Can anyone explain how these, "SPECIAL PARTY INVITATION FROM {Insert Name Here}," bulk email scams get the address list?

britechguy

Well-Known Member
Reaction score
5,242
Location
Staunton, VA
I just had another client call me saying that he was really concerned that his account had been hacked because a flurry of email messages with the subject, "SPECIAL PARTY INVITATION FROM {HIS NAME}," had gone out to at least many in his address book (BTW: I was one of the recipients). Of course, the "To:" field is vacant in these messages and there's the standard button, in this case "Open Invitation," at the end.

There was a period of time where this particular sort of scam was so common that I was constantly having to assure clients that it was not the result of their email accounts being hacked (and it doesn't seem to be) but I've never figured out how, exactly, the list of a given person's contacts (probably a subset thereof) gets put together for these things. It's impossible to know if "out of contacts" addresses are used as well as the person whose name is on these things will likely never hear from anyone who received it who has no idea who {Insert Name Here} might be.

I used to even email clients telling them I got this sort of thing so they'd be aware it was happening if they weren't already, but it became so ubiquitous for a time that I stopped doing that. People were learning that there was nothing to be done after the fact and there was no indication of actual account access that anyone could detect.

So since this has just popped up again, I thought I'd ask the cohort if anyone knows the broad "nuts and bolts" of the mechanics of this variety of email scam.
 

Check his email address there. My personal email has 33 email breaches in the past 20 years. Lists get resold all the time. Nothing has changed the same answer you gave a few years ago so applies now.
 
I'm aware of Pwning, but even that doesn't typically involve login credentials, though it sometimes does.

It's not so much the "how do they get the email address used to send this stuff out" that I wonder about, but how do they compile the list of addresses they send to, which seem to be at least substantially congruent with the pwned source sending address, but where no obvious actual compromise of the account itself can be detected?

I did check his email address, which has 12 breaches listed, the most recent in April 2025. Most of what I've ever seen, or heard reported, coming out of data breaches has a very short shelf life. If it's not occurred within 6 months of the breach, it's not all that likely to occur. Pwned information "gets moldy" pretty fast.
 
Password get changed but many people have had the same email address for years. Most account breaches result in the theft of address books. They make valuable targets as, like I said, email addresses don’t change often. If the guy ever used an yahoo account chances are high his address book was taken.
 
I don't know if this is how it's actually done, but this is how I'd do it:

1. Nefariously obtain Alice's address book.

2. Pick an address from it - say, Bob.

3. Send spam from Bob to everyone else in Alice's address book, but crucially not to Alice.

4. Count on a significant number of people who know Alice also knowing Bob and falling for it.

5. Bob gets blamed for sending out spam and he calls in technician Ted, who spends hours looking for a breach that isn't there.

6. Alice (the actual victim) remains oblivious and her technician Carol isn't even notified that there's a problem.

7. Profit, somehow.
 
Last edited:
1. Nefariously obtain Alice's address book.

And that's the key part I'd like someone to lay out who actually may know how this is done, whether by one technique or another.

Most data breaches do not involve passwords (though some do) and there has to be some way that address books are "routinely snagged by the nefarious." But how? They're not a part of most data breaches. I've been part of at least 3 or 4, two huge ones, Anthem and Equifax. While both of these had my email address, none had the password for my email accounts so anyone who had every bit of data from those breaches would not likely have a way to get into my email accounts. It's been many, many years since I used the same password across accounts or used any easily guessable or crackable passwords.
 
At a guess, Alice got sloppy.

In the old days it would be a drive-by infection on Alice's unprotected Windows machine. Now I'd be looking at apps asking for (and being given) Alice's permission to access her phone's address book. But remember - in the scenario I described Alice doesn't even know that her address book has leaked and at no point does anyone need her email password, so the chance of anyone ever tracing the source of the leak is pretty low.

The only really tricky part is faking a message from Bob that passes SPF, DKIM, DMARC and similar checks. After that you're just relying on basic human gullibility.

About ten years ago I had a client who was convinced that this kind of forgery couldn't happen, until I sent her a personal email message from Pope Francis <pope@vatican.org>. To say that she was shocked is an understatement.
 
