
FOMO as an Attack Vector: How Fake Party Invites Are Hijacking Inboxes
Hello to all our cyber party pals!
This week, Selena is joined by co-host Sarah Sabatka (and several very persistent, very uninvited pod crashers) to talk about a threat that's landed in a lot of listeners' personal inboxes lately: malicious event invitations.
Selena and Sarah walk through what these lures actually look like — polished, Evite- or Paperless Post-style invitations for birthdays, weddings, baby showers, housewarmings, and even generic "Celebrate with Me" surprises, sent from real, compromised accounts belonging to people the recipient actually knows. Sarah explains why the generic, low-detail invites may be the most effective: they don't require any specific knowledge of the target to feel plausible, and they lean on curiosity and FOMO rather than fear, a notable departure from traditional phishing psychology.
The conversation dives into ATO jumping, the mechanism that makes this threat spread so efficiently — once a threat actor compromises one inbox, they mine the contact list and send credential phishing to those contacts, who then get compromised themselves, expanding the reach with every hop. Sarah also connects this lure to established delivery chains like RMM tooling (ScreenConnect, Atera) and credential phishing panels such as TA4903 and "Evil Tokens," which use AI-assisted, sometimes vibe-coded automation to filter, organize, and scale compromised mailboxes rather than to improve the social engineering itself.
Selena and Sarah also dig into:
- Why CAPTCHA and Cloudflare challenges are increasingly bundled into these lures — both to build a false sense of legitimacy and to slow down defenders and researchers trying to analyze the infection chain
- Why Microsoft 365 and Google accounts are such high-value targets: they're the hub for cloud documents, financial access, social platforms, and a trusted contact list an attacker can impersonate
- Practical recovery steps if you've already entered your credentials: revoke active sessions, change your password, enable MFA (passkeys where possible), freeze accounts if financial exposure is a concern, and give your contacts a heads-up
- Why smart, security-aware people still fall for these — FOMO and curiosity are natural human responses, not a knowledge gap, and no lure is universal, but there's a lure for everyone
- The FTC's May consumer alert on fake party invitations, and simple habits (a quick text or call to confirm an invite) that can blunt the whole scam
Plus: several unannounced podcast "guests" (Tim, Isaac, and Jared) who show up mid-episode having fallen for the very scam being discussed, a genuinely useful tangent on TA2725's shifting tool preferences, and a closing thought on why these lures work in the first place — people miss connecting with each other.
Resources Mentioned:
Asked to Enter Your Email Address and Password to Open a Party Invite? That's a Scam — Federal Trade Commission
https://www.proofpoint.com/us/blog/threat-insight/remote-monitoring-and-management-rmm-tooling-increasingly-attackers-first-choice
For more information about Proofpoint, check out our website.
Subscribe & Follow:
Stay ahead of emerging threats, and subscribe! Happy hunting!
Więcej odcinków z kanału "DISCARDED: Tales From the Threat Research Trenches"



Nie przegap odcinka z kanału “DISCARDED: Tales From the Threat Research Trenches”! Subskrybuj bezpłatnie w aplikacji GetPodcast.








