Phishing is getting harder to spot.
Not because the emails look better—but because they’re often completely legitimate.
A recent pattern shows attackers compromising real email accounts and using trusted platforms like Punchbowl to send invitations that lead to credential theft.
No spoofed domains. No obvious red flags. Just a clean, believable flow.
What the Attack Looks Like
It starts with a compromised email account.
From there, the attacker:
- sends a real Punchbowl invitation (or similar service)
- targets contacts already in the victim’s inbox/history
- uses a harmless-looking message like “Save the Date” or “Invitation”

The email itself passes all checks:
- valid sender
- proper authentication (SPF, DKIM, DMARC)
- trusted domain (Punchbowl)

Nothing looks suspicious.
---
The Trap
When the recipient clicks the invitation, they are taken through a flow that looks like a normal document or invite experience.
Then comes the pivot:
- a prompt to “log in to view the document”
- branded as Outlook, Office365, or another provider

At this point, everything feels legitimate:
- the email was real
- the branding looks familiar
- the context makes sense
So users enter their credentials.
And that’s the breach.
Why This Works So Well
1. It Comes From a Real Account
This isn’t spoofing.
The message comes from:
- someone you know
- a real conversation thread
- a legitimate email provider
That kills most skepticism immediately.
2. It Uses a Trusted Platform
Punchbowl is a legitimate service.
That means:
- links aren’t flagged
- domains aren’t blocked
- security tools trust the traffic
Attackers are piggybacking on that trust.
3. The Flow Feels Normal
Nothing feels out of place:
- invitations → click to view
- documents → login required
This mirrors real workflows people use every day.
4. It Bypasses Traditional Defenses
Most email security focuses on:
- malicious domains
- suspicious attachments
- known phishing patterns
But here:
- the domain is clean
- the email is valid
- the content looks normal
So it gets through.
The Bigger Shift
This is part of a larger trend:
Attackers are no longer faking legitimacy—they’re using it.
Instead of building phishing infrastructure, they:
- compromise accounts
- leverage trusted SaaS platforms
- insert themselves into real workflows
This makes detection much harder.
What This Means for Your Organization
If your defense relies on:
- blocking bad domains
- scanning attachments
- detecting obvious phishing
You will miss attacks like this.
Because there’s nothing obviously “bad” to block.
How to Reduce the Risk
1. Focus on Behavior, Not Just Content
Train users to question:
- unexpected login prompts
- invitations that require credentials
- anything that breaks normal flow
Even if it looks legitimate.

2. Verify Out-of-Band
If something feels even slightly off:
- confirm via another channel (Slack, phone, etc.)
Especially for:
- shared documents
- invitations
- requests involving login
3. Harden Accounts
Since this starts with account compromise:
- enforce MFA everywhere
- monitor login anomalies
- detect impossible travel and unusual access
4. Limit Credential Reuse
Even if credentials are stolen:
- SSO + MFA can limit impact
- segmentation reduces blast radius
Final Thought
This attack doesn’t rely on tricking filters.
It relies on tricking people—using tools they already trust.
That’s what makes it dangerous.
And that’s why security awareness needs to evolve:
It’s no longer about spotting fake emails.
It’s about recognizing when a real interaction is being abused.

