tech
2,400-Person Study Underlies FTC's Party Invite Phishing Warning

Federal regulators say a wave of emails mimicking Evite and Paperless Post invitations is built to steal login credentials, not to invite anyone to a party, according to a Federal Trade Commission consumer alert issued in May 2026 and detailed by Wired on September 25, 2026.
For New York journalist Eric Umansky, the fake invite arrived in April while he attended his nephew's bar mitzvah on Cape Cod: an inbox full of messages from people he hadn't heard from in 15 years, all asking whether he was really hosting a party, Wired reported.
What Does the Fake Invitation Actually Ask For?
The messages that triggered the FTC's alert impersonate well-known invitation platforms and push recipients toward one of two traps, according to the agency's guidance as cited by Wired. Some versions ask a user to enter an email username and password to "see event details." Others instruct the target to enter a phone number and a special code to RSVP, a step that can hand over enough information to hijack an account.
In Umansky's case, the invite described a "Special Private Dinner Party" set for 7 pm on May 2 and was formatted to look like a Paperless Post message. He had not sent it. He also had two-factor authentication enabled on his email, a precaution that did not stop his contacts from receiving the fraudulent message, per his account to Wired.
How Big Is the Problem, According to the FTC?
The FTC issued its consumer alert in May 2026 after what Wired described as an increase in reports tied to invitation-themed phishing. The agency's warning places the scam inside a broader pattern: phishing has been one of the largest security risks facing individuals and companies for roughly two decades, Wired reported, and the tactics keep evolving. Attackers now layer in social-engineering techniques such as manufactured urgency and fear, plus a targeted variant called spear phishing that exploits real relationships between two people. Generative AI has made these fabricated messages harder to distinguish from genuine ones, according to the report.
Why Are the Scam Emails Reconnecting Old Contacts?
After the fake invite went out under his name, Umansky posted on Facebook, LinkedIn, and other networks telling contacts not to show up at his house, since no party existed. But the fallout produced an unplanned upside. "It was so striking to me after it happened that I actually had a thought that I was like, 'Oh, is this a net positive?'" Umansky told Wired.
Over the following months he reconnected with several old friends and colleagues by lunch and text, the outlet reported. One reconnection stretched into an hour-long video call with a former coworker now living in Mexico City, someone he hadn't spoken with in more than a decade. Roughly 10 minutes of the call covered the work topic that prompted it; the rest, Umansky said, was catching up on their lives.
What Does Research Say About the Social Withdrawal the Scam Interrupts?
Wired connected the reconnection pattern to a 2024 study published in the journal Communications Psychology that examined social withdrawal, surveying 2,400 adults in the United States. The study's presence in the reporting underscores the scale of the underlying behavior the fake invites appear to be nudging against: a large, recently studied population of adults whose social ties had gone quiet before a phishing email, of all things, prompted a check-in.
How Can Users Avoid Falling for a Fake Invitation?
The FTC's core guidance, as relayed by Wired, is straightforward: do not enter an email password or a phone verification code into a page reached by clicking a link inside an unexpected invitation. Anyone unsure whether a message is real should contact the supposed host directly through a known phone number or a separate, previously established channel rather than replying to the email or clicking through it.
Two-factor authentication remains a baseline defense, but Umansky's experience shows its limits: attackers do not need to breach the account holder's own email to spoof an invitation to that person's contacts, since the deception often works upstream, through address books or spoofed sender fields, rather than through the target's own credentials.
The practical lesson from both the FTC alert and Umansky's account is the same one that has applied to phishing for two decades: verify before clicking, and treat any invitation asking for a password or a one-time code as a signal to stop, not to RSVP.
AlterEgo — A keyboard for character voices. Five free persona rewrites a day.
Questions
What is the party invite phishing scam?
It is a fraudulent email designed to look like an Evite or Paperless Post invitation that tries to get recipients to enter an email password or a phone verification code, according to a Federal Trade Commission consumer alert cited by Wired.
When did the FTC warn about fake invitation emails?
The Federal Trade Commission issued its consumer alert in May 2026 after an increase in reports of the scam, Wired reported.
How did the scam affect journalist Eric Umansky?
A fake Paperless Post invite went out under his name in April 2026 while he was at a family event; he had two-factor authentication enabled but was still targeted, and he ended up reconnecting with several old contacts who reached out to check if the invite was real, per Wired.