Does anyone recognize this phishing attack?
My friend owns a circus performance company, and she got a very real-seeming request to discuss a possible wedding gig. "Client" requested that she join a meeting link at https://joininivite.es/egooglemeet.us to discuss (several zero-width spaces are pasted throughout that to make it unclickable). Friend joined the call and it asked her to update software in order to join, she didn't follow any links from the site directly but tried updating Chrome through Microsoft Store etc. This sounded fishy to me so I asked to see the URL and this definitely seems like a scam.
This seems extra concerning because:
- Initial outreach from scammer seemed genuine even when I read it specifically looking for signs of phishing
- Initial outreach from scammer was specifically tailored to friend's website content, this is exactly the kind of gig she would get booked for
- There were several back-and-forth legit-seeming emails before any meeting was agreed to
Friend now wants to make a post within her artist community to protect others and I'm wondering if anyone has already heard of this particular type of attack and has additional details that could help for informing non-tech-savvy performers about it (more specific than "have intuition about when URLs seem dodgy and never click install links that originated from email")
Scammers have gotten a lot more persistent and tailored in the age of AI. They will keep you going for hours or days if it means they can get a decent payout (and even $100 is good for someone in a developing country, never mind $1000 or $10000).
Personally I’d look through old posts in r/scams, since they have a bigger archive than Tildes. But several things set this off for me:
This is probably the main recommendation I would emphasize. Even take it a step further and say that, if you are the person being contacted, you should be the one providing the meeting link whenever possible. At the very least, you should choose the channel you are comfortable using and verify that any link shared by the other person is a legitimate, official link for that platform.
Also be prepared to double down "in case they have a technical problem with your link and they totally have one that works..."
Basically don't click links you didn't source yourself. If you must click one, setup a VM preferably a Linux one (not that you can't pwn a Linux computer but it takes more effort and most auto attack stuff is exploited on windows)
I would redact that link or make it not clickable here. If that is the exact link, it’s definitely URL Phishing since it’s a typo of “joininvite”.
I’ll try to grab a (trusted) resource on that type of attack and reply to my own comment with it.
This is is a link to some related information on a similar “fake update”, https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc, though likely more sophisticated than the one aimed at your friend.
Your friend did everything right by trying to update “out of band”.
Unfortunately, as nukeman mentioned, with LLMs it’s gotten a lot easier and cheaper to tailor phishing towards basically anyone with a public presence.
Thanks so much! Sent her this link
Ah good point, I pasted in some zero-width spaces
Thanks!