A new wave of digital fraud is exploiting the trust users place in their daily schedules. Scammers are inserting fake meeting reminders and service renewal notices directly into electronic calendars, tricking victims into clicking malicious links that steal their login details. This calendar phishing scam has seen exponential growth, according to cybersecurity experts who warn that the technique bypasses traditional email filters by appearing in trusted scheduling apps.
How the Calendar Phishing Scam Works
The attack begins with an email containing a calendar invitation. Victims often do not even need to open the email or manually accept the event. Many calendar applications, including Google Calendar, are configured to automatically add invitations to a user’s schedule. This means the fraudulent entry appears in the victim’s view without any active engagement from them.
Once the entry is in the calendar, it creates a sense of borrowed credibility. The invitation might appear alongside legitimate appointments, such as a dentist visit or a weekly check-in with a manager. This context makes the fake request seem more urgent and legitimate. The event title often mimics standard notifications, such as “New voicemail received,” “Payment receipt confirmation,” or “PayPal unusual activity.” Some scammers even customize the content to include company logos, making the invitation look like an internal communication from within the victim’s own organization.
The description of the event typically contains a link or a phone number. Clicking the link directs the user to a fake login page for services like Microsoft, Google, or PayPal. Entering credentials on these sites hands over personal data to fraudsters. Alternatively, victims may be prompted to call a “support” number to cancel a charge that never actually existed. Until the user clicks the link or makes the call, their account remains secure.
Why Traditional Defenses Fail
Standard email security tools often struggle to detect these threats. Max Gannon, an intelligence analysis manager at Cofense, notes that some scammers use legitimate platforms like Zoom to send the invitations. This makes the requests appear trustworthy to both users and security software. Blocking invitations from these platforms would also block legitimate meeting requests, creating a difficult trade-off for system administrators.
Luke Wescott, a threat detection engineer at Sublime Security, describes the method as a variation of standard phishing. The core technique remains the same: luring the user to a fake site to enter their password. The innovation lies in the delivery method. By using the calendar, scammers exploit the fact that users check their schedules frequently and often treat calendar entries with less suspicion than unsolicited emails.
Steps to Protect Your Accounts
Experts advise treating unexpected calendar entries with the same caution as suspicious emails. If you see a meeting or reminder you do not recognize, do not click on any links or call any numbers provided. Instead, delete the invitation or report it as spam. Wescott warns against clicking “decline” on suspicious invites, as this confirms to the sender that the email address is active and monitored.
To prevent these invitations from appearing automatically, users can adjust their calendar settings. In Google Calendar, for example, users can opt to only accept invitations from known senders or require manual acceptance for all new events. Gannon emphasizes that paranoia is the best defense. “It doesn’t matter if the invitation has come from someone two desks down, you’ve got to be suspicious of everything,” he said.
As these attacks become more sophisticated, staying vigilant about unexpected digital requests is essential for maintaining online security.
Source: The Guardian


