The Better Business Bureau is warning about a sophisticated “You’re Invited” phishing wave — fake e-vites that look like Evite, Paperless Post, or Punchbowl and push Houston-area and nationwide victims to hand over email passwords or one-time codes. The FTC published the same pattern in a May 26, 2026 consumer alert; local TV (including Houston-market coverage) has kept the warning in rotation through summer party and graduation season.
This is not a duplicate of any prior EmailMeNow article — we have no earlier “You’re Invited” / e-vite phishing post.

Snapshot
| Field | Detail |
|---|---|
| Scam name | “You’re Invited” fake e-vites |
| Brands impersonated | Evite, Paperless Post, Punchbowl |
| Channels | Email + text |
| Goal | Steal email login / OTP → take over inbox → spam contacts |
| Who is warning | FTC, BBB, invite platforms, local TV |
| Houston angle | Consumer coverage amplifying the BBB/FTC alert for the metro |
How the scam works
- You get an unexpected invite that names a neighbor, coworker, or “special celebration.”
- The link opens a page that looks like a real invite platform.
- You’re told to log in, enter a security code, or download a file just to see details.
- Attackers use the credentials to reset accounts or blast the same lure to your address book.
Paperless Post has said it still sees hundreds of scam reports a week — tiny versus real volume, but enough to keep the FTC and BBB repeating the message.

Red flags
| Red flag | Why it matters |
|---|---|
| Password required to view the invite | Real platforms do not need your email password to open an RSVP |
| Ask for a one-time code / phone to “RSVP” | Account-takeover / SIM-reset bait |
| Download an attachment to see the event | May install remote-access malware |
| Vague party, no verifiable host | Social engineering without a callback path |
| Sender is Gmail / Yahoo, not the platform | Evite and peers say check the From address first |
What Houstonians and Texas employers should do
- Call the supposed host on a known number before clicking.
- Never enter an email password or OTP on an invite link.
- Turn on MFA on email and banking.
- If you already entered a password: change it from a clean device, review forwarding rules / sent mail, and warn contacts.
- Report to ReportFraud.ftc.gov, BBB Scam Tracker,
reportphishing@apwg.org, and texts to 7726.
Independent cybersecurity audits
We audited domains tied to this alert on July 25, 2026. 100% is the ideal — none reach it. Scores are public email / transport / website posture, not proof an invite link is safe.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| Paperless Post | paperlesspost.com | 76% | 65% | 50% | 90% | −24 |
| Evite | evite.com | 75% | 90% | 15% | 62% | −25 |
| FTC | ftc.gov | 72% | 95% | 45% | 40% | −28 |
| BBB | bbb.org | 68% | 45% | 45% | 92% | −32 |
| Punchbowl | punchbowl.com | 52% | 50% | 15% | 37% | −48 |
How to read this table: Strong scores on evite.com / paperlesspost.com do not make a password prompt legitimate — scammers impersonate those brands. ftc.gov / bbb.org are the warning publishers.
Audit links: paperlesspost.com · evite.com · ftc.gov · bbb.org · punchbowl.com
Website stack note
Passive website-tech probes on July 25, 2026 (1 notable in this set):
| Domain | Stack signal |
|---|---|
| ftc.gov | Drupal 10 — major version behind latest 11.x (notable) |
| evite.com | Webflow (vendor-managed SaaS) |
| paperlesspost.com | Next.js (version not exposed) |
| bbb.org / punchbowl.com | No notable public CMS / PHP / short-horizon TLS flags |
An outdated Drupal major on ftc.gov is a hygiene signal on the consumer-protection site — it does not change the advice: never enter your password to open an invitation. Point-in-time only; not proof of exploitability.
Related
Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.
Sources: FTC — party invite phishing · CBS Chicago / BBB — You’re Invited red flags · ABC13 Houston — FTC party invite warning