The FTC Is Warning About Fake Party Invitation Scams Arriving by Email and Text
Criminals are sending convincing fake event invitations to steal personal information. Here is what the scam looks like and how to avoid it.

Key points
- The Federal Trade Commission issued a warning in 2025 about fake party and event invitation scams sent by email and text.
- Phishing messages disguised as RSVPs trick people into handing over passwords or payment information.
- Victims are lured by what looks like a genuine invitation to a birthday party or wedding.
- The FTC advises verifying any unexpected invitation directly with the supposed sender before clicking anything.
The Federal Trade Commission, the US government agency that protects consumers from fraud, is raising the alarm about a scam that hides behind something almost everyone receives: a party invitation.
Criminals send fake invitations by email and text, made to look like real RSVPs from people you know. They're not. Click the link or fill out the form it leads to, and your personal information goes straight to whoever sent it.
That's phishing: sending a fake message that impersonates someone trustworthy to trick you into giving up private details like your name or payment card number. Our earlier report on TA558 targeting hotels and airlines with fake booking emails showed the same playbook used at industrial scale against travel companies. Party invitations are just a more personal version of the same trick, and harder to dismiss.
The social packaging is what makes this one awkward to catch. A message about an upcoming birthday doesn't set off alarm bells the way a suspicious bank transfer might. That's the point.
NBC News Tech, which flagged the FTC's warning for a broad audience, noted the scam circulates across email and SMS, so no single platform is safe.
How can you tell a real invitation from a fake one?
Go around the message entirely. Contact the supposed host by phone or through a separate message you start yourself. Don't reply to the suspicious message and don't use any contact details inside it.
Other signs to watch: the message demands an immediate RSVP. The link doesn't match a real event platform or anyone you recognise. The sender's address or phone number isn't saved in your contacts.
Should you worry if you already clicked?
Yes, and act quickly. Change any passwords connected to information you entered. Entered payment card details? Call your bank straight away.
For everyone else, the practical step is simple: treat any unexpected invitation the same way you'd treat an unexpected bill. Pause, and check the source through a channel you already trust.
What matters most here is the vector, not the lure. Fraudsters keep repackaging phishing as something socially normal, whether that's a travel booking or a wedding invitation, because social context suppresses suspicion. The FTC warning is worth heeding, but the real habit to build is source verification before any click, regardless of how friendly the message looks.



