
Most employees know to approach unexpected emails with caution. They may check the sender, avoid unfamiliar attachments and pause before clicking a link.
But would they apply the same caution to a meeting invitation already sitting in their calendar?
Calendar phishing, or CalPhishing, uses calendar invitations and events to present malicious links, attachments or instructions within a familiar business workflow.
Because the invitation appears alongside legitimate meetings, it may feel like an ordinary work item rather than a potential threat.
The business takeaway is clear:
Phishing protection can no longer stop at the inbox.
What is CalPhishing?
CalPhishing uses calendar invitations, often delivered through an .ics file, to direct recipients towards a suspicious action.
The event may appear as a:
- Domain renewal or expiry notification
- Billing or vendor update
- Document-signing request
- Account verification prompt
- Urgent administrative alert
The invitation may encourage the recipient to open a link, review an attachment or sign in to an account. The objective can include stealing credentials or authentication information, delivering malicious content or enabling further social engineering.
The technique can be effective because it places the interaction inside a workflow employees already trust.
Why can CalPhishing be overlooked?
Employees regularly receive calendar invitations from colleagues, customers, suppliers and other external contacts. In a busy workplace, these invitations may be reviewed quickly, particularly when they appear urgent.
Several factors can make calendar phishing difficult to recognise.
Calendar events can feel trustworthy
Once an invitation appears among legitimate meetings, employees may assume it has already passed through a trusted business process. However, its presence in the calendar does not confirm that the organiser, request, link or attachment is legitimate.
Awareness training often focuses on email
Traditional phishing training commonly teaches employees to examine email senders, links and attachments. These behaviours remain important, but they should also be applied to calendars, collaboration platforms and shared resources.
Current phishing reporting describes attackers shifting towards calendar invitations and other collaboration channels that may receive less scrutiny than the inbox.
The event may continue to attract attention
Calendar events can resurface through reminders and notifications, giving recipients further opportunities to interact with suspicious content.
Reported CalPhishing activity has also shown that removing the original email may not necessarily remove the associated calendar event. If the event remains, its content and reminders may continue to be visible.
This changes the incident-response question from:
“Was the phishing email deleted?”
to:
“What did the phishing attempt create or trigger across the environment?”
What are the warning signs?
Not every unexpected invitation is malicious. The goal is not to make employees distrust every meeting, but to encourage a moment of caution when the context does not feel right.
Potential warning signs include:
- An unfamiliar external organiser
- A meeting with no clear business purpose
- Urgent billing, renewal or account requests
- Unexpected links or attachments
- Instructions to sign in through an unfamiliar page
- Pressure to act immediately
- Administrative alerts delivered through an unusual channel
- Invitations unrelated to the recipient’s role
Important financial, administrative or account-related requests should always be confirmed through a known, official channel.
What should employees do?
A simple principle can help:
Pause. Verify. Report.
Pause: Do not open unfamiliar links or attachments, or enter authentication information, simply because the request appears in a calendar.
Verify: Check whether the organiser is known and whether the event has a legitimate business purpose. Confirm important requests through an official portal or trusted contact method.
Report: Send suspicious invitations to your IT or security team. Reporting allows them to investigate the sender, calendar event, included content and any related activity.
How can businesses strengthen their response?
Employee awareness is important, but responsibility should not rest on employees alone. Effective protection combines people, processes and technology.
Extend awareness beyond email
Training should cover the tools employees use throughout their day, including calendar invitations, collaboration platforms, shared files and authentication prompts.
Review calendar and collaboration visibility
IT teams should assess whether their current security controls and monitoring provide appropriate visibility over suspicious invitations, external organisers and links contained within calendar events.
Update incident-response processes
A CalPhishing investigation may need to consider:
- The original delivery message
- The calendar event
- Included links and attachments
- Any user interaction
- Related authentication activity
- Remaining reminders or artefacts
- Other employees who may have received the invitation
Current CalPhishing guidance recommends following the full interaction across email, calendar content and related activity instead of examining the delivery message alone.
Support people with layered protection
Awareness training should be backed by properly configured identity, device, access and cloud security controls. Regular reviews can help ensure those protections continue to reflect how the organisation works.
Protect the workflow, not only the inbox
CalPhishing is a reminder that cybercriminals can misuse the same trusted tools employees rely on every day.
The answer is not to treat every meeting invitation as a threat. It is to help employees recognise unusual requests, extend security visibility across the working environment and ensure incident-response processes follow suspicious activity wherever it leads.
Your people do not work only in their inbox, and your phishing strategy should not end there.
Is your Microsoft 365 environment protected beyond email?
Fuse Technology helps businesses identify security gaps and strengthen protection across email, calendars, identity, devices and collaboration tools.
Do not wait for a suspicious invitation to expose a gap in your security strategy.
Take Fuse Technology Cybersecurity Health Check to understand your current exposure and identify practical steps towards stronger, layered protection.