Family Sentinel
Scam Watch · September 27, 2026 · 8 min read

The invitation from a friend that isn't from your friend

An email arrives from someone you actually know — a real friend, a member of your church, someone whose address you'd recognize anywhere. It looks like a party invitation. You're one of dozens of names quietly copied on it. And opening it asks you for your email password. That last part is the whole scam.

One person described it plainly in a public post after it happened to her: she opened what looked like an e-vite, it asked for a password, and it kept telling her the password was wrong — so she kept trying every password she could think of, handing over each one in turn. Her warning to everyone who knew her: "if you get one from my email, it's not me." By the time she posted that, her account had already sent the same card to her entire contact list.

What it looks like

The email shows up in a normal inbox, not a spam folder, because it comes from a normal, real email account — one that belongs to someone the recipient knows personally. The giveaway, if you look closely at the header, is that the recipient's own address sits in the Bcc field rather than the To or Cc line. That single detail means the message didn't go to one person. It went to the sender's entire contact list at once, with everyone blind-copied so no one sees the size of the list.

The body of the email is image-heavy and polished: a card styled to look like a Paperless Post invitation, a "For: Friends & Family" label, a lavender envelope graphic with a postmark, and a button that says something like "View the Card." The wording varies — some versions describe an e-invite for dinner, others for brunch — but there's rarely a specific date, place, or personal note attached. It's a shell built to get one click.

The scam email as it appears on a phone: a Paperless Post logo, the line "For: Friends & Family", a "View the card" button, and a lavender envelope with a postmark and a Paperless Post stamp, reading "Friends & Family". Reply and Forward buttons sit below it.
What arrives in the inbox. It borrows Paperless Post's branding, but it came from a friend's hijacked personal account, not from Paperless Post, and the "View the card" button leads to a password-stealing page.

Click that button and the trap does the rest. A page opens asking you to enter your email password to "view the invitation." Type it, and the page says the password is wrong. Type it again, a variation, another password entirely — it keeps rejecting whatever you enter, and each attempt is captured before the rejection ever shows up. There is no invitation. There never was. The only thing being collected is a list of passwords you actually use.

Why it works

The chain reaction

Once a password is entered on that page, the attacker logs into the real account behind the scenes. From there, the cycle repeats itself automatically: the same card gets sent to that person's entire contact list, from their real address, carrying their real trust — and each new recipient becomes a candidate to repeat the cycle again. It spreads less like a phishing campaign and more like a chain letter, with every victim's address book becoming the next batch of targets.

The compromised account rarely stops at sending the card. Attackers commonly return to it later for follow-up scams — a message to a contact that says something like "are you available? I need a favor," often leading into a request for gift cards. Many also quietly add hidden inbox filters or rules to the compromised account: rules that delete or archive any reply containing words like "hacked," "scam," or "compromised," and sometimes forwarding rules that copy mail to the attacker going forward. The effect is that the real account owner can go a long time without ever seeing the replies warning them something is wrong.

The one thing to remember: No genuine invitation, card, or document-sharing notice ever needs your email password to be viewed. That single request — regardless of how the message is dressed up — is the entire scam.

How to spot it

  1. Check who it's actually addressed to. A real invitation from Paperless Post, Evite, or Punchbowl comes from the platform itself — a paperlesspost.com or evite.com address — with the host's name in the message, not from your friend's personal Gmail or Yahoo account.
  2. Check the To/Cc/Bcc line. If you're blind-copied alongside a card claiming to be personal, that's already a contradiction. A genuine host-sent invitation names its guests, or at minimum doesn't hide the guest list from view.
  3. Look at where the button actually leads. On a phone, press and hold the "View the Card" button instead of tapping it, and a preview of the real destination address appears. On a computer, hover over it without clicking and look at the address shown in the corner of the browser. If that address isn't the platform named in the card, don't click.
  4. Notice what's missing. A real invitation usually includes a specific date, time, and location, or at least a personal note from the host. A card that's all image and no detail, with nothing to look at except a button, is a shell built for one purpose.
  5. Remember the one rule. An invitation should never require your email password to view it. If any card, document link, or "shared file" notice asks for that, close it.

