top of page

Phishing Campaign Identified: How OSINT Exposed a Real Calendly Link in a Fake Bloomberg Interview invite trough a x.com DM

Writer: Nico Dekens | dutch_osintguy
Nico Dekens | dutch_osintguy
6 minutes ago
10 min read

How a fake Bloomberg interview invite used a genuine scheduling platform, a borrowed profile image and credential-harvesting (phishing) infrastructure to target people working in AI and OSINT.

Safety note: This article documents a live phishing campaign. Indicators are rendered as plain text where possible. Do not submit the scheduling form, enter credentials, or approve an OAuth request.

Most phishing advice starts with the same line: check the domain.


That is still good advice. It was not enough here.


The link I received was on a real domain: Calendly. The page loaded on genuine Calendly infrastructure. It had normal branding, a normal-looking form and a normal HTTPS connection.


The phishing was not in a misspelled URL.


The phishing was in the chain.


THE PHISHING MESSAGE


I received a DM on X from @Conviasa, using the display name Liv Conviasa and a blue checkmark. The message claimed to come from Bloomberg:


“Hey Nico, Liv from @Bloomberg. We’re looking at how OSINT is used as AI makes it easier to gather, analyze, and verify information at scale. Would love your take on where this shift is heading.”
A phishing DM sent on x.com
The DM

It was tailored.


Not “hello dear.” Not a crypto giveaway. Not an obvious fake job offer.


It mentioned OSINT, AI, gathering, analysing and verification: topics that sit directly inside my work. After I replied, the account proposed a short meeting with its team and sent a Calendly link.


That is the point where a lot of people lower their guard.


The account looks established. The message is relevant. The link is Calendly. The conversation has already started. That is exactly why this works.


THE PROFILE WAS PART OF THE LURE


The account presented itself as a Bloomberg correspondent focused on technology, AI and startups. Its profile image appears to be a cropped reuse of an image from a random Instagram post:


A stolen image from Instragram used as profile picture by the phishing account on x.com
The image that was used/stolen

That matters, but it needs to be described correctly.


A reused image is not, by itself, proof of who operates an account. A blue checkmark is not proof of identity either. X says its blue check generally indicates an active Premium subscription and does not mean the account has been ID verified.



In this case, the image reuse sits next to a false media affiliation, a targeted interview pretext and a known phishing link. The assessment comes from the combination.


Do not treat profile age, follower count or a subscription badge as identity documents.


THE CALENDLY PAGE WAS GENUINE. THE DESTINATION WAS NOT.


The link delivered in the DM was:


calendly[.]com/d/d336-3mq-q2z


The page presents a routing form asking for a name and a meeting type. Its visible choices are “Collaboration” and “Press Release.” Nothing about that first page looks like credential theft.


That is because it is not pretending to be Calendly.


It is Calendly.


The documented abuse happens after the form is submitted. A public investigation of this exact URL recorded a redirect into an X OAuth authorization flow for an app called Events Portal. The app claimed eventsportal[.]com, while its callback pointed to plugins[.]cal-apis[.]com.


A legitimate service can be used as one stage in a malicious workflow.


Checking the first domain is necessary. It is not the end of the analysis.


THE OPERATIONAL HOST: PLUGINS[.]CAL-APIS[.]COM


I investigated the infrastructure without submitting the Calendly form, authorizing an app or entering credentials.


The root domain cal-apis[.]com was registered on 16 September 2026 through Dominet (HK) Limited, via an Alibaba Cloud registrar channel. Its authoritative nameservers are Cloudflare’s bill.ns.cloudflare[.]com and paige.ns.cloudflare[.]com.



The relevant host is the subdomain plugins[.]cal-apis[.]com.


It resolves through Cloudflare and redirects to /login. The active page identifies itself as “Twitta” and asks for a username and password. Its form submits those credentials back to the same host.


That is not an X login.


It is not a beta product.


It is a credential-harvesting page using a Twitter-like name and visual cue.


