A couple of days ago, I received an email from a client whose site I’ve been managing for over a decade, but who doesn’t have much reason to contact me on a regular basis, because, not to brag, but generally when I build something, it just works.
The subject line was BID PROPOSAL (in all caps), so my immediate thought was, ah crap, they’re planning to redo their website and they’re not just automatically giving the project to me. Bummer. But at least they still want to consider me.
Here’s the message:

I should have immediately suspected the curious phrasing of “Kindly review” but I was too concerned about the nature of the message to focus on that detail. In retrospect, I also should have been suspicious that the “To” field was addressed to herself and I was listed in the “Bcc” field but, then again… if you’re blasting this out to a bunch of different people, that would be the easiest way to do it.
But then, if that was the case, the “inform me if any modifications are required” bit wouldn’t make any sense. Never mind any of that though, this was late in the afternoon and I was sitting on a beach reading this, so I wasn’t exactly giving it my full level of concentration.
I opened the PDF and was confused, because it looked like a special invitation to some kind of private event. I became convinced that the client meant to send this to someone else who has my same first name — that happens to me a lot. So, not yet thinking anything was untoward (which, again, I probably should have already), I replied:

Very quickly she replied:

OK, so, at this point, I was finally starting to get suspicious, but mostly I was just so confused by it all that I wasn’t thinking clearly. “Thank you for reaching out!” certainly seemed odd.
Anyway, I took another look at the PDF, was still confused by the vague wording of it and the fact that it didn’t come right out and say what I would be submitting a proposal for, but since this isn’t a client I want to lose, I ignored the nagging feeling that something wasn’t right.
There was a link in the PDF to access the full details, so I clicked it. (Again, it’s all so obviously “off” in hindsight, but in the moment I kind of just went with it.)
The link initially went to a Cloudflare CAPTCHA page, which wasn’t entirely surprising, and I was mainly thinking, wow, they are really being excessively cautious with this whole thing.
And then it happened. The moment that shook me out of my beach vibes stupor. It took me to the Google account login screen. Or, at least, a page that fully appeared to be the official Google account login screen. Hence that bit in the last email about having to “authenticate using your email address.”
Uh yeah… no way. Sorry phishing scammers. I may be getting old and clueless, but I’m not that old and clueless. I immediately closed the window, deleted my cookies, cleared my cache, and even restarted my computer for good measure.
Then I checked the raw source of the original email, and it did appear to originate from this client’s legit email account, so it was obvious at that point that she must have gotten hacked. Instead of replying any further to the email chain, I sent an email to her boss, saying I had just gotten a really suspicious email from her and asking if she had been hacked.
The next day he replied, confirming that was the case.
Now, of course, I suppose it’s possible that I got infected with a virus by even opening that PDF, but… I doubt it. These scams are all about social engineering. Why bother writing a virus when you can just convince someone to hand them your Google login credentials?