What to do

A) You received one — haven't clicked

B) You clicked, and typed a password into the page

  1. From a different device if you can — one you're sure is clean — change the password on the email account tied to that page immediately.
  2. Also change every other account where you used any password you typed on that page, even variations. The fake page was designed to collect several attempts, and it counts on password reuse.
  3. Turn on 2-Step Verification, or a passkey if your provider offers one, on that email account and anywhere else you just changed a password.
  4. Then work through the full account-owner checklist below (C) — a captured password can be used quietly for some time before anything looks wrong.

C) It was sent from your account — the account-owner checklist

Gmail

Outlook.com

Yahoo

Then, regardless of provider:

My email account was briefly compromised and may have sent a fake "invitation" or "e-vite" card to my contacts. Please don't click the link in it or enter any passwords — it isn't from me. I've secured my account.

D) For families helping an older parent — what to set up this weekend

The one rule that stops all of it

No genuine invitation, card, or shared-document notice ever needs your email password to open it. Not once, and not for any reason a page can give you. If a "view" button leads to a password prompt, close it — the invitation was never real, and the account that sent it needs your help, not your password.

Frequently asked questions

Why didn't my spam filter catch this?
Because there's nothing forged for a filter to catch. The message comes from a real account, in good standing, that has sent real mail to these same contacts before. Spam and phishing filters are built to catch a fake or unfamiliar sender — this scam works precisely because the sender is neither.

My friend says they never sent me anything like this. Are they lying?
No — this is the normal experience of the person whose account was used. The card goes out automatically once the account is compromised, and the real owner usually has no idea it happened until someone tells them, or until they notice sent mail they don't remember writing.

I already typed my password once, then realized it looked wrong and stopped. Am I still at risk?
Yes, treat it exactly like checklist B above. Even one password entered on the fake page may have been captured, and the page's "incorrect password" loop is designed to make one attempt turn into several.

Can I just delete the email and move on?
If you haven't clicked anything, yes — report it as phishing and delete it. If you clicked the button or entered any password, deleting the email doesn't undo what the page already collected; you still need to change passwords and work through checklist B or C.

Is this the same as a normal phishing email?
The password-harvesting page works the same way a phishing page always has. What's different is the delivery: it doesn't arrive from a stranger or a spoofed address, it arrives from someone real, using their real account — which is why it's worth learning to recognize on its own.

How Family Sentinel helps

Family Sentinel's engine flags a card, invitation, or document-share notice that arrives from a person's own mailbox but whose button leads somewhere other than the platform it names — and it does this even when the sender is a trusted, long-standing contact, because that trust is exactly what this attack borrows. A person on our team reviews every alert before a family is contacted, so a flag means something. We don't claim to catch every variant of this scheme, and we are read-only by design: we don't block or delete email, and we can't fix an account that's already been compromised. What we can do is watch for the pattern and get a human warning to your family before the next click happens.

Related reading

This scam spreads through the inbox — and that is where we watch.

A card or invitation from a real contact, leading somewhere it shouldn't: Family Sentinel reads every message in the inbox for exactly this pattern and gets a warning to your family fast — ideally before anyone types a password into a fake page. Read-only by design, with a real Security Architect behind every serious flag. Your family can also set a personal verification phrase, so a scammer can never fake a warning from us.

Start your free month →

Want the next threat before it reaches you?

Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.

Written by the Family Sentinel security desk — a working Security Architect and the team who watch family inboxes around the clock. This breakdown is based on publicly posted, first-hand accounts of the pattern described above, plus the account-recovery procedures published by Google, Microsoft, and Yahoo for compromised accounts. No names or identifying details from any source have been used. Have a suspicious message you'd like a verdict on? Forward it to security@familysentinel.org — no charge, no strings. (940) 281-6672.