Calendar Phishing Scams Show Exponential Growth, Targeting Users with Fake Meeting Invites and Renewal Reminders
A new form of phishing scam, known as calendar phishing, is experiencing exponential growth, according to Luke Wescott, a threat detection engineer at Sublime Security. This scam involves fraudsters sending calendar invitations that automatically appear in a victim's electronic calendar, even if the email is not opened or goes to spam. These fake entries often masquerade as meeting requests, voicemail notifications, or service renewal reminders. When a user clicks on the calendar entry, they are typically directed to a fraudulent website that prompts them to enter login details for services like Google, Microsoft, or PayPal, or to call a fake support number to cancel a non-existent charge. The deceptive nature of these calendar entries, appearing alongside legitimate appointments, lends them a 'borrowed credibility,' making them harder for users to identify as malicious. Max Gannon, an intelligence analysis manager at Cofense, notes that some scammers are using legitimate platforms like Zoom to send these ...