Calendar phishing is growing exponentially as fake meetings steal logins
Researchers at Sublime Security and Cofense report exponential growth in calendar phishing, where scammers send meeting invites and renewal reminders that land automatically in Google Calendar. The links lead to fake Google, Microsoft or PayPal login pages that harvest credentials.
- Invites appear in calendars automatically even if the email lands in spam
- Sample subjects: 'New voicemail received', 'Payment receipt $298.99', 'PayPal unusual activity'
- Scammers use Zoom and company logos to appear legitimate
- Experts advise disabling auto-accept and avoiding the 'Decline' button
Read next
Security