|
Urgent E-Security Alert:
Fake Punchbowl Invitations (Action Required)
Hi everyone,
We have detected a widespread phishing scam involving fake “You’re Invited” digital invitations that mimic the Punchbowl platform. These emails frequently look like they are coming from a known contact (they have been sent from several different HCA emails) but are designed to steal your passwords or infect your device with malware. It looks like these phishing emails began Saturday evening.
If you received or clicked on one of these links, your required next steps depend heavily on the type of device you used to open it:
🛑 IF YOU ENTERED YOUR PASSWORD (ANY DEVICE)
If you typed your email password or any other login credentials into the phishing site, take these steps IMMEDIATELY regardless of your operating system:
1. Change your password for that account right now.
2. Log into your account security settings, view “Active Sessions/Devices,” and force-logout all other sessions.
3. Ensure Multi-Factor Authentication (MFA/2FA) is turned on.
📱 MOBILE DEVICES
• iPhone / iPad (iOS):
Phishing links rarely install malware on iPhones unless the device is jailbroken. Your primary risk is credential theft. If you only clicked the link but didn’t type anything, your device is likely secure. As a precaution, clear your browsing history (Settings > Safari > Clear History and Website Data).
• Android:
Android devices can occasionally download malicious files (.apk) in the background if safety settings are disabled. Go to your “Downloads” folder or files app and delete any recently downloaded files you don’t recognize. Next, open the Google Play Store, tap your profile icon, select “Play Protect,” and run a full scan to ensure no hidden malicious apps were installed.
💻 DESKTOP & LAPTOP COMPUTERS
• Windows PC:
Windows is the primary target for malicious software hidden in these links. If you clicked the link on a PC, immediately run a full system scan using Windows Security (Windows Defender) or your company’s designated antivirus software. Do not download or open any unexpected attachments.
• macOS (Mac):
While Macs are less prone to automated drive-by downloads, malware can still masquerade as a required “system update” or browser extension. Check your “Downloads” folder and trash any unrecognized files. Run a scan with a trusted tool like Malwarebytes if you notice any unusual pop-ups or browser behavior.
• Chromebook (ChromeOS):
Chromebooks operate in a secure sandbox, meaning traditional desktop malware cannot infect them. Your risk here is strictly restricted to fake login screens or malicious Chrome extensions. Go to your browser menu (three dots) > Extensions > Manage Extensions, and remove anything you did not intentionally install.
• Other Systems (Linux, Unix, etc.):
Similar to ChromeOS, the risk of a background malware infection is very low. Treat this entirely as a credential phishing attempt and ensure your active browser sessions are secure.
WHAT TO DO NEXT:
If you suspect you clicked this link on a company-managed device, may want to contact the IT department help verify your account safety.
We apologize for any inconvenience this may cause.
Best regards,
Mr. Krueger
|