How Calendar Phishing Bypasses Your Inbox Defenses

Lana Kuzmina
August 7, 2026
Threat Intelligence
4 mins

What Is a Calendar Attack?

A calendar attack (also called "calendar phishing" or "CalPhishing") is a social engineering technique where attackers deliver malicious content through a calendar invite instead of, or in addition to, a traditional phishing email.

The attacker sends or embeds an iCalendar (.ics) file that many email clients process automatically, often adding a "tentative" meeting straight to the victim's calendar without them ever opening the original email. The attacker then manipulates fields inside the invite (e.g. event summary, location, description), to insert urgent-sounding messages and malicious links or content.

Why Are Calendar Attacks so Effective?

Calendar attacks succeed because they exploit trust in a place people don't expect to be attacked.

The common thread across these techniques is a loaded remote resource: an image, a link, an invite. This is exactly what standard inbox hygiene doesn't catch, since security teams have spent years hardening email filters while calendars remained largely unmonitored.

A few structural factors make the calendar an especially good attack surface:

  • Automatic processing: Many clients add invites to a user's schedule before the email is even opened, so the "click" the attacker needs may already be halfway done.
  • Two chances per attack: Using calendar invites creates two chances for the attacker with only one phishing email. Even after doing the right thing in the email inbox, a user might later be tempted to click the event in their calendar. Reporting or deleting the phishing email doesn't remove the calendar entry. That has to be handled separately, and most reporting tools are built for email, not calendar objects.
  • Delayed detonation: A suspicious invite can sit untouched for days, then resurface as a reminder notification, at which point the victim may have forgotten the original red flags and simply click to "see what this meeting was."

Are Calendar Attacks a New Threat?

Calendar attacks feel like a brand-new trick, but they're not. This is an old idea that attackers have quietly kept in their back pocket for years, occasionally dusting off and refining whenever a new wave of security spending made the inbox a little harder to crack.

What's happening now is the technique’s maturation. The same basic move that once looked like a clumsy spam experiment has evolved into a polished, well-resourced part of large-scale fraud operations, chained together with credential theft, fake login pages, and remote-access tools rather than standing alone.

In many setups it doesn't even need a click to land: calendars are often set to add new invitations automatically, so the trap is already sitting on the victim's schedule before they've opened anything. Google flagged this exact pattern in its June 2026 fraud advisory, naming calendar phishing as one of the most direct and sophisticated techniques currently being used against Gmail and Google Calendar users.

One campaign, tracked since early 2026 and known as CalPhishing, shows exactly this pattern in action: it starts with an email dressed up as an urgent administrative alert, carrying an .ics file that quietly adds a "tentative" meeting to the victim's Outlook calendar - no need to even open the original email.

Health-ISAC, the U.S. health sector's information-sharing body, flagged the campaign in June 2026 as a threat to Protected Health Information and urged healthcare organizations to simply turn off automatic calendar processing as a first line of defense.

{{quote}}

How Do You Spot a Calendar Phishing Attack? Red Flags to Watch For

  • An invite from a sender you don't recognize, or one impersonating IT, HR, finance, or a "government" address.
  • Urgent or threatening language in the event title, location, or description ("account will be suspended," "legal action," "renewal required today").
  • A meeting that appears on your calendar that you never accepted or scheduled.
  • Links or QR codes embedded in the event description or location field, especially ones requiring login.
  • Requests to "confirm your details," pay a fee, or call a number to avoid a penalty.
  • Pressure to act immediately, or a follow-up phone/video call using official-sounding branding to increase urgency.
  • An invite arriving alongside an otherwise unremarkable or unexpected email, especially one with an attached .ics file.

What Can Organizations Do to Defend Against Calendar Attacks?

Reframe the calendar as an active attack surface: The single most important cultural shift is teaching employees that the calendar, like the inbox, is now somewhere attacks land.

Extend awareness training to the calendar: Employees are trained to scrutinize the inbox but rarely the calendar. Simulation programs that cover emerging vectors, teach people to treat an unexpected invite with the same suspicion as an unexpected email, before a real campaign tests them.

Handle the calendar separately: Delete suspicious calendar events independently from reporting the originating email, since one action doesn't remove the other.

Scan .ics files as active content, not passive attachments, in email security scanning.

Restrict auto-add: Set calendar clients to only auto-add invites from known senders (Google Calendar's "Known Senders" setting is one example)

Related Articles

25.06.2026
Threat Intelligence
4 mins

Spam Bombing: The Opening Move Attackers Are Counting On

threat-intelligence
13.05.2026
Threat Intelligence
4 mins

When Breach Notifications
Become the Breach

threat-intelligence
08.05.2026
Threat Intelligence
4 mins

ClickFix Attacks in 2026: 7 Variants, Real Attack Data & Defense Guide

threat-intelligence
White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?

"In many setups it doesn't even need a click to land: calendars are often set to add new invitations automatically, so the trap is already sitting on the victim's schedule before they've opened anything."

Lana Kuzmina
Threat Intelligence Analyst