Have you received email invitations to read Blue Mountain greeting cards or respond to Evite or Paperless Post messages that might not have been real? Worse, did a hacker use your email to send false messages like these to your contacts?

There’s been a recent increase in such emails that aren’t legit arriving in the inboxes of my clients and friends. Most such messages appear to have been sent by someone you know but without their actual awareness.

Here are some tips on how to reduce these occurrences and how to respond if this happens to you. And if you weren’t aware, just knowing that these are going around will hopefully make you think twice about clicking a link in one.

Client Notes

In recent weeks, I’ve simplified Alison’s password management and cloud storage strategies, imbued confidence in Rebecca & Bob as they moved their business home, and enabled Susan to print wirelessly to both of her printers even though neither does so in color.

I also thoroughly explored Denni’s tech strategy, supported Inette & Ida to make the move to 1Password, and resolved the effects of an email hack with Sharon. Plus, I supported John to modernize his Mac experience, upgrading from a 2015 iMac with a 2021 model, and I’m in the middle of helping Valeria do similarly and Judi switch from Android to iPhone.

My brief time with Sharon also influenced me to publish today’s edition. Recently, I’ve noticed an uptick in the frequency of phishing attempts disguised as online greeting cards or event invitations. While I’ve written similar posts in years past, the content below is more thorough in explaining how to recognize such messages and what to do in response.

 

BlueMountain Phishing Invitations

Are These Invitations Legit?

When you receive invitations that you don’t expect and that might be phishing attempts, here’s an easy way to tell whether this sort of email message is for real. Check the address of the main link without clicking it:

  • On a Mac or PC, move your pointer on top of the link to the card or invitation. Wait for a tooltip to appear or look at the bottom of the window to see the address.
  • On iPhone, long-press the link and the address should pop up with a preview of the page
  • You can also copy a link without opening it (right-click, Control+click, or long-press, depending on your device/settings) and paste the text somewhere else, such as a note or a blank email

Looking at the link: Does the beginning of the address include the domain of the supposed provider? If it doesn’t show bluemountain.com, evite.com, or a website related to the email, the message is probably spam.

In the example pictured above, I’ve moused over the View Your Ecard link and the URL appears on the status bar in the bottom left. cutt.ly is the domain of a third party URL shortener service.

It’s unlikely a commercial platform like Blue Mountain would use such a service, unless they had their own short domain. As Gemini explains, they don’t, and the AI shares some useful safety measures you can take to ensure you can access a legitimate card you truly received.

Google Account Security Settings

Change Passwords

Has your account been breached and used to send false invitations like this? Here’s what to do first:

  1. Change your email account password!
  2. Does the account associated with your email have a security setting that lists where devices are signed in? If so, find anyone who isn’t you and log them out or remove their device from the list.*
  3. Have you used the same password for any other account? If so, change the password for those accounts, too.

*For example, if you use Gmail, a service of Google, visit Google’s account security settings. Scroll down to view devices where you’re signed in. Click Manage all devices to see the full list and, optionally, remove those you don’t recognize.

Were you on the receiving end of such a phishing campaign, whose apparent sender is someone you know or recognize?

Contact them about it, ideally on a different channel than the email you received. A malicious actor may have changed their password or added a filter that makes receiving email difficult. Invite them to change their password and even link them to this post.

Invitations to Increase Security

Are you overwhelmed when asked to create a new password? Do you tend to keep passwords in your head, on paper, or in a notes or contacts app? I highly recommend switching to a dedicated password manager. You probably already have one or more built into the devices and/or web browsers you use.

This tool can generate and securely store complex passwords for you and then autofill them when needed, so you neither have to remember nor type them yourself. As a result, you no longer need to fill your brain with this excess information and can use your energy and creativity for more delightful pursuits.

For added security, some account providers allow you to create a passkey. If your password manager supports these, I encourage you to opt in. Some accounts will even generate one automatically in the course of logging in.

A passkey is a non-alphanumeric object that relies on your ability to securely sign into your device or password manager and permits that entity to make a secure handshake with a provider. Passkeys are gaining popularity and are considered more secure than passwords. They also deliver a more efficient sign-in process.

I’m happy to help you navigate the process of changing passwords, which is different on every website; adopting a password manager; and/or considering other options. You may also want to read my past articles on this topic: Gone Phishing and Is This Legit?

Plus, if you’ve read any of my dozen-plus articles about 1Password or have worked with me directly to get help adopting it, you know how much I trust and admire this application. I have a clear curriculum to support new users to smoothly transition from their analog or digital, often disconnected password systems to 1Password and then improve their online security with stronger credentials and greater awareness.

If you need more help or insight related to this or anything else about your technology, feel free to reach out. Also, I encourage you to share this article with people you know who are affected by these hacks.