Cybersecurity Experts Warn of Rising Calendar Phishing Scams
Cybersecurity experts warn that fraudsters are using automatic calendar invitations to bypass security filters and steal user credentials through fake meeting links.
Cybersecurity experts are reporting an exponential growth in calendar phishing scams that insert fraudulent meetings or service renewal prompts directly into electronic calendars. The attacks often begin with email invitations that apps like Google Calendar may automatically add to a user's schedule without explicit acceptance.
Luke Wescott, a threat detection engineer at Sublime Security, Inc., explains that these entries mimic legitimate business meetings or payment warnings to create borrowed credibility. Once a user clicks a link within the event description, they are directed to fraudulent login pages for services such as PayPal, Google, or Microsoft to steal their credentials.
To evade security software and AI-backed blockers, some attackers utilize legitimate platforms like Zoom. Max Gannon, an intelligence analysis manager at Cofense, notes that the use of these trusted platforms makes the scams particularly difficult to block. Experts advise users to disable automatic invitation settings and avoid clicking decline, as doing so can confirm to attackers that an email address is active.