Last edited:
About ten years ago I had a client who was convinced that this kind of forgery couldn't happen, until I sent her a personal email message from Pope Francis <pope@vatican.org>. To say that she was shocked is an understatement.

About 10 years ago, I can believe that most people might have been shocked. But with spoofing having become what it is, I wouldn't expect that to nearly the same extent today.

In the end, I still counsel my clients that the probability that their account has been hacked, in any meaningful sense of "account hacking" in my own mind, is nearly zero. This particular scam has been perfected using "account external means" for a very long time now.
 
I don't know if this is how it's actually done, but this is how I'd do it:

BTW, your step-by-step explanation of the steps, big picture wise, directly echo what I have had in mind for a very long time.

Nice, clean, and appreciated, too. I didn't want to come off as pooh-poohing that contribution. My only intention was to zero in on the step of interest to me, and that territory has been at least pretty decently covered.
 
5. Bob gets blamed for sending out spam and he calls in technician Ted, who spends hours looking for a breach that isn't there.

6. Alice (the actual victim) remains oblivious and her technician Carol isn't even notified that there's a problem.

Now I feel very old, having suspected the Bob & Carol & Ted & Alice play as I was reading step 1 - 🤣
 
A church I do tech for just went through one of these. I suspected a breach of their congregant database, "Breeze", but @Computer Bloke puts forth a plausable alternative. No way to find patient zero easily in that instance, as well. Frustrating.
 
And that's the key part I'd like someone to lay out who actually may know how this is done, whether by one technique or another.

Most data breaches do not involve passwords (though some do) and there has to be some way that address books are "routinely snagged by the nefarious." But how? They're not a part of most data breaches. I've been part of at least 3 or 4, two huge ones, Anthem and Equifax. While both of these had my email address, none had the password for my email accounts so anyone who had every bit of data from those breaches would not likely have a way to get into my email accounts. It's been many, many years since I used the same password across accounts or used any easily guessable or crackable passwords.
I was specifically referring to breaching of email accounts. All you need is a successful phishing campaign and a token hijack for that. It’s so bad that Microsoft is making passkey the default login and ending SMS as a MFA method next month.
 
Fun times guaranteed for many techs!

Woo-hoo! I enrolled in the Microsoft 365 Message Center a while back just so I could see what water is passing under the many bridges and noticed the announcement that @nlinecomputers gives the link to.

I am just so glad that I am "of a certain age" and not really actively dealing with the "big business" world at all. This change will be causing both anger and WTF! reactions for many months to come. That doesn't mean that it's not necessary, nor that once it's in place a great may will also be saying, "Why did I resist this? Why didn't I do it earler?," but that comes later, after the fury.
 
"Why did I resist this? Why didn't I do it earler?," but that comes later, after the fury.
Followed still later by fury again when they realize the pain caused by losing/breaking/replacing the only device that held the passkey. Maybe MS will force you to create passkeys on at least 2 devices, but I doubt it. Probably they'll offer to store it in Edge with your MS account, but fail to explain the non-portability if you elect otherwise.
 
Followed still later by fury again when they realize the pain caused by losing/breaking/replacing the only device that held the passkey.

Oh, yeah, this too!

It's one of the reasons I pound home, again and again and again, with clients the "primacy of passwords." They are still used as the "when all else fails" way to gain access to virtually everything. They are the keys to your kingdoms.

I use passkeys quite a bit these days simply for the sake of convenience, but I have very single password logged in a password manager, and still force myself to use a lot of them for occasional login cycles for things where I have occasion to need access outside of the devices with passkeys.

I also only MFA accounts that, in my opinion, warrant that level of protection or where I'm forced to. I don't give a flying rats patootie if, say, my account on PBS.org were to be compromised. I very much care if my credit card accounts were to be. It comes back to the quotation I've posted on many occasions:
In the computer security field, we often say that one doesn't need Fort Knox to safeguard a broken bicycle.
~ Glenn Glazer, M.S. ’07 UCLA Security & Cryptography,
April 25, 2019, in Message on Groups.io Beta Group

Not everything needs or deserves "maximum protection."
 
Back
Top