Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Calendar phishing attacks surge as scammers exploit automatic meeting invites

Experts warn that phishing scams are increasingly using calendar invitations to trick users into revealing login credentials.

A new wave of phishing attacks is leveraging calendar applications to deliver malicious invitations, according to threat detection engineer Luke Wescott of Sublime Security. The scheme involves sending calendar requests that automatically appear in tools like Google Calendar, presenting fake meetings, voicemail alerts, or payment confirmations that contain deceptive links or phone numbers. Because the invites are treated as legitimate schedule items, users are more likely to trust them, especially when they appear alongside genuine appointments.

Max Gannon of Cofense adds that scammers sometimes use authentic services such as Zoom to make the invitations harder to block, and even AI-based security tools can miss them without also filtering out real events. The attacks remain harmless until the recipient clicks the link or calls the number, at which point their credentials can be harvested for further fraud. Both experts recommend disabling automatic acceptance of invites and treating unexpected calendar entries with the same caution applied to suspicious emails.

Why it matters

Calendar phishing can compromise personal and corporate accounts, exposing users to identity theft and credential theft.

In this story

calendar phishingautomatic invitationscredential theftphishing scamsecurity blockersAI-backed filteringfake meetinguser vigilance
Get the beta ↗