What's happened
Calendar phishing is on the rise as criminals embed fake invitations in calendar apps, using legitimate platforms to appear credible. Victims report fake meetings, voicemails, and service renewals that bypass filters and target individuals through internal-looking prompts. Experts warn of the growing sophistication and ongoing risk.
What's behind the headline?
Brief
- The pattern shows attackers embedding fraud within everyday tools, undermining user trust in calendar notifications.
- Security experts see this as a scalable tactic that leverages automation, AI-derived impersonations, and familiar interfaces.
- The core risk is credential exposure and subsequent targeted impersonation across services.
What this reveals
- The tactic exploits the human tendency to treat calendar invites as routine, bridging digital and real-world trust cues.
- Organizations must harden filtering while preserving legitimate scheduling, hinting at a need for improved anomaly detection and user education.
Forecast
- Expect new platform-level safeguards and stricter invitation handling; criminals may pivot to more integrated social engineering using AI-generated content. Readers should review calendar permissions and enable multi-factor authentication where possible.
How we got here
The Guardian reports on calendar phishing where scammers insert invitations directly into users’ calendars, sometimes via legitimate platforms like Google Calendar or Zoom. Victims can be tricked into clicking links or handing over login details, leading to access to work emails or personal accounts. Security professionals note exponential growth and the difficulty in blocking such invitations without affecting legitimate ones. Separately, UK and US fraud victims describe follow-on attacks, while authorities urge vigilance and standard security practices.
Our analysis
The Guardian reports on calendar phishing and includes insights from Sublime Security and Cofense; additional reporting from UK and US fraud victims illustrates follow-on scams and the evolving threat landscape.
Go deeper
- Are your calendar invites being filtered correctly by your security tools?
- Have you checked your recent calendar entries for unexpected meetings or renewals?
- What MFA steps could reduce risk of calendar-based credential theft?
More on these topics
-
The Guardian - Newspaper
The Guardian is a British daily newspaper. It was founded in 1821 as The Manchester Guardian, and changed its name in 1959. Along with its sister papers The Observer and The Guardian Weekly, The Guardian is part of the Guardian Media Group, owned by the S
-
United Kingdom - Country in Europe
The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom or Britain, is a sovereign country located off the northÂwestern coast of the European mainland.
-
Google - Technology company
Google LLC is an American multinational technology company that specializes in Internet-related services and products, which include online advertising technologies, a search engine, cloud computing, software, and hardware.