A growing number of people are falling victim to a deceptive tactic known as calendar phishing. The scam starts innocuously: a meeting reminder appears in your Google Calendar, often for an event you don’t recall scheduling. Curiosity leads you to click on the provided link, where you’re prompted to log in. Unbeknownst to you, the details you enter go straight to fraudsters, who then exploit them for further malicious activities.
According to Luke Wescott, a threat detection engineer at Sublime Security, this type of phishing is still relatively new but has seen exponential growth. The scam operates in various forms, including fake meetings or auto-renewal notifications. What makes it particularly insidious is that calendar apps like Google Calendar can automatically add these invitations without requiring user approval, making it easy for scammers to bypass traditional email filters.
Max Gannon, an intelligence analysis manager at Cofense, notes that some fraudsters use legitimate platforms like Zoom to send these invitations, making them harder to detect. This legitimate appearance challenges even AI-backed security software. Gannon warns that filtering out such invitations could also block real meetings, leaving users vulnerable.
To protect yourself, experts recommend treating unexpected calendar entries with the same skepticism as suspicious emails. Avoid clicking on links or calling numbers provided in these notices. Wescott advises disabling automatic acceptance of calendar invites and reporting or deleting suspicious entries rather than declining them, as declining can confirm your email address is active to scammers.