Calendar invite scams surge: How to spot and stop them

A cybersecurity firm reports a sharp rise in attacks that use malicious calendar invites, with August seeing a 1,216% increase over July. These attacks exploit email programs that automatically add invites to users' calendars. Experts advise reporting and deleting suspicious invites rather than responding to them.
The surge in calendar-based attacks reflects a fundamental gap in email security: most platforms scan incoming messages but fail to scrutinize embedded ICS files that auto-populate calendars. Sublime's data shows attackers overwhelmingly favor Google's infrastructure, with Microsoft's platform a secondary vector, because both are widely trusted domains that bypass reputation-based filters. The technique also costs nothing to deploy, relying on free services.
One documented campaign disguised a malicious link as a credit adjustment conversation, using a Gmail address to avoid domain-based blocking. Security experts note that even declining an invite can confirm a valid email address to attackers, making engagement of any kind risky. The projected September increase of 2,852% suggests this vector is still gaining momentum.
This trend could significantly expand the phishing threat surface for everyday users, particularly professionals who rely heavily on Outlook or Google Calendar for scheduling. Because invites appear in trusted calendar interfaces rather than suspicious email folders, victims may lower their guard when clicking embedded links. Organizations could face increased malware infections and credential theft, potentially disrupting operations. Individual users may need to adjust default settings and adopt new vigilance habits, though awareness campaigns and software updates could mitigate the risk over time.