My guess would be it's to build up reputation of the sending accounts, by being "connected" to trusted, aged, accounts? However, the combination of garbled text + number @ large provider on its own should be pretty suspicious by now. Another idea is some kind of affiliate marketing / pumping attack, but I don't see ads.
Kind of out there, but if you were running a network of agents that are autonomously looking for exploits, then perhaps those agents have decided that a good source of fresh ideas might be to periodically receive Schneier’s newsletter in an inbox they control.
> All Gmail. None of the addresses has actually subscribed to Crypto-Gram. They could; whoever is sending the emails could easily have confirmed the subscription.
My guess would be it's to build up reputation of the sending accounts, by being "connected" to trusted, aged, accounts? However, the combination of garbled text + number @ large provider on its own should be pretty suspicious by now. Another idea is some kind of affiliate marketing / pumping attack, but I don't see ads.
Yeah, I think you might be right. I was also thinking that it could be a weird setup of Moltbook-style LLM training?
Kind of out there, but if you were running a network of agents that are autonomously looking for exploits, then perhaps those agents have decided that a good source of fresh ideas might be to periodically receive Schneier’s newsletter in an inbox they control.
That would be a good guess but the post says:
> All Gmail. None of the addresses has actually subscribed to Crypto-Gram. They could; whoever is sending the emails could easily have confirmed the subscription.