. Use a password manager.
Password managers generate and store strong passwords for you, with built-in options available from both Google and Apple. An additional benefit is that password managers will only fill in your login on the real website. If you land on a fake page and your password manager doesn’t offer to fill anything in, that’s a cue that the page may not be what it claims to be.
3. Download our AntiScam for Chrome browser extension.
Nearly half of Americans say they get a message they suspect is a scam every single day (2026 U.S. News survey). It’s helpful to educate yourself and stay vigilant, but it only takes one tired moment or one particularly clever scam to cause a big headache. Our AntiScam extension protects all your browsing – and warns you before you click, reply, or send money.
What the industry can do to keep you safer
1. Make it easier to flag compromised accounts.
Because this phishing email was sent from my friend’s real, hacked address, the danger didn’t stop with me. By the time I opened it, the scam had already been blasted to her entire contact list. How do I let my friend know that her account is compromised? How does she know what to do next, to recover her account and make sure her contacts are safe?
In this case, I had to reach out to my friend over WhatsApp to sound the alarm, and then call her to walk through account recovery steps. While every email client has a “Report Phishing” button to protect yourself, the industry lacks a seamless way to protect the sender.
Email platforms should consider a “Report Compromised Account” option. With a single click, it could securely alert the account owner via out-of-band channels (like SMS) and provide them with a clear, step-by-step account recovery playbook.
2. Shift from static blocklists to adaptive AI
Tech platforms protect millions of users daily, but inconsistently flag attacks like this one. Gmail marked this phishing email as “important” in my inbox, and Chrome failed to trigger a Safe Browsing warning on the phishing page.
With modern AI, it’s possible to catch 99% of scams that are falling through the cracks in existing filters, without overflagging. Yet, most of the industry still relies on traditional blocklists, which are simply too static and slow to intercept fast-evolving scam techniques. Safety requires adaptive technology that protects all your apps and devices, all the time.
Our AntiScam app successfully warned me about the phishing page, though it missed the initial email. The email featured a red flag – an “open invitation” link pointing to onyzforbidden.com – alongside subtler indicators like the use of BCC and a typo in the subject line (”Your Invited” instead of “You’re invited”). AI is fully capable of catching this. We are actively learning from every one of these missed opportunities, and are committed to building the most proactive and effective scam detection in the industry.






