discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

‘You have a meeting’: the calendar phishing scam growing exponentially

A new calendar phishing scam is rapidly increasing, tricking users into believing they have forgotten meetings or renewals, leading them to fake login pages for services like Google, Microsoft, or PayPal.

Oct 11·theguardian.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

‘You have a meeting’: the calendar phishing scam growing exponentially
Image: theguardian.com

Scammers are exploiting the automatic invitation feature of calendar applications to bypass traditional email filters, making their phishing attempts appear more credible. These fake calendar entries prompt users to click malicious links or call fraudulent support numbers, ultimately aiming to steal personal login credentials and financial information.

Why it matters

This evolving cyber threat directly impacts the financial security of individuals and businesses by facilitating credential theft, which can lead to significant monetary losses, identity fraud, and corporate data breaches, thereby affecting broader economic stability and trust in digital platforms.

Imagine someone secretly adding a fake playdate to your school planner, making it look like a real one. When you check it, there's a link saying 'click here for details.' If you click and type in your secret club password, you've accidentally given it to the trickster! That's what grown-ups are facing with their digital calendars, where sneaky people put fake meetings to steal their online passwords for things like games or shopping.

Analysis

The emergence and rapid proliferation of calendar phishing represent a significant evolution in cybercrime tactics, leveraging the inherent trust users place in their digital calendars. Unlike traditional email phishing, which often relies on users opening suspicious messages, calendar phishing exploits the automatic acceptance features of popular calendar applications like Google Calendar. This allows malicious invitations to appear directly alongside legitimate appointments, lending them a 'borrowed credibility' that makes them harder to discern as fraudulent.

Luke Wescott

Luke Wescott, a threat detection engineer at Sublime Security, highlights the alarming rate at which this scam is expanding, noting its "exponential growth." His observations underscore the novelty and effectiveness of this method, which circumvents typical security measures. Wescott points out that calendar apps can automatically add invitations without user acceptance, meaning scammers don't even need the victim to open an email. This passive infiltration makes the scam particularly insidious, as users are more likely to interact with something already present in their trusted calendar interface.

Max Gannon

Max Gannon, an intelligence analysis manager at Cofense, further elaborates on the sophistication of these attacks. He notes that some fraudsters are utilizing legitimate platforms, such as Zoom, to dispatch these deceptive invitations. This tactic not only makes the invites appear more authentic to recipients but also poses a significant challenge for advanced security software, including AI-backed blockers, to detect and filter. Gannon explains that blocking invitations from such platforms entirely would inadvertently block legitimate meeting requests, creating a dilemma for cybersecurity defenses.

Google Calendar

The article specifically mentions Google Calendar as one of the platforms susceptible to this scam due to its automatic invitation acceptance settings. The scam typically involves an email containing a calendar request, which, regardless of whether it's opened or lands in spam, can automatically populate the user's calendar. These entries often masquerade as urgent notifications, such as 'New voicemail received,' 'Payment receipt confirmation,' 'PayPal unusual activity,' or 'Your auto-payment will be processed within 24 hours.' The goal is to prompt the user to click a link embedded in the event description, leading to a fake login page for services like Microsoft, Google, or PayPal, or to call a fraudulent 'support' number to cancel a non-existent charge. Users are advised to disable automatic acceptance of invitations in their calendar settings and to treat all unexpected entries with extreme suspicion, deleting or reporting them as spam rather than declining, which could confirm their address is 'live'.

Key points

  • Calendar phishing is a rapidly growing scam that exploits automatic invitation features in digital calendars.
  • Scammers send fake meeting or renewal requests that appear directly in victims' calendars, often bypassing email filters.
  • These deceptive entries lure users to fraudulent login pages for services like Google, Microsoft, or PayPal, or to scam support numbers.
  • The scam gains 'borrowed credibility' by appearing alongside legitimate appointments, making it harder for users to identify.
  • Users are advised to disable automatic invitation acceptance in calendar settings and to treat all unexpected entries with suspicion, deleting them rather than declining.
The Downside

The exponential growth of calendar phishing, coupled with its ability to bypass advanced security filters and leverage trusted platforms, suggests a significant and escalating threat. This could lead to widespread credential theft, substantial financial losses for individuals and businesses, and a further erosion of trust in digital communication and scheduling tools.

Originally reported at

theguardian.com

Discernion covers the story. Read the full piece at the source.

Tagsscamscybercrimedata-securityinternet-safetyeconomyfinance

Intelligence analysis by

Gemini 2.5 Flash

Published

Oct 11, 2026

Source

theguardian.com

Share

Topics

scamscybercrimedata-securityinternet-safetyeconomyfinance

Related

More from this desk

Oct 11·theguardian.com

US’s Reagan-era economic promises return as Trump’s AI-fueled growth fantasy

Republicans are reviving Reagan-era promises that tax cuts and AI-fueled growth will resolve the US's massive federal debt, but financial markets remain skeptical as bond yields surge.

Oct 11·theguardian.com

‘Some aren’t going to make it’: how pressure on farmers threatens UK food security

UK farmers face immense pressure from soaring fuel and fertilizer costs, climate change impacts, and geopolitical shocks, threatening the nation's food security. Experts warn of government complacency regarding the vulnerability of British food supply chains.

Oct 11·theguardian.com

‘Halloweenmas’: how the spooky one-nighter turned into a month-long spectacular

Halloween is transforming from a single-night event into a month-long "Halloweenmas" celebration, mirroring Christmas traditions with increased consumer spending on decorations, gifts, and themed activities. This shift is driven by retailers and younger generations seekin…

Scott Jobson, a man with a shaved head and beard who wears glasses, standing in front of the bright blue vans used by the Daft as a Brush charity. He is wearing  a similarly coloured lanyard.
Oct 11·bbc.co.uk

Charities and businesses wrestle with diesel cost

UK charities and businesses are struggling with soaring diesel prices, which have surpassed £2 per litre. This is impacting operational costs and service delivery.