britechguy
Well-Known Member
- Reaction score
- 5,242
- Location
- Staunton, VA
I just had another client call me saying that he was really concerned that his account had been hacked because a flurry of email messages with the subject, "SPECIAL PARTY INVITATION FROM {HIS NAME}," had gone out to at least many in his address book (BTW: I was one of the recipients). Of course, the "To:" field is vacant in these messages and there's the standard button, in this case "Open Invitation," at the end.
There was a period of time where this particular sort of scam was so common that I was constantly having to assure clients that it was not the result of their email accounts being hacked (and it doesn't seem to be) but I've never figured out how, exactly, the list of a given person's contacts (probably a subset thereof) gets put together for these things. It's impossible to know if "out of contacts" addresses are used as well as the person whose name is on these things will likely never hear from anyone who received it who has no idea who {Insert Name Here} might be.
I used to even email clients telling them I got this sort of thing so they'd be aware it was happening if they weren't already, but it became so ubiquitous for a time that I stopped doing that. People were learning that there was nothing to be done after the fact and there was no indication of actual account access that anyone could detect.
So since this has just popped up again, I thought I'd ask the cohort if anyone knows the broad "nuts and bolts" of the mechanics of this variety of email scam.
There was a period of time where this particular sort of scam was so common that I was constantly having to assure clients that it was not the result of their email accounts being hacked (and it doesn't seem to be) but I've never figured out how, exactly, the list of a given person's contacts (probably a subset thereof) gets put together for these things. It's impossible to know if "out of contacts" addresses are used as well as the person whose name is on these things will likely never hear from anyone who received it who has no idea who {Insert Name Here} might be.
I used to even email clients telling them I got this sort of thing so they'd be aware it was happening if they weren't already, but it became so ubiquitous for a time that I stopped doing that. People were learning that there was nothing to be done after the fact and there was no indication of actual account access that anyone could detect.
So since this has just popped up again, I thought I'd ask the cohort if anyone knows the broad "nuts and bolts" of the mechanics of this variety of email scam.