The scam works by sending calendar invitations via email to work or personal addresses. Even if the email is missed or sent to spam, the event can appear automatically in apps such as Google Calendar, which may add invitations without requiring the user to accept them.
Luke Wescott, a threat detection engineer at Sublime Security, said the technique was still relatively new but the company had seen "exponential growth".
The scam takes several forms, including a fake meeting or a prompt to renew a service. When users click on the entry and follow a link to more details, they land on a website that asks for login details. Handing over credentials allows fraudsters to sell the information, break into work email accounts, or impersonate trusted institutions.
"Calendar apps, such as Google Calendar, can add invitations automatically without users even accepting them," Wescott said. "So scammers don't even need you to open an email."
Security experts advise users to treat unexpected calendar entries with the same caution as suspicious emails, and to check with the organiser before clicking any links.