Glossary

What is calendar phishing?

Calendar phishing is an attack that uses a fake meeting invitation to deliver a malicious link, file or phone number.

Also known as
Calendar invite phishing, meeting invite phishing
Channel
Calendar invitations and event reminders
Typical goal
Credentials, malware or a callback phone call
Related term
Phishing

How it works

The meeting you
never accepted.

  1. 01

    Send an invite

    The attacker sends an event with a believable title: a bonus review, a policy briefing, a client call.

  2. 02

    Land in the calendar

    Many calendars add invites automatically, so the event shows up with reminders.

  3. 03

    Hide the payload

    The event description holds a link to “join”, a document to “review” or a dial-in number.

  4. 04

    Wait for the reminder

    When the reminder pops up, the victim clicks through without thinking about where it came from.

How to spot it

Your calendar is not
a trusted sender.

An event in your calendar feels like something you agreed to. With automatic invites, it might not be.

CHECKLIST

Warning signs

  • Organiser you don’t know or an external address
  • Event you don’t remember accepting
  • Sign-in link or file in the description
  • Sensitive topic such as pay, HR or legal
  • Unusual dial-in number to “join”

Don’t join from the event. Verify, then report.

Questions buyers ask

Frequently asked questions.

How do phishing invites get into my calendar?

Many calendar apps automatically add events from incoming invitations. Checking your calendar settings for how external invites are handled can reduce this.

Is it safe to decline a suspicious invite?

Declining may notify the sender that your address is active. It’s usually better to report the invite through your organisation’s process and let your security team advise.

What is the difference between calendar phishing and email phishing?

Both usually start with an email, but calendar phishing uses the event itself, and its reminders, to deliver the link or number.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo