Scammers have timed a new credential-theft campaign to graduation season, sending fake digital invitations that ask recipients to enter their email address and password before they can view the message. The Federal Trade Commission issued a consumer alert in May 2026 warning that these party and graduation invites are designed to hijack email accounts and then spread the same scam to every contact in the victim’s address book. The scheme requires no technical sophistication from the target, only a moment of trust in what looks like a celebration announcement from someone they know.
Seasonal urgency makes fake invitations effective
The core trick is simple: an unexpected digital invitation arrives by email or text, styled to look like a graduation announcement or party invite. To “view” the details, the recipient is asked to enter an email address along with a password or pass code. That information goes straight to the attacker. Once inside the compromised account, the scammer sends the same fraudulent invite to the victim’s entire contact list, giving the next wave of messages the appearance of coming from a trusted friend or family member. The FTC alert describes this chain reaction as the primary harm: one stolen password turns into dozens of new targets within hours.
The timing matters. Graduation ceremonies, end-of-year parties, and summer gatherings generate a flood of legitimate digital invitations every May and June. Recipients are primed to expect these messages, which lowers the instinctive suspicion that might otherwise stop them from typing in credentials. Attackers exploit that seasonal pattern. A spoofed message that appears to come from a recent graduate or a mutual friend carries more weight than a generic promotional email, because it taps into a real social expectation.
Social pressure also plays a role. People do not want to miss a milestone event or seem rude by ignoring what looks like a personal message. That urgency can override basic security habits, such as hovering over links to check their destination or questioning why a party invite would require a password at all. The combination of emotional stakes and realistic timing makes these lures unusually persuasive.
How fake login pages capture credentials at scale
The invitation link does not lead to a real event page. Instead, it loads what security professionals call a “scampage,” a replica of a legitimate login screen built to capture usernames and passwords. The FBI’s Internet Crime Complaint Center has documented how criminals develop and sell credential-harvesting kits, distributing them through emails, texts, and web applications. The pages mirror brand-name sites closely enough that most users cannot spot the difference at a glance.
Universities have seen the same tactic deployed against students and staff. NC State University’s Office of Information Technology, for example, has warned about phishing emails that directed recipients to a fake single-sign-on page designed to steal campus credentials. According to federal cybercrime advisories, attackers increasingly build lookalike employee portals and consumer login pages, then redirect victims to the real site after capturing their details. That redirection, along with suppression of security notifications where possible, helps hide the compromise long enough for criminals to search email archives, reset passwords on connected services, or attempt financial fraud.
Once an email account is under their control, scammers can quietly set up forwarding rules, download contact lists, and impersonate the victim in ongoing conversations. In the context of graduation scams, that access enables them to keep sending new fake invitations that appear to come from multiple legitimate accounts, widening the pool of potential victims without having to break into each account individually.
Gaps in tracking and what readers should do first
No federal agency has published complaint volume or incident counts specific to graduation or party invite lures. The FTC alert describes the scam pathway in detail but does not quantify how many people have reported falling for it. The IC3 toolkit advisory and related FBI warnings provide technical context, yet neither offers comparative data on how event-themed phishing performs against other lure types. That lack of granular statistics makes it harder to measure how much damage seasonal scams cause relative to more familiar tactics like fake shipping notices or payroll updates.
For individual users, the absence of precise numbers does not change the basic response. If an online invitation or announcement asks for your email password, do not enter it. Legitimate event platforms may request a name or email address to track RSVPs, but they do not need the password to your inbox. When in doubt, contact the supposed sender using a phone number or address you already have, not the reply button on the suspicious message.
Anyone who realizes they have entered credentials on a fake page should change the affected password immediately and enable multi-factor authentication if it is available. They should also review account settings for unfamiliar forwarding rules, recovery addresses, or recent login locations. Friends and family may need a brief warning that a scam invite went out from the compromised account so they know to delete it.
Consumers looking for broader guidance on spotting and reporting scams can review the Federal Trade Commission’s English-language resources as well as its Spanish-language portal at consumidor.ftc.gov. Those materials emphasize a consistent rule that applies neatly to graduation-season invitations: any message that unexpectedly demands your password in order to share good news is more likely to be a scam than a celebration.