Skip to content
Discussion options

You must be logged in to vote

Your account is completely safe — you were not hacked.
When I read this, the first thing that came to my mind was my senior. He went through the exact same thing. When he told me about it I finally understood how convincing it looks because the email actually comes from notifications@github.com — GitHub's own domain, which is why it felt so real and official.
Here is what actually happened. A spam account created a fake repository, wrote a fake security alert Discussion with a made-up CVE number and researcher name, then mass @mentioned 30 plus random GitHub users including you. GitHub's own notification system delivered it straight to your inbox.
No token leaked. No breach. Nothing was c…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@minirang
Comment options

Answer selected by minirang
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
other General topics and discussions that don't fit into other categories, but are related to GitHub Question Ask and answer questions about GitHub features and usage source:ui Discussions created via Community GitHub templates Other Features and Feedback Discussions that fall into "Other" category
2 participants