Skip to main content

Punchbowl Phishing Attack Explained: How Digital Invites Are Used to Steal Credentials

February 24, 2026

By: Adriane Andaya, Cofense Phishing Defense Center

In today’s digital environment, online invitations have become a routine part of planning events. Platforms such as Punchbowl and Paperless Post make it easy for individuals and organizations to create customized invitations, track RSVPs, and send event updates. That familiarity also gives threat actors a useful social-engineering opportunity, particularly during seasons when digital invitations become more common.

The Cofense Phishing Defense Center (PDC) intercepted and analyzed a malicious digital invitation that looked harmless at first glance but exposed recipients to significant credential-theft risk. The message prompted the recipient to sign in before viewing the event details, closely resembling a normal invitation workflow.

Figure1 (14)

Figure 1: Email Body

After the recipient interacted with the invitation, the link redirected to a phishing site that presented familiar brands—including Microsoft, Yahoo, AOL, Google, and Dropbox—as sign-in options. The variety of choices made the page appear flexible and legitimate while giving the attacker multiple opportunities to collect credentials.

Figure2 (14)

Figure 2: Phish Landing Page

The branded pages were designed to capture more than one set of credentials. Even when a recipient entered a valid username and password, the phishing page could return a fabricated error and encourage another attempt with a different account. Submitted credentials were then exfiltrated to infrastructure controlled by the threat actor.

 

Figure3 (14)


Figure6 (5)

Figure5 (7)

Figure4 (10)

Figure7 (4)

Figure 3-7: Branded Phishing Pages

The landing domain was newly registered, a common tactic in credential-phishing campaigns. New domains give threat actors control over DNS records, certificates, and hosting while avoiding the negative history that reputation-based tools use to identify known malicious infrastructure. Because registration is inexpensive, these domains can be discarded and replaced as soon as defenders begin blocking them.

Figure8 (4)

Figure 8: Malicious Domain Whois Information

Why Campaign-Level Context Matters

Disposable infrastructure makes these attacks difficult to stop with reputation checks or exact indicators alone. A threat actor can rotate a sender, URL, domain, or login-page design while keeping the same campaign structure and credential-theft objective. To defenders, those changes can make related emails look unrelated.

Cofense Vision applies phishing-specific AI to cluster related messages using structural and behavioral relationships, helping security teams see the campaign before every indicator is known. When one email is confirmed malicious, analyst-controlled response can extend quarantine across related messages in the cluster and apply new intelligence retroactively to remove older variants that may still be sitting in inboxes.

What Attackers Can Do With Stolen Credentials

  • Gain direct access to personal or corporate accounts and perform credential-stuffing attacks against other services where passwords may have been reused.
  • Escalate privileges or conduct business email compromise, especially when a corporate mailbox is exposed.
  • Commit identity theft, fraud, or extortion.
  • Add compromised accounts to botnets or use them to support additional attacks.

How Recipients Can Reduce the Risk

1. Verify the invitation. If the sender or event is unfamiliar, contact the host through verified contact information and confirm that the invitation is relevant.

2. Treat unexpected login prompts with caution. If an RSVP link redirects to a separate sign-in page, inspect the address bar and page details for suspicious indicators.

3. Report irrelevant or unexpected invitations through the organization’s approved reporting process.

4. If credentials were entered on a suspicious site, reset the password immediately, review account activity, and notify the security team.

5. Enable multi-factor authentication wherever possible to reduce the impact of a stolen password.

User vigilance remains essential, but it should not be the only line of defense. Employee reports provide high-value signals that can be validated by phishing experts and fed back into detection, response, and training. That closed loop helps organizations adapt as attackers change brands, domains, and page designs.

Cofense delivers AI-driven post-perimeter phishing defense built for the reality that phishing gets through. By combining phishing-specific AI trained on expert-validated, real-world phishing intelligence with Managed Phishing Defense and campaign-level remediation, Cofense helps teams identify related variants, contain confirmed attacks, and reduce the time malicious emails remain in inboxes. Schedule a demo to see how Cofense protects against credential-phishing campaigns like this one.


Stage 1 - Observed Email Infection URL:

Infection URL IP(s):

hXXp://t[.]ly/KwKzQ

104[.]20[.]6[.]133; 104[.]20[.]7[.]133


Stage 2 - Observed Payload URL(s):

Payload IP(s):

hXXps://dry[.]za[.]com/if1/

172[.]67[.]221[.]157; 104[.]21[.]67[.]111

All third-party trademarks referenced by Cofense whether in logo form, name form or product form, or otherwise, remain the property of their respective holders, and use of these trademarks in no way indicates any relationship between Cofense and the holders of the trademarks. Any observations contained in this blog regarding circumvention of end point protections are based on observations at a point in time based on a specific set of system configurations. Subsequent updates or different configurations may be effective at stopping these or similar threats. Past performance is not indicative of future results. 

The Cofense® and PhishMe® names and logos, as well as any other Cofense product or service names or logos displayed on this blog are registered trademarks or trademarks of Cofense Inc.