The domain had a Let’s Encrypt wildcard certificate for *.cal-apis[.]com, meaning the operator can add further subdomains without obtaining a separate certificate for each one. At the time of review, public VirusTotal records showed plugins[.]cal-apis[.]com as the only indexed subdomain and no vendor detections.



That is not a clean bill of health. It is a reminder that new phishing infrastructure often exists before reputation systems catch it.


The claimed app website, eventsportal[.]com, is currently a GoDaddy domain-for-sale page. It does not appear to be the operational phishing host. It looks like credibility material in the OAuth app metadata. The infrastructure that matters in this case is plugins[.]cal-apis[.]com.


THIS WAS A CAMPAIGN, NOT A ONE-OFF


Public X replies show that @Conviasa used this interview-to-DM pattern against people working in AI, developer tooling, research, robotics, startups and AI safety.


The earliest public reply I could directly verify was posted on 19 August 2026, to Dan Shipper. The wording is already familiar:


“Your perspective on how AI is changing the future of work is really interesting. I’m writing an article and your insight is needed. DM me if you’re open to chatting.”


The operator changes the topic to fit the target. The mechanism stays the same.


• AI coding agents for developers and software builders.

• Reinforcement learning and agentic AI for researchers.

• Robotics for robotics people.

• AI safety and alignment for safety researchers.

• Startups and future-of-work language for founders and writers.

• OSINT and AI for me.


In public search results, I identified at least 99 likely reply recipients. This is a lower bound, not a definitive victim list. A public reply proves that the account addressed someone publicly. It does not prove that the person replied in DM, received the Calendly link, clicked it or was compromised.


The list of targeted accounts I was able to identify:


They are accounts that appeared as public reply targets of @Conviasa in indexed results. They are not a victim list and should not be read as evidence that any person received a DM, clicked a link or was compromised.


@0xtonixie, @10xmylife, @adamgries, @agarwl_, @andrew__reed, @ashleymayer, @ashtom, @astaxie, @billtheinvestor, @bleysg, @Blonskr

@bremen79, @brivael, @camillericketts, @celinehalioua, @cellier_, @cloudwu, @colinwu, @danshipper, @decohack, @devonzuegel, @doomie

@ericjang11, @Fenng, @gallabytes, @GenAI_is_real, @geoffreyirving, @GillVerd, @goodhunt, @henryquantum, @interjc, @Ion_Mio_, @jamesqquick

@jbhuang0604, @jefrankle, @jessethanley, @jessyshen, @Jilles, @jorandirkgreef, @kagigz, @kalashvasaniya, @Khazix0918, @kliu128, @kushalbyatnal

@leerob, @LiamFedus, @LinearUncle, @lulumeservey, @lxfater, @m_bourgon, @maithra_raghu, @MakerThrive, @MariusHobbhahn, @matt_gray_, @mattzcarey

@mehul, @MiaAI_lab, @minney_cat, @mitsuhiko, @mr_r0b0t, @mtrainier2020, @NaderLikeLadder, @ninklefitz, @ohyishi, @orca_so, @osanseviero

@owl_posting, @paw_lean, @penberg, @peng_hellen, @PhilippSpiess, @q_yeon_gyu_kim, @realDanFu, @realPureNomad, @RonVonng, @RookieRicardoR, @rronak_

@RyanCarniato, @samselikoff, @sarthakgh, @sjwhitmore, @skywind3000, @sobedominik, @stephenbalaban, @stephmui, @steveruizok, @stolinski, @tanayj

@thesephist, @TheZvi, @tison1096, @tualatrix, @vivianmshen, @wjmzbmr1, @wufantouzi, @Xianbao_QIAN, @Yun_HDY, @Zachly, @zty0826


X’s public reply timeline is login-gated, and web indexes are incomplete and can miss deleted, unindexed or later replies.


The public reply creates legitimacy. The flattering topic creates engagement. The DM removes the conversation from public view. The Calendly link creates a normal-looking next step.


The link is not the beginning of the operation. It is the final nudge after the social engineering has already done its work.


