Almost got phished this week and tbh it was pretty clever.
My buddy @constantout sends me a lead. Says he can't take it on, asks if I want it for a referral fee. Also says "not sure how legit it is lol."
He adds me to the email thread. The name is weird already. Feels a little off. I think maybe they're just weird.
They send me a Calendly link. Looks totally normal. Pick a date, pick a time.
Then a Google sign-in pops up. A googel domain in the URL bar, little padlock, Calendly logo. Looks exactly right.
Except you never need to sign in with Google to book a call with someone on Calendly. It's just name and email. And thank god, I knew about that.
And the sign-in "window" wasn't a window at all. It was drawn inside the page. Fake URL bar and everything. That's why the address looked perfect. It wasn't real.
I've seen the version where a "journalist" wants to interview you about a post. This one came through a friend as a paid lead, which is a way better hook.
Anyway: if a booking link ever asks you to log in to Google, close it!!
Update: Our preliminary Post Incident Review (PIR) is available at the link below. Details include the incident overview, remediation actions, and preliminary learnings. More to come in our full Root Cause Analysis (RCA).
Automated recovery techniques, coupled with strategic service delivery partners, have rapidly accelerated resolution.
We can’t repeat enough, we’re aware of the impact and deeply sorry this occurred. We want to thank our customers and industry partners for their support and assistance following the release of a faulty content update. We know what happened and how to make sure it doesn’t happen again.
Stay informed with the latest news and updates on our remediation hub: https://t.co/VxZdW6gKmt