← Back to the feed

Calendar phishing exploits trusted invitations to steal users’ login details

The Guardian ·

Calendar phishing scams are growing exponentially, with fraudsters sending fake meeting or renewal notifications directly to users' electronic calendars. When victims click links in these invitations, they're directed to spoofed login pages for Google, Microsoft, PayPal and other services, where they unknowingly provide their credentials to criminals.

The scams work by appearing alongside legitimate appointments like dentist visits or work meetings, giving them "borrowed credibility" that makes them more trustworthy than typical phishing emails. Calendar applications automatically add invitations without user acceptance, and some scammers exploit legitimate platforms like Zoom to send the fake invitations, making them nearly impossible for security software to block without filtering out genuine calendar requests. Examples include fake meetings, voicemail notifications, payment confirmations, and automatic payment warnings, often customised to appear as internal company communications.

  • Fraudsters send fake calendar invitations to trick users into entering credentials on fake login pages.
  • Calendar invitations gain credibility by appearing alongside legitimate appointments, unlike suspicious-looking emails.
  • Scammers use legitimate platforms like Zoom, making these invitations difficult for security software to block.

New here? Start with this

Calendar phishing is a form of fraud where criminals send fake meeting invitations or notification messages directly to users' electronic calendars. When someone clicks a link in one of these fake notifications, they are taken to a deceptive website that mimics the login page of a trusted service such as Google, Microsoft or PayPal. The victim then unknowingly enters their login details, giving the fraudsters access to their real accounts.

These scams are particularly effective because the fake notifications appear alongside genuine calendar items like doctor's appointments or work meetings. This context makes the fake invitations seem legitimate and trustworthy, unlike typical phishing emails which arrive in an inbox. Calendar applications automatically add these invitations without requiring users to accept them first, and some fraudsters exploit legitimate platforms like Zoom to send their messages, making them difficult for security filters to detect and block.

Users who fall victim to calendar phishing risk having their personal accounts compromised and taken over by criminals. Fraudsters may then use these stolen credentials to access sensitive information, commit further fraud, or infiltrate company systems if the victims are employees with access to valuable data. This method of attack is particularly dangerous because many people trust invitations that appear on their calendars more readily than suspicious emails.

Business Cybersecurity Technology

Read the full article at the source →

Originally published by The Guardian as “‘You have a meeting’: the calendar phishing scam growing exponentially”.