Examples that remain publicly visible:


• AI coding agents / indie software: https://x.com/Conviasa/status/2092830578932339036

• Software and the technology industry: https://x.com/Conviasa/status/2092720892849594397

• A public report warning that the account had already been reported: https://x.com/JeffLadish/status/2101795356828692856

• A later warning describing bulk Bloomberg-impersonation DMs: https://x.com/AI_Jasonyu/status/2105312308335669270


WHAT THE OSINT EVIDENCE SUPPORTS - AND WHAT IT DOES NOT


The X DM and screenshot support that the account used a Bloomberg/OSINT interview pretext and sent the Calendly link. They do not reveal who is physically operating the account.


The reused profile image supports that the displayed image appears sourced from a public Instagram post. It does not identify or locate the operator.


Public replies support a repeated public interview-to-DM pattern aimed at relevant people. They do not show which targets continued privately or were compromised.


The exact Calendly URL has been publicly documented in an OAuth-phishing chain. That does not prove every visitor sees an identical downstream flow.


The plugins[.]cal-apis[.]com login page supports that an active fake “Twitta” credential form exists on the reported callback infrastructure. It does not establish the full scope of every credential, token or data item collected.


Registration and DNS records support that the domain is newly registered and fronted by Cloudflare. They do not attribute the operation to a person, group or country.


The correct conclusion is not “we know who did it.”


The correct conclusion is this:


The available evidence is consistent with an ongoing, targeted phishing campaign using a false Bloomberg persona, legitimate Calendly infrastructure, an OAuth lure and active credential-harvesting infrastructure.


That is already enough to report it.


WHAT ELSE CAN WE LEARN FROM AN OSINT OR CTI ANGLE?


This is where the investigation becomes useful beyond a single screenshot. The objective is not to chase an identity claim. It is to preserve evidence, map the campaign safely, improve detection and make abuse reports actionable.


1. Preserve a proper OSINT evidence package


Capture the complete X profile and DM thread, including the account handle, display name, URL, timestamp, follower count and link preview. Save the material as PDFs or WARC captures where possible, not only screenshots. Record the timezone and hash the files with SHA-256.


An evidence log should record what was collected, from where, when and by whom. This makes the material more useful for a platform report, a journalist or an incident-response team.


2. Pivot on phishing infrastructure without interacting with the lure


Use passive sources to examine certificate transparency, historical DNS, registration data and URL reputation. Look for additional subdomains under cal-apis[.]com, new certificates, changes in nameservers, and domains sharing the same technical patterns.


Useful pivots include certificate serial numbers, certificate timestamps, page title, favicon hash, JavaScript hashes, form action, registrar, registration timing and nameserver pair.


These pivots can identify related infrastructure. They do not prove who owns or operates it.


Do not submit the Calendly form, authenticate, approve OAuth permissions or test the login page with credentials. Passive collection is both safer and more defensible.


3. Map targeting, not “victims”


Build a campaign table with the public target handle, relevant source post, reply text, timestamp, topic, and whether the reply asks for a DM. Only record public information and label the result “publicly approached accounts.”


Do not label someone a victim without their confirmation. Do not contact every possible target unsolicited. A public warning and accurate reporting are usually more helpful.


4. Create detections and conduct a look-back


For an organisation, block cal-apis[.]com and *.cal-apis[.]com at DNS, proxy and endpoint layers. Search DNS, proxy and browser telemetry for the domain, subdomain and related URLs. Review X connected applications and unusual login or OAuth activity around the time the lure was received.


If someone approved the app, revoke unfamiliar connected applications immediately and review active sessions. If a password was entered at the “Twitta” page, reset it anywhere it was reused and enable multi-factor authentication.


5. Report the chain, not only the account


Report the X account, the DM, the Calendly path, the OAuth app metadata, the callback host and the credential page. Different providers can act on different pieces of the chain.


Cloudflare phishing reporting: https://abuse.cloudflare.com/phishing


For cal-apis[.]com, the public RDAP record lists domainabuse@service.aliyun.com as registrar abuse contact.


