Calendar Phishing Attacks Expected to Surge by 33,000% in Q3 2026
A growing concern in the world of cybersecurity is calendar-based phishing, where attackers bypass email filters by sending .ics files that look like legitimate meeting invitations. According to Sublime Security, this type of attack is expected to surge by roughly 33,000% between May and September 2026.
Google responded to this threat by introducing a block button in Google Calendar in August 2026, which can be accessed on the web but not on Android devices. However, this feature only works for invitations sent from other Google accounts, leaving non-Google spammers unchecked.
To mitigate this issue, users are advised to block senders upstream by marking emails as spam or reporting them as phishing attempts. Additionally, Calendar settings can be adjusted to only allow events from known contacts and organization members, which can help prevent unauthorized access.