A phishing scheme that plants fake appointments and bogus renewal reminders inside people’s digital calendars is growing sharply, cybersecurity researchers have warned.
Luke Wescott, a threat detection engineer at Sublime Security, said calendar phishing remains a comparatively recent tactic but that his firm has recorded what he called exponential growth in its use. The scam was detailed in reporting by Hilary Osborne for Guardian Money.
The fraud works by sending an invitation to a work or personal email address. Calendar applications are able to register such invitations on their own, so the message does not need to be opened, and it makes no difference if the recipient overlooks it or the email lands in a junk folder.
According to Wescott, services including Google Calendar can add invitations without any acceptance from the user, meaning fraudsters do not require the victim to open an email at all. He said an entry appearing alongside routine appointments, such as a dental check-up or a regular meeting with a manager, lends the invitation a form of borrowed credibility that a stranger’s email would not carry.
Titles vary widely. The Guardian reviewed examples that included fabricated meetings, alerts about voicemail messages, software renewal notices and invitations to submit bids on contracts. Wescott said warnings commonly seen include messages about a new voicemail, a payment receipt for a specific sum, unusual activity on PayPal, or an automatic payment scheduled to be processed within a day.
Max Gannon, an intelligence analysis manager at the cybersecurity company Cofense, said some scammers route their invitations through legitimate platforms such as Zoom, which makes them appear more convincing both to recipients and to security tools. That, he said, makes the invitations very difficult to block and even AI-backed filters struggle to catch them. Setting up a filter to exclude invitations from those platforms would in turn block genuine meeting requests, he added.
Gannon said an invitation can be made to look as though it originated inside the recipient’s own organisation, with customised content and the company’s logo attached.
The description attached to the calendar event typically carries either a link or a telephone number. Wescott said the aim is to draw victims to a fake login page for Microsoft, Google or PayPal so they hand over a password, or to persuade them to ring a support line and cancel a charge that never existed.
No compromise takes place until the recipient clicks the link or makes the call, and the scammers do not gain access to the contents of the calendar. The technique, Wescott said, is the same as standard phishing, simply delivered through a different channel.
Credentials harvested this way can be sold in bulk alongside other stolen data, used to break into a victim’s work email, or deployed to impersonate a bank or another institution, according to the report.
Anyone who finds an unexpected meeting or reminder is advised not to panic. Security professionals say it should be treated like an unsolicited email, with the link left untouched.
Gannon said his foremost advice is that people should be suspicious of every invitation, regardless of how familiar the apparent sender looks. Wescott recommended switching off automatic acceptance, noting that Google Calendar allows users to restrict acceptance to known senders or to invitations they have personally agreed to.
He also warned against pressing decline on a suspicious invitation, because doing so can signal to the sender that the email address is active. Deleting the entry or reporting it as spam or junk is the better course.







COMMENTS