Cybercriminals Use Fake Calendar Invites for Phishing

Scammers target users with deceptive calendar entries that contain links to fraudulent login pages.

Updated on Oct. 11, 2026 in Financial Crime

Bold geometric illustration in navy, cream, and red, depicting a stylized calendar icon representing digital security risks.
Cybercriminals are increasingly exploiting automated calendar synchronization features to distribute phishing scams, tricking users into clicking fraudulent login links. AI Illustration. Upload story photo >

Live Poll

Do you trust the authenticity of unexpected meeting notifications appearing in your digital calendar?

Cybercriminals are using automated calendar invitations to execute phishing scams by sending fake meeting requests to personal and work email addresses. These deceptive events often impersonate legitimate platforms to trick users into clicking links that lead to fraudulent login portals.

Why it matters

Attackers exploit the automatic synchronization features of calendar apps to steal sensitive credentials or financial information from unsuspecting users. By mimicking trusted brands like Google, Microsoft, or PayPal, scammers attempt to bypass traditional security skepticism.

Phishing entries often display fake payment receipts of $298.99 and warn of charges occurring within 24 hours. The investigation into the origin of these campaigns remains ongoing as attackers leverage platforms like Zoom to send invitations.

The players

Google

Google is a global technology company that provides widely used email and calendar services often impersonated by attackers.

Microsoft

Microsoft is a multinational technology corporation whose enterprise and consumer platforms are frequently targeted by phishing campaigns.

PayPal

PayPal is a major digital payments platform that scammers frequently mimic in fraudulent communications to harvest financial data.

Zoom

Zoom is a video conferencing provider that serves as a legitimate platform misused by scammers to deliver malicious calendar invitations.

The details

Scammers customize calendar events with company logos to increase credibility, often framing them as voicemail notifications or service renewals. Once a user clicks the link or calls the provided support number, they are prompted to enter login credentials on fake websites controlled by attackers.

Legal Context

This activity follows the rise of calendar-based social engineering attacks, representing a shift toward exploiting automated software features rather than manual user interaction. This tactic highlights the ongoing evolution of cybercrime as attackers move to circumvent traditional email filters.

Users can protect themselves by adjusting calendar settings to prevent the automatic addition of invitations from unknown senders. Always verify the source of unexpected notifications before clicking any links or calling numbers listed in event descriptions.

The takeaway

Exercise caution when receiving unexpected calendar invitations, even if they appear to originate from trusted services. Never input login credentials on a site reached through a calendar link without first confirming the request via the official platform portal.

Further reading

Learn more about evolving threats in Financial Crime.

Source note: This article includes information reported by The Guardian.

Live Poll

Do you trust the authenticity of unexpected meeting notifications appearing in your digital calendar?