Post #4240288
2026-07-30 12:03 UTC
Replies (9)
-
@neurovagrant@masto.deoan.org 2026-07-30 12:07
@briankrebs@infosec.exchange I would love to see the raw body of the scam email to see if there was any attempt at prompt injection, or if it was literally just Gemini falling for a basic scam email.
-
@Sassinake@mastodon.social 2026-07-30 14:22
@briankrebs@infosec.exchange I want to know if Proton mail (etc) is GOOD OR BAD. I don't have enough info to figure it out.
-
@sharkfie@infosec.exchange 2026-07-30 15:55
@briankrebs@infosec.exchange how much of a chance of a prompt injection in the invisible text or an image?
-
@Dennisqr@infosec.exchange 2026-07-30 17:16
@briankrebs@infosec.exchange just brilliant.. 🤣🤣
-
@briankrebs@infosec.exchange 2026-07-30 15:45
There is actually a LOT more to this scam than meets the eye. It's quite a well crafted phishing scam, and also quite targeted. I will almost certainly be writing about this.
-
@MillardPhillmore@mastodon.social 2026-07-30 12:09
@briankrebs@infosec.exchange "thank you for calling movie phone!"
-
@moses_izumi@fe.disroot.org 2026-07-30 12:22
@briankrebs@infosec.exchange all my tasks gone
-
@briankrebs@infosec.exchange 2026-07-30 18:23
Okay, there's a Reddit thread about this scam. Apparently a lot of people are falling for this. It appears these messages may have abused some email sending trust relationships or credentials, because the phishing messages reportedly passed SPF, DKIM and DMARC tests, and the URL points to a genuine subdomain on their site that they actually use in coms. https://www.reddit.com/r/CryptoCurrency/comments/1vaj96n/cryptocom_phishing_scam/
-
@madem@infosec.exchange 2026-07-30 19:14
@briankrebs@infosec.exchange ok so this is new would be interesting to see if attackers try to consciously get the AI to nudge their phishing emails to be interacted by the user