As Dean Martin used to sing: “Ain’t That A Kick In The Head”. My email account was somehow compromised, and an email was sent out to my contact list titled “You are Invited!”, which invited recipients to respond to an RFP. Please disregard the email.
Here’s what I know happened so far:
I opened an email at 1:24pm CT that discussed submitting a response to a request for proposal, with a button to click. I DID NOT click that button or anything else in the email.
Nonetheless, at that exact same time, an email was sent out from my account to my contacts, which said the following:
“eDiscovery Today**, we are pleased to invite qualified organizations to review and submit competitive proposals for upcoming projects and service opportunities”
I realized what happened when I started getting a bunch of bounce backs on the email for undeliverable messages (for email addresses no longer active). The interesting thing is that the bounce back emails were hitting my phone notification, but by the time I checked my Inbox, they were already being deleted as soon as they were received – clearly whoever hacked my account was trying to cover their tracks.
Once I realized what was going on, the first thing I did was to change my email password. As soon as I did that, the bounce back emails stopped. I then proceeded to run a scan of my computer with both Windows Defender and Malwarebytes (thanks David Greetham for the suggestion to use that program as well). Neither found anything of note.
Several people have reached out to me to double-check whether this was a legitimate email, which I appreciate. I am responding to each person who does so to let them know to please disregard the email.
I’m not sure if simply opening the email I received triggered the mass send, or if my account had already been compromised some other way. The timing of when my email was sent seems too coincidental to be related to anything other than my opening of the email.
I have been reading up since this happened a short time ago about pixel tracking, so that may have been a possible cause. Hidden links is another potential I’ve been reading about. I also did discover that my account on my iPhone was set to “Always display external images” instead of “Ask before displaying external images” and I may have opened the email on my iPhone first, which could have triggered the issue.
I welcome inquiries and suggestions from readers out there who are cyber experts – I’ll take all the help I can get. I’ll respond to any comments on this blog post or share any that I get from other means. Let’s all learn from my experience.
In the meantime, please disregard the email from me that says, “You are Invited!” – it’s a bad email. “Ain’t That A Kick In The Head”?
So, what do you think? Are you aware of a phishing scam than can occur without clicking anything in the email? Please share any comments you might have (no, really, I mean it this time!) or if you’d like to know more about a particular topic.
Disclaimer: The views represented herein are exclusively the views of the author, and do not necessarily represent the views held by my employer, my partners or my clients. eDiscovery Today is made available solely for educational purposes to provide general information about general eDiscovery principles and not to provide specific legal advice applicable to any particular circumstance. eDiscovery Today should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.

