Science & Tech · Cybersecurity · 16 hrs ago
Calendar invitations are being used to steal login details
Scammers are using electronic calendar invitations to trick people into sharing personal information.
The invitations can appear in work or personal calendars and may describe a meeting, a voicemail, or a payment or service renewal.
Some calendar apps add invitations automatically, even if the recipient does not accept them.
The event description may include a link to a fake login page or a phone number for a false support service.
The invitation itself does not give scammers access to the person’s calendar; the risk comes if they follow the link or call and share details.
Security researchers say the scam is growing, and some invitations use legitimate platforms such as Zoom to look more convincing.
Filtering invitations from those platforms could also block legitimate meeting requests.
Calendar phishing scams place fake meeting or service-renewal entries in electronic calendars to trick people into revealing login details.
The invitations can appear even if recipients do not accept them or open the email that sent them.
Links may lead to fake login pages, while some entries ask recipients to call a fake support number.
Threat detection engineer Luke Wescott says Sublime Security has seen “exponential growth” in the scam.
Scammers may use legitimate platforms such as Zoom to make invitations harder to identify and block.
- Who
- Scammers target people through work or personal email and calendar accounts.
- What
- Fake calendar invitations try to get recipients to reveal login details or call a fake support number.
- When
- Not stated.
- Where
- In electronic calendars, after invitations are sent to work or personal email addresses.
- Why
- To obtain personal details, which scammers may sell or use for further fraud and account access.
This story does not have two clearly opposing sides.
exponential growth
Even AI-backed blockers struggle.
Calendar apps, such as Google Calendar, can add invitations automatically without users even accepting them.
If they want to they could make it look like an internal invitation
This story does not have a timeline yet.
- Sublime Security
- Luke Wescott says the company has seen “exponential growth” in calendar phishing.
- Cofense
- Max Gannon says scammers use legitimate platforms such as Zoom.
- Common lures
- Fake meetings, voicemail notifications and software renewals.
- Phishing methods
- Fake login pages or phone numbers presented as support contacts.











