Calendar phishing scam is a rapidly growing cyber threat that can compromise your financial security. You’re preparing for the week ahead and take a look at your Google calendar. There’s an entry for a meeting that you must have completely forgotten. The note that pops up when you click on it says you’ll be reviewing a project and includes a link to more details. Confused, you follow it to find out more; the website you land on asks for logon details, and you provide them. Unfortunately, this was not a failure of your memory but a calendar phishing scam.
You have handed your name and password to fraudsters who will sell it on in a batch with other people’s details, use it to break into your work email, or to persuade you that they are contacting you from your bank, or another institution. Luke Wescott, a threat detection engineer at Sublime Security, says calendar phishing is still relatively new but the company has seen “exponential growth”.
What Is Calendar Phishing and How Does It Work?
The scam takes several forms, including a fake meeting, or a prompt to renew a service you pay for. In all, an entry appears in your electronic calendar. It ends up there after scammers send an email to your work, or personal address, with a calendar request. It doesn’t matter if you miss it, or it ends up in your spam folder.
“Calendar apps, such as Google Calendar, can add invitations automatically without users even accepting them,” Wescott says. “So scammers don’t even need you to open an email.” And while you may not look twice at one suspicious entry, the more you see, the more likely you are to click. These attacks often target financial credentials, as scammers aim to access bank accounts, credit cards, and investment platforms.
Types of Calendar Phishing Attacks
- Fake Meeting Invites: Scammers send calendar invites for meetings that don’t exist, with links to phishing sites.
- Service Renewal Reminders: Fake notifications about subscription renewals prompt you to update payment details.
- Bank Alerts: Fraudulent alerts about suspicious account activity direct you to fake banking login pages.
- Package Delivery Notifications: Fake delivery updates trick you into entering personal and financial information.
How Calendar Phishing Impacts Your Finances
When you enter your login details on a phishing site, you’re not just giving away an email password. If you reuse passwords, fraudsters can access your bank accounts, investment portfolios, and credit card information. They may also use your stolen credentials to impersonate you and authorize fraudulent transactions.

The financial impact can be devastating. Unauthorized transactions, drained accounts, and damaged credit scores are just the beginning. Victims often spend months resolving identity theft issues and recovering lost funds. According to the FBI, phishing scams cost Americans over $50 million in 2022 alone, with calendar phishing contributing to this growing figure.
Calendar Phishing vs. Traditional Phishing: Key Differences
| Feature | Calendar Phishing | Traditional Phishing |
|---|---|---|
| Delivery Method | Calendar invite (auto-added) | Email or text message |
| User Action Required | None (auto-sync) | Open email and click link |
| Common Targets | Work and personal calendars | Email inboxes |
| Detection Difficulty | High (blends with real events) | Moderate (spam filters) |
How to Protect Yourself from Calendar Phishing
Prevention is your best defense against calendar phishing. Start by adjusting your calendar settings to prevent auto-add of invitations. In Google Calendar, go to Settings > Event settings > Automatically add invitations and select “No, only show invitations to which I have responded.” Also, enable “Ask to join” for external invitations.
Always verify the sender’s email address before clicking any links in calendar events. Legitimate meeting invites come from known contacts. If you receive an unexpected invite, contact the organizer directly through a separate channel to confirm. Additionally, use unique passwords for each account and enable two-factor authentication (2FA) wherever possible.
If you suspect a calendar phishing attempt, report it to your IT department and delete the event immediately. For personal accounts, report the phishing email to the platform (e.g., Google) and consider running a security checkup.
Key Takeaways
- Calendar phishing scams auto-add fake events to your calendar, bypassing email filters.
- These attacks can lead to stolen financial credentials and significant monetary loss.
- Adjust calendar settings to block auto-invites and verify all event links.
- Use 2FA and unique passwords to limit damage if credentials are compromised.
FAQ
What is calendar phishing?
Calendar phishing is a scam where fraudsters send fake calendar invitations that automatically appear in your calendar. When you click the link in the event, you’re directed to a phishing site that steals your login credentials.
How can calendar phishing affect my finances?
If you enter your login details on a phishing site, scammers can access your bank accounts, credit cards, and investment accounts. They may make unauthorized transactions or steal your identity, leading to financial loss and damaged credit.
How do I prevent calendar phishing attacks?
Adjust your calendar settings to stop auto-adding invitations. Verify all event links and sender addresses. Use unique passwords and enable two-factor authentication. Report suspicious events to your IT department or email provider.