Calendar phishing scams surge as fake meetings trick users into handing over credentials

Threat detection engineer warns of 'exponential growth' as scammers exploit automatic calendar invites

By LineZotpaper
Published
Read Time2 min
A phishing scam that inserts fake meetings into users' electronic calendars is growing exponentially, according to security researchers, exploiting the trust people place in calendar entries to steal login credentials.

The scam works by sending calendar invitations via email to work or personal addresses. Even if the email is missed or sent to spam, the event can appear automatically in apps such as Google Calendar, which may add invitations without requiring the user to accept them.

Luke Wescott, a threat detection engineer at Sublime Security, said the technique was still relatively new but the company had seen "exponential growth".

The scam takes several forms, including a fake meeting or a prompt to renew a service. When users click on the entry and follow a link to more details, they land on a website that asks for login details. Handing over credentials allows fraudsters to sell the information, break into work email accounts, or impersonate trusted institutions.

"Calendar apps, such as Google Calendar, can add invitations automatically without users even accepting them," Wescott said. "So scammers don't even need you to open an email."

Security experts advise users to treat unexpected calendar entries with the same caution as suspicious emails, and to check with the organiser before clicking any links.

§

Analysis

Why This Matters

  • The scam exploits the inherent trust users place in calendar appointments, which appear alongside legitimate events like dentist visits or work meetings.
  • Automatic addition of invitations by calendar apps gives scammers a direct channel to victims without requiring an email click.
  • Credentials stolen through this method can enable further fraud, including business email compromise and bank impersonation scams.

Background

Calendar phishing is a relatively new variant of credential theft. Unlike traditional phishing emails, which users may be trained to spot, calendar entries feel familiar and often appear without explicit acceptance. The technique has been observed targeting both personal and work accounts. Sublime Security, a threat detection firm, has reported a sharp increase in incidents.

Key Perspectives

Users: Many are unaware that calendar invitations can be added automatically. Those who receive a meeting request from an unknown sender may still click the link because it appears in a trusted app. Security Researchers: Sublime Security and other firms highlight the rapid growth of this vector and warn that even tech-savvy users can be caught off guard. Calendar Providers: Platforms such as Google Calendar face pressure to adjust default settings so that invitations from unknown senders are not automatically added, reducing the attack surface.

What to Watch

  • Whether calendar app developers change default settings to require user acceptance before showing events from unknown senders.
  • The scale of reported credential thefts linked to calendar phishing over the coming months.
  • Additional variations of the scam, such as fake auto-renewal notices or meeting rescheduling prompts.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe