Calendar phishing scams surge: fraudsters exploit meeting invites to steal login credentials

It can create borrowed credibility by sitting in your calendar
Threat analysts explain why calendar phishing exploits trust that email-based attacks cannot.
Mark

So the scammer never actually gets into my calendar or my email unless I give them my password?

Mimi

Exactly. They're just sending an invitation that pops up in your calendar. The whole attack depends on you clicking the link or calling the number they provide.

Luke

But here's what matters: the invitation auto-populates without you accepting it. That's the technical vulnerability they're exploiting.

Mark

Why is that harder to block than regular phishing emails?

Mimi

Because legitimate services like Zoom also send calendar invitations that auto-populate. If you block all auto-populating invitations, you'd also block real meetings from your colleagues.

Luke

Right. The source says even AI-backed blockers struggle with this. That's a real constraint on the defense side.

Mark

So what's the actual risk if I give them my password?

Mimi

They sell it in batches to other criminals, or they use it to break into your work email directly, or they use it to impersonate your bank and manipulate you into sending money.

Luke

The source doesn't specify how often each of those happens or which is most common. We know it's a risk, but the scale of actual harm isn't detailed here.

Mark

And the advice is just to be paranoid and delete things?

Mimi

Basically, yes. And turn off auto-accept in your calendar settings so invitations require your approval first.

Luke

That's the technical fix. The behavioral fix is treating calendar invites like email—skeptical by default.

Mark

What if I accidentally click it before I realize it's fake?

Mimi

As long as you don't enter your credentials on the fake login page, you're still safe. The damage only happens when you hand over your password.

Luke

The source doesn't address what to do if you've already been compromised, though. That's a gap.

  • Calendar phishing is surging because fake invitations auto-populate directly into schedules without user acceptance, bypassing the skepticism most people apply to email.
  • The scams impersonate PayPal alerts, software renewals, internal company meetings, and voicemails — each designed to manufacture urgency and prompt an immediate click or call.
  • Security teams face a near-impossible dilemma: blocking invitations from platforms like Zoom would also block legitimate meeting requests, leaving a gap that even AI-powered filters struggle to close.
  • Victims who click phishing links or call fraudulent support numbers risk surrendering login credentials that can be sold, weaponised, or used to impersonate them further.
  • Experts urge users to disable auto-accept settings, apply email-level suspicion to every unexpected calendar entry, and delete — never decline — suspicious invitations to avoid confirming an active address.

In the quiet architecture of our daily schedules, a new form of deception has found its footing — fraudsters are now slipping counterfeit meeting invitations into digital calendars, exploiting the trust we extend to the tools that organize our working lives. Unlike the suspicious email from an unknown sender, a calendar entry feels woven into the fabric of routine, and that sense of belonging is precisely what makes it dangerous. Threat analysts describe the growth of this tactic as exponential, a reminder that every new layer of digital convenience becomes, in time, a new surface for exploitation.

On an ordinary Monday morning, a calendar entry appears that you don't remember creating — a project review, a link for details, a login page that looks entirely official. You enter your credentials. By the time doubt arrives, the damage is done.

This is calendar phishing, a tactic that threat detection engineer Luke Wescott of Sublime Security describes as growing exponentially. Its power lies in mechanics that feel mundane: a scammer sends a calendar invitation that populates your schedule automatically, no acceptance required, settling in beside your dentist appointments and team check-ins and borrowing legitimacy from the company it keeps.

The disguises vary — urgent PayPal warnings, software renewal notices, internal meetings dressed in your organisation's branding, voicemails demanding attention. Each leads either to a fake login page harvesting credentials for Google, Microsoft, or PayPal, or to a fraudulent support line where operators pressure victims to cancel charges that were never real.

What makes the attack so difficult to counter is the trust we instinctively extend to our calendars. Max Gannon of Cofense notes that scammers increasingly send invitations through legitimate platforms like Zoom, making them credible to both recipients and security software alike. Blocking such invitations indiscriminately would also silence genuine requests — an impossible trade-off for security teams.

Defence begins with a change in posture. Wescott recommends disabling automatic acceptance in Google Calendar and treating every unexpected entry with the same suspicion reserved for unknown emails. Crucially, he warns against clicking decline — doing so signals to the scammer that the address is active and monitored, raising its value as a future target. Delete it, or report it as spam. Gannon's counsel is simpler still: be paranoid. Until you click the link or dial the number, the scammers have nothing. The keys remain yours.

You're scanning your calendar on a Monday morning, coffee in hand, when you spot a meeting you don't remember scheduling. The title looks plausible—something about a project review. There's a link in the description asking you to click through for details. You do. The page that loads looks official enough, asking for your login credentials. You enter them. Only then does the reality settle in: you've just handed your username and password to criminals who will now sell that information to other fraudsters, use it to break into your work email, or impersonate a bank to manipulate you further.

This is calendar phishing, and it's growing fast. Luke Wescott, a threat detection engineer at Sublime Security, describes the trend as experiencing exponential growth, though the tactic itself remains relatively new to most people. The mechanics are straightforward but effective: scammers send a calendar invitation to your work or personal email address. Unlike traditional phishing emails that you might catch and delete, these invitations often populate your calendar automatically, without requiring you to accept them first. They sit there alongside your dentist appointments and weekly check-ins with your boss, borrowing credibility from their placement among legitimate events.

The invitations take various forms. Some impersonate internal company meetings, complete with your organization's logo. Others pose as urgent alerts—a PayPal warning about unusual activity, a notification that an auto-payment will process within 24 hours, a voicemail message waiting for you, a software renewal notice demanding immediate action. The descriptions typically contain either a link to a fake login page for Google, Microsoft, or PayPal, or a phone number for a fraudulent support line where operators will pressure you to "cancel" charges that never existed.

What makes this attack vector particularly difficult to defend against is how it exploits the trust we place in our calendar systems. Max Gannon, an intelligence analysis manager at Cofense, notes that some scammers are now using legitimate platforms like Zoom to send these invitations, making them appear more credible to both human recipients and security software. Blocking such invitations wholesale would also block genuine meeting requests from those same platforms, creating an impossible choice for security teams. Even artificial intelligence-backed email filters struggle to distinguish the fraudulent from the legitimate when the delivery mechanism itself is trusted infrastructure.

The attack works because it operates on a different channel than email, where most people have developed some skepticism. A calendar entry feels more official, more integrated into your workflow. You're less likely to question it the way you might question an unexpected email from an unknown sender. The scammers are counting on that psychological difference—the same social engineering technique as traditional phishing, just arriving through a different door.

Defense requires a shift in how you think about calendar invitations. Wescott recommends disabling automatic acceptance in Google Calendar, configuring it instead to accept invitations only from known contacts or those you've already accepted from before. More importantly, treat every unexpected calendar entry with the same suspicion you'd apply to an unexpected email. If you see something suspicious, don't click the link. Don't even click decline, Wescott warns, because declining tells the scammer your email address is active and monitored, making you a more valuable target for future attacks. Instead, delete it or report it as spam. Gannon's advice is blunter: "Be paranoid," he says. "It doesn't matter if the invitation looks like it came from someone two desks down. You've got to be suspicious of everything." Until you click that link or call that number, you remain uncompromised. The scammers have no access to your calendar or your accounts. They're simply waiting for you to voluntarily hand over the keys.

Calendar apps can add invitations automatically without users even accepting them, so scammers don't even need you to open an email.
— Luke Wescott, threat detection engineer at Sublime Security
It can create a borrowed credibility by showing up in the same place as your dentist appointment or a weekly meeting with your boss.
— Luke Wescott, Sublime Security
Contattaci Domande frequenti