READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Calendar phishing surges as invites land on victims' schedules without a click

Calendar phishing surges as invites land on victims' schedules without a click
Security firms report fast growth in phishing scams that push fake meetings, voicemail alerts and billing notices straight into Google Calendar. Sublime Security's Luke Wescott calls the growth "exponential," and KnowBe4 Threat Labs puts the rise at 49% over six months. A single setting, "Only if the sender is known," blocks the main delivery route.

You open your calendar to plan the week. There's a meeting you don't remember. The description has a link, you click it, and a login page asks for your password.

That is calendar phishing. It is growing fast, and the delivery method is the part that should bother you.

The invite shows up without you doing anything

Scammers email a calendar request to a work or personal address. Calendar apps such as Google Calendar can add the event automatically, without the user accepting it.

"So scammers don't even need you to open an email," Luke Wescott, a threat detection engineer at Sublime Security, said. It doesn't matter if the email lands in spam.

Sublime Security says it has seen "exponential growth" in the tactic, which Wescott called still relatively new. The KnowBe4 Threat Labs report puts the surge at 49% over the past six months.

The entry then sits next to real appointments. "It can create a borrowed credibility by showing up in the same place as your dentist appointment or a weekly 1:1 with your boss," Wescott said.

What the lures look like

Titles vary. Wescott lists "New voicemail received," "Payment receipt confirmation – $298.99," "PayPal unusual activity" warnings, "Your auto-payment will be processed within 24 hours," and invitations to bid on a contract.

The event description carries either a link or a phone number. The link leads to a fake Google, Microsoft or PayPal login page. The phone number connects to a scammer posing as customer support who will "cancel" the bogus charge.

IRONSCALES research from March 2026 documented fake billing invites, one describing a "$399.77 CoreDefense Plus" charge, that told recipients to call a toll-free number. In those messages the links resolved to legitimate calendar.google.com addresses and the .ics attachment carried no executable payload. DKIM passed because Google signed the message. The phone number was the only red flag.

Stolen credentials get sold in batches, used to break into work email, or used to pose as a bank or another institution, according to the Guardian's reporting.

The attackers do not get calendar access. Nothing is compromised until the target clicks the link or makes the call.

Why filters struggle

Max Gannon, an intelligence analysis manager at Cofense, says some scammers send the invitations through legitimate platforms such as Zoom. "That makes it really hard to block," he said. "Even AI-backed blockers struggle."

Blanket-blocking those platforms would also cut off real meeting invitations, Gannon said. Gannon added that attackers can make an invite look internal, with customized content and a company logo.

The security firm cyberunit, which says it has seen Google Calendar phishing hit clients this week, makes a related point: because the invites come from Google's own infrastructure, they pass email authentication checks and often bypass spam filters. Sublime Security has documented that the calendar entry often stays on the target's calendar even after an email security tool quarantines the message.

Barracuda researchers said in August 2026 that attackers favor calendar invites because they exploit user trust, evade traditional email detection, and persist after the original email is gone.

A slower variant aimed at sales staff

Fortra researchers, in findings relayed by KnowBe4 on Oct. 7, are tracking a different version. The attacker poses as a prospective customer and contacts a non-sales employee, asking to be routed to a sales representative.

The attacker then sends a meeting-booking link and asks that it be forwarded. A sales rep receives it from a known colleague. The booking page asks for a date and time, then throws up a Microsoft 365 sign-in prompt framed as necessary to finish the booking.

"What makes this effective is not a clever email alone," Fortra said. "It is the trust chain." Fortra added that every step is individually familiar, so the full chain does not feel like phishing.

The fix is a setting

For individual users, Google Calendar Help directs you to Settings, then Event settings, then Add invitations to my calendar, then "Only if the sender is known." Events are then added automatically only if the sender is in your contacts, in your organization, or someone you previously interacted with.

For businesses, cyberunit says Google Workspace administrators have been able to enforce that setting organization-wide since August 2026, so employees cannot switch it back to allow invitations from everyone.

The default has historically been to add all invitations automatically, according to cyberunit. That default is what the scam rides on.

The setting has a cost. Some legitimate invitations from first-time contacts will no longer appear automatically and will need manual acceptance. Gannon's warning about filtering out legitimate invites applies here too, though the sender-known option is narrower than blocking whole platforms.

Google has not said in the material reviewed whether it plans to change the default for individual accounts. That is the open question. Until it does, the protection depends on each user, or each company's administrator, turning the setting on.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Malay MailSpam isn’t just in your email: How a rogue calendar invite could disrupt your workday
left
The Guardian‘You have a meeting’: the calendar phishing scam growing exponentially
unknown
Newsy TodayExperts Warn Against Rising 'You Have a Meeting' Calendar Scams
unknown
Finwire‘You have a meeting’: the calendar phishing scam growing exponentially
unknown
cyberunitGoogle Calendar Phishing: How to Stop Fake Meeting Invites from Reaching Your Team
unknown
blog.knowbe4Warning: Attackers Are Tricking Employees Into Sharing Malicious Calendar Invites
unknown
biztoc‘You have a meeting’: the calendar phishing scam growing exponentially