6. Share indicators responsibly


Share a concise incident package with timestamps, screenshots, hashed files, the exact defanged indicators, a short behaviour summary and confidence labels. Use careful language: “observed,” “publicly documented,” “consistent with” and “not established.”


The goal is to help someone block, investigate or report the campaign—not to overstate an attribution.


A PRACTICAL WORKFLOW WHEN THE INTERVIEW REQUEST LOOKS REAL


1. Preserve before you investigate.


Take screenshots of the DM and profile. Record the date, time, account handle, display name, profile URL and exact link. Keep the original message unchanged. If you save a file, hash it.


2. Verify the claimed affiliation independently.


Do not use contact details supplied by the sender. Find the alleged journalist through the publication’s staff page, author archive, official newsroom contact channel or verified corporate account. Check for a byline, author page, work email and public history that matches the claimed expertise.


3. Treat the next click as a new decision.


Ask what happens after the page. Why would a scheduling request need an X, Google, Microsoft or Facebook login? Why would a meeting request need broad account permissions? Does the callback host belong to the organisation you expect?


A calendar invite does not need your social-media account.


4. Read the permission request.


OAuth screens are designed to look official because they often are official. The danger may be an official platform asking you to authorize an attacker-controlled app.


Read the app name, developer identity, requested permissions and callback domain. If the request is unexpected, decline it and verify first through a known contact channel.


5. Report the chain, not only the account.


Report the X account, original DM, Calendly path, callback host and credential page. Separate reports help different providers see the same campaign.


IF YOU ALREADY CLICKED


Opening a page is not the same as handing over an account. The risk changes with the action you took.


• You only opened the Calendly page: close it. Do not submit the form or authorize anything.

• You submitted the form but rejected the next permission request: your submitted form data may be known to the operator, but you should not have granted account access through that authorization step.

• You approved an OAuth request: revoke unfamiliar connected apps immediately at https://x.com/settings/applications, change your X password and review active sessions. X guidance: https://help.x.com/en/managing-your-account/connect-or-revoke-access-to-third-party-apps

• You entered a password into the “Twitta” page: change that password immediately anywhere it was reused, enable multi-factor authentication and review active sessions and recovery details.


Do not wait for a strange post from your account before acting.


INDICATORS AND REPORTING PIVOTS


  • X account: @Conviasa

  • Display name: Liv Conviasa

  • Claimed affiliation: Bloomberg

  • Calendly lure: calendly[.]com/d/d336-3mq-q2z

  • OAuth app name: Events Portal

  • Claimed app website: eventsportal[.]com

  • Operational phishing host: plugins[.]cal-apis[.]com

  • Credential page title: Sign in — Twitta

  • Credential path: /login

  • Parent domain: cal-apis[.]com

  • Registration date: 2026-09-16T12:34:51Z

  • Registrar: Dominet (HK) Limited / Alibaba Cloud channel

  • Cloudflare nameservers: bill.ns.cloudflare[.]com and paige.ns.cloudflare[.]com


Treat indicators as pivots, not magic answers. Cloudflare IP addresses, Let’s Encrypt certificates and generic registrar details are useful for reports and correlation. They are not evidence of operator identity by themselves.


FINAL THOUGHT


The most effective phishing messages are not always badly written.


Sometimes they are researched.

Sometimes they quote your work back to you.

Sometimes they arrive through an account that looks older than it is trustworthy.

Sometimes the first link is real.


That does not make the next step safe.


Preserve the evidence. Verify the person independently. Follow the workflow, not only the domain. Read the permissions. Stop when the request no longer makes sense.


Because a source does not need to lie about every part of the chain.


It only needs you to trust the wrong part.


SOURCES AND LIMITATIONS


This article is based on preserved screenshots, passive review of public web and DNS records, publicly indexed X replies, and the publicly available analysis of the exact Calendly link cited above. I did not submit the Calendly form, authorize the OAuth app, enter credentials or attempt to identify the real-world operator.


The public reply-recipient list is not a victim list. It records accounts that appeared in public search results as recipients of the account’s interview-to-DM replies. It does not establish private contact, link delivery, clicking or compromise.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page