Announcements Icon

c/announcements

Local Instance
[email protected] • 18,400 members • Official administrative board
SECURITY lantern_staff u/lantern_staff • Dec 14, 2024 • 6 replies

Emergency: Phishing Campaign Targeting Members

⚠️ Active Threat Alert

We have identified an active phishing campaign targeting Lantern members. Attackers are sending DMs containing links to fake login pages that mimic The Lantern's authentication system.

Indicators of Compromise
  • DMs from accounts created within the last 7 days
  • Links to domains: thel4ntern-login[.]com, lantern-auth[.]org
  • Login pages requesting both username AND password on the first page (the real site asks for username first, then password on a second screen)
  • Some messages reference "account verification required" or "policy violation — confirm your identity"
What You Should Do
  1. Do NOT click any links in unsolicited DMs
  2. Enable 2FA on your account immediately if you have not already
  3. If you entered credentials on a phishing site, change your password right now and enable 2FA
  4. Report any suspicious DMs using the report function

We are actively working to take down the phishing domains and have reported them to the relevant registrars. Updates will be posted in this thread.

Replies (6)
arcadeghost
u/arcadeghost • Dec 14, 2024

I got one of these yesterday. The domain was thel4ntern-login[.]com — noticed the "4" instead of "a" immediately. Almost clicked it too because the message said my account would be "suspended within 24 hours" if I did not verify. Glad I double-checked the URL first.

new_crypto_buyer
u/new_crypto_buyer • Dec 14, 2024

I think I fell for this. I clicked the link and entered my username and password. I did not notice anything wrong until I was redirected to a generic page. What should I do now? I already changed my password but I am panicking a bit.

lantern_staff
u/lantern_staff SECURITY • Dec 14, 2024

u/new_crypto_buyer — do not panic, you did the right thing by changing your password immediately. Please also enable 2FA if you have not done so already. If you had any marketplace payment tokens saved in your account, remove and regenerate them. We are monitoring for any unauthorized access on compromised accounts.

neon_drift
u/neon_drift • Dec 14, 2024

Tip for everyone: if you use a password manager, it will not autofill credentials on a domain that does not match the one saved in your vault. This is one of the easiest ways to spot phishing pages. If your password manager does not offer to fill, that is a huge red flag.

terminal_sage
u/terminal_sage • Dec 15, 2024

I ran the phishing domains through VirusTotal and they are already flagged by 12+ AV engines. The registrar is Namecheap — they are usually responsive to abuse reports. Has anyone checked if the phishing pages are still live? I can set up a canary cookie to track if they are still harvesting.

pixel_wraith
u/pixel_wraith • Dec 15, 2024

Just want to add — the phishing DM I received had perfect grammar and formatting. It did not have the usual spelling mistakes you see in phishing attempts. These attackers are getting more sophisticated. Everyone needs to be extra vigilant about checking URLs, even when the message itself looks legitimate.