Active phishing campaigns are impersonating electronic invitation platforms such as Punchbowl. These messages are typically sent from known and trusted contacts whose email accounts have been compromised. Users often trust emails from known accounts and are more likely to click the included link, which leads to a webpage that prompts the user to log into their email account to view the invitation.

If the user enters their email account username and password, the threat actor steals them to compromise the user’s account, send phishing messages to their contacts, and access sensitive files and information.
Recommendations
- Refrain from clicking links delivered in unexpected emails, even those in messages sent from known contacts.
- Ensure multi-factor authentication (MFA) is enabled for all accounts, choosing stronger methods, such as an authentication app code instead of SMS text codes.
- Review the Sublime Security blog post regarding a similar campaign from last year.
- If your account is compromised, immediately reset the password for your email account as well as all other accounts, as the threat actor could have obtained additional passwords. Furthermore, delete any auto-forward, auto-delete, and other inbox rules that may have been put in place.

