Calendar Invite Scams
An invite already on your calendar feels pre-approved.
What Is Calendar Invite Scams?
Calendar invites often arrive over a channel the email gateway never inspects, and an event already sitting on your calendar feels pre-approved. Attackers use both gaps: an invite from a one-letter lookalike of a real vendor domain, a last-minute reminder that leaves no time to check, and a join link to a page that harvests your password. You'll read the organizer address rather than the display name, check the join URL against the real meeting domains, confirm out of band, and report the near-miss.
What You'll Learn in Calendar Invite Scams
- Recognize how calendar auto-accept policies bypass the email security gateway by delivering invites over a protocol the gateway does not inspect
- Read the actual organizer email address rather than the display name to spot one-letter or different-TLD lookalikes of real vendor domains
- Inspect the join URL on every invite and refuse to enter credentials on any domain that is not a known meeting platform (zoom.us, teams.microsoft.com, or your own corporate platform)
- Treat tight last-minute timing and demands for immediate join as social engineering pressure designed to short-circuit verification
- Verify suspicious meeting invites out of band on a phone number, chat, or directory entry that was authenticated before the suspicious request arrived - never the contact info inside the invite
- Preserve a confirmed-hostile calendar event as evidence and report it to SOC first, removing it only once the security team has the organizer address, join URL and timestamps
- File a structured incident report capturing the spoofed organizer address, the fake join URL, and the detection narrative so the SOC can block at the email gateway and DNS resolver and hunt for parallel attempts
Calendar Invite Scams — Training Steps
-
A Quiet Tuesday At Home
It is a quiet Tuesday afternoon. Alice is finishing her vendor scorecards from her home office desk. Her usual quarterly compliance partner, Halcyon Insurance Group, isn't due for a review until April - so the day feels routine.
-
An Unexpected Reminder
A meeting reminder slides up from the system tray: Q1 Vendor Compliance Review - starts in 5 minutes . Hosted by someone called Marco Reyes at Halcyon Insurance Group. Alice never accepted this invite - it was added to her calendar automatically by corporate policy.
-
Inspect The Meeting
The Q1 Vendor Compliance Review is right there on today's agenda, marked External and Auto-accepted . The Join meeting button is one click away. The clock is at 2:27. The reminder says the meeting starts in three minutes. Alice's instinct is to click Join meeting - the calendar already accepted it, the organizer name matches a real partner, and the request looks routine. But a calendar entry is not the same as a verified invitation. Before clicking Join, what is the safest move?
-
Pause Before The Click
-
Read The Address And The Link
Alice slows down and reads the parts of the invite she usually skips - the organizer email and the join URL. Display names are decoration. The address is the truth.
-
Verify With The Vendor
Alice picks up her phone and calls Sarah Donovan, her usual contact at Halcyon, on the extension she has had saved for two years. Not the number on the invite. Not the email. A channel that was authenticated before any of this started.
-
Open The Security Portal
Sarah confirms what Alice already suspected. There is no Marco Reyes at Halcyon. There is no Q1 review scheduled. The invite is hostile and the join link is a credential harvest dressed up as a meeting platform. She told Sarah she would delete the event, but she stops herself and leaves it exactly where it is. It is evidence now, and SOC will want the organizer address, the join URL and the delivery timestamps straight off the invite. Reporting comes first; the event can be removed once the security team has the details.
-
Sign In To The Portal
Alice signs in to the security portal using her stored credentials.
-
File The Incident Report
Alice files the report with the details SOC needs first: the spoofed organizer address, the suspicious join URL, and a short narrative of what happened and how she caught it.
-
What Makes The Report Useful
The portal echoes Alice's submission back so she can review it before the SOC analyst picks it up. Three sections do most of the SOC's work for them - the spoofed organizer, the spoofed join URL, and the narrative of how Alice detected and contained the attempt.
Security Framework Coverage
MITRE ATT&CK
- T1566.002 Phishing: Spearphishing Link
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind