Is this a spam mail? And has my account been hacked? #190674
-
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
Your account is completely safe — you were not hacked. |
Beta Was this translation helpful? Give feedback.


Your account is completely safe — you were not hacked.
When I read this, the first thing that came to my mind was my senior. He went through the exact same thing. When he told me about it I finally understood how convincing it looks because the email actually comes from notifications@github.com — GitHub's own domain, which is why it felt so real and official.
Here is what actually happened. A spam account created a fake repository, wrote a fake security alert Discussion with a made-up CVE number and researcher name, then mass @mentioned 30 plus random GitHub users including you. GitHub's own notification system delivered it straight to your inbox.
No token leaked. No breach. Nothing was c…