the WORST phishing email i've ever seen

the WORST phishing email i've ever seen

🎙 John Hammond 👥 2.2M 📅 April 24, 2026 ⏱ 21 min 👁 46K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingFacebookMetacybersecurityanalysis

Summary

John Hammond analyzes a phishing email that appears to come from Facebook, exploiting a legitimate email template by embedding malicious URLs in the business name field. He demonstrates how the email triggers a genuine Facebook notification, making it appear credible. He then examines the phishing website, which is hosted on Vercel and protected by Cloudflare, and walks through the process of submitting fake credentials to observe the backend behavior. He discovers that the site uses client-side JavaScript to encrypt data with AES and sends it to an API endpoint, which likely forwards it to Telegram. He decodes the encryption using the passphrase found in the code and shows the exfiltrated data. He also notes that many similar phishing sites are already offline. The video includes a sponsor segment for Vanta, a compliance automation platform. Hammond concludes by rating the phishing email as clever but the website as poorly constructed, advising viewers to ignore such emails.

155 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the mechanics of a phishing campaign, particularly the use of legitimate email templates to bypass filters. The argumentation is solid, based on direct observation and technical analysis. Hammond demonstrates the entire process, from receiving the email to decrypting the exfiltrated data, which adds credibility. However, the analysis is anecdotal and does not provide broader context or statistics on the prevalence of such attacks.

78 words

Title / Content Match

The title accurately reflects the content, as the video dissects a particularly poorly constructed phishing email and website.

Quality & Reliability

8/10

The video provides a detailed technical analysis of a phishing campaign, including examination of the phishing website's code, network requests, and encryption methods. The analysis is hands-on and transparent, with the author demonstrating the process. However, the video is primarily based on the author's personal investigation and does not cite external sources or studies, limiting its generalizability.

Key Moments

Cited Sources

  • CodeCrafters — Mentioned as a resource for learning to code
  • CyberDefenders — Mentioned as a resource for blue team training and SOC analyst certifications
  • InfoSec Map — Mentioned as a resource for cybersecurity events
  • Newsletter — Mentioned as a way to stay updated
  • OpenVPN — Mentioned as a resource for hosting your own VPN
  • Just Hacking Training — Mentioned as a resource for learning cybersecurity
  • Vanta — Sponsor of the video, mentioned for compliance automation

Concurring Sources

  • Reddit post about similar phishing attempt — Mentioned in the video as a similar report from other users

Contribution & Novelties

The video provides a detailed, hands-on analysis of a phishing campaign that exploits legitimate email templates, offering practical insights into how such attacks work and how to analyze them. It demonstrates reverse-engineering techniques, including decrypting exfiltrated data, which is educational for cybersecurity enthusiasts.

Pour aller plus loin :

  • Phishing — Overview of phishing attacks and techniques.
  • AES encryption — Explanation of the encryption algorithm used in the phishing site.
  • Telegram Bot API — Documentation on how Telegram bots can be used for data exfiltration.

84 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-balanced video that is both informative and accessible.

Reliability 8/10

💬 Positif. Sur les 30 commentaires analysés, la majorité exprime amusement et appréciation de l'analyse, certains partageant des expériences similaires.