Massive Rise in Calendar-Based Phishing: What Users Must Know to Stay Safe

Calendar phishing attacks surged by 33,000% recently, bypassing email filters and exploiting ICS invites. Learn how these attacks work and how to protect yourself effectively.

Massive Rise in Calendar-Based Phishing: What Users Must Know to Stay Safe
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is Calendar-Based Phishing and Why Does It Matter?

Calendar-based phishing, also known as ICS phishing, uses calendar invitation files (.ics) sent via email or calendar apps to trick users into opening malicious links. The significance lies in its stealthy nature: attackers exploit legitimate-looking calendar events, which often evade traditional email security filters, exposing users to threats even if the invite lands in spam.

This method targets users by doubling the attack exposure — both in the inbox and within the calendar application. Recipients may see what appear to be ordinary meeting invites, but embedded within are links that lead to malware installation, creating a high risk of full endpoint compromise.

How Calendar Phishing Works and Why It's Surging

Sublime Security has observed a >1000% month over month increase in calendar-based  phishing attacks, aka ICS phishing, since August. These attacks have a  variety of objectives, including delivering… | Josh Kamdjou
Sublime Security has observed a >1000% month over month increase in calendar-based phishing attacks, aka ICS phishing, since August. These attacks have a variety of objectives, including delivering… | Josh Kamdjou

Attackers typically use free, trusted services such as Gmail to send calendar invites. Since these platforms are legitimate, many security systems do not flag or block such invitations. The invites often contain links to download remote management and monitoring (RMM) tools like ScreenConnect, which, when installed, allow attackers to control the victim’s device, deploy further malware like infostealers or ransomware, and exfiltrate sensitive data such as passwords and documents.

Since May 2026, there has been an explosive increase in these attacks — with reports indicating a rise of approximately 33,000% over just a few months. The rapid escalation is due to the low cost and high effectiveness of this technique, combined with its ability to fly under the radar of many email filters.

Who Is Affected and How to Identify Suspicious Calendar Invites

All users with calendar functionalities linked to email are potentially vulnerable, including enterprises and individuals using widely popular services like Google Calendar and Microsoft Outlook. The risk is particularly pronounced where users routinely accept calendar events without verifying senders.

Key signs of malicious calendar invites include:

  • Unexpected calendar events from unknown or suspicious email addresses.
  • Urgent requests to download attachments or software.
  • Links directing to remote control or monitoring software downloads.
  • Invites that create a sense of urgency around payments or financial transactions.

Because these attacks bypass spam filters, relying solely on automated protections is inadequate.

Effective Steps to Defend Against Calendar Phishing

Fake calendar invites are spreading. Here's how to remove them and prevent  more | Malwarebytes
Fake calendar invites are spreading. Here's how to remove them and prevent more | Malwarebytes

Users can reduce their risk by adopting the following practices:

  1. Verify sender identity: Confirm calendar invites with the sender through separate communication channels if the invite seems unexpected or suspicious.
  2. Be cautious of links and attachments: Avoid clicking on any links or downloading attachments from calendar events unless their legitimacy is verified.
  3. Disable automatic calendar event additions: Adjust calendar settings to prevent automatic addition of events from email messages without explicit user approval.
  4. Educate yourself and your team: Familiarize with calendar phishing techniques and common indicators to raise awareness.
  5. Use layered security solutions: Complement email filters with endpoint protection tools that can detect anomalous behaviors linked to remote management software installations.

Practical Takeaway: Vigilance Over Automation Is Key

Calendar-based phishing attacks are a growing security concern due to their ability to bypass traditional email filters and leverage legitimate calendar features. The best defense combines skepticism of unsolicited calendar events, thorough verification of senders, and cautious handling of links and downloads embedded in invites. While technology solutions improve, user awareness and cautious behavior remain crucial to prevent these sophisticated intrusions.

React to this story

Related Posts