Elektrine lite

← Feed

@briankrebs@infosec.exchange

Post #4240288

2026-07-30 12:03 UTC

Oh my. A trusted source who enabled Google's new AI feature for Gmail just received this nudge from the service today, which encouraged him as part of his suggested to-dos list to fall for a cryptocurrency scam waiting in his inbox. IDK why, but when I saw this I was reminded of that Seinfeld episode where Kramer gets a new phone number but it's the old Moviephone number, and so he starts answering the phone and reading the listings. "Why don't you just tell me what scams to click?" https://www.youtube.com/watch?v=XagGEi_n_ok

Replies (9)

  • @briankrebs@infosec.exchange I would love to see the raw body of the scam email to see if there was any attempt at prompt injection, or if it was literally just Gemini falling for a basic scam email.

    Open ##4242294

  • @Sassinake@mastodon.social 2026-07-30 14:22

    @briankrebs@infosec.exchange I want to know if Proton mail (etc) is GOOD OR BAD. I don't have enough info to figure it out.

    Open ##4243306

  • @sharkfie@infosec.exchange 2026-07-30 15:55

    @briankrebs@infosec.exchange how much of a chance of a prompt injection in the invisible text or an image?

    Open ##4245272

  • @Dennisqr@infosec.exchange 2026-07-30 17:16

    @briankrebs@infosec.exchange just brilliant.. 🤣🤣

    Open ##4247187

  • @briankrebs@infosec.exchange 2026-07-30 15:45

    There is actually a LOT more to this scam than meets the eye. It's quite a well crafted phishing scam, and also quite targeted. I will almost certainly be writing about this.

    Open ##4247526

  • @briankrebs@infosec.exchange "thank you for calling movie phone!"

    Open ##4247531

  • @moses_izumi@fe.disroot.org 2026-07-30 12:22

    @briankrebs@infosec.exchange all my tasks gone

    Open ##4247532

  • @briankrebs@infosec.exchange 2026-07-30 18:23

    Okay, there's a Reddit thread about this scam. Apparently a lot of people are falling for this. It appears these messages may have abused some email sending trust relationships or credentials, because the phishing messages reportedly passed SPF, DKIM and DMARC tests, and the URL points to a genuine subdomain on their site that they actually use in coms. https://www.reddit.com/r/CryptoCurrency/comments/1vaj96n/cryptocom_phishing_scam/

    Open ##4248963

  • @madem@infosec.exchange 2026-07-30 19:14

    @briankrebs@infosec.exchange ok so this is new would be interesting to see if attackers try to consciously get the AI to nudge their phishing emails to be interacted by the user

    Open ##4250539