Calendar Invite Scams

Calendar Invite Scams

An invite already on your calendar feels pre-approved.

What Is Calendar Invite Scams?

Calendar invites often arrive over a channel the email gateway never inspects, and an event already sitting on your calendar feels pre-approved. Attackers use both gaps: an invite from a one-letter lookalike of a real vendor domain, a last-minute reminder that leaves no time to check, and a join link to a page that harvests your password. You'll read the organizer address rather than the display name, check the join URL against the real meeting domains, confirm out of band, and report the near-miss.

What You'll Learn in Calendar Invite Scams

Calendar Invite Scams — Training Steps

  1. A Quiet Tuesday At Home

    It is a quiet Tuesday afternoon. Alice is finishing her vendor scorecards from her home office desk. Her usual quarterly compliance partner, Halcyon Insurance Group, isn't due for a review until April - so the day feels routine.

  2. An Unexpected Reminder

    A meeting reminder slides up from the system tray: Q1 Vendor Compliance Review - starts in 5 minutes . Hosted by someone called Marco Reyes at Halcyon Insurance Group. Alice never accepted this invite - it was added to her calendar automatically by corporate policy.

  3. Inspect The Meeting

    The Q1 Vendor Compliance Review is right there on today's agenda, marked External and Auto-accepted . The Join meeting button is one click away. The clock is at 2:27. The reminder says the meeting starts in three minutes. Alice's instinct is to click Join meeting - the calendar already accepted it, the organizer name matches a real partner, and the request looks routine. But a calendar entry is not the same as a verified invitation. Before clicking Join, what is the safest move?

  4. Pause Before The Click

  5. Read The Address And The Link

    Alice slows down and reads the parts of the invite she usually skips - the organizer email and the join URL. Display names are decoration. The address is the truth.

  6. Verify With The Vendor

    Alice picks up her phone and calls Sarah Donovan, her usual contact at Halcyon, on the extension she has had saved for two years. Not the number on the invite. Not the email. A channel that was authenticated before any of this started.

  7. Open The Security Portal

    Sarah confirms what Alice already suspected. There is no Marco Reyes at Halcyon. There is no Q1 review scheduled. The invite is hostile and the join link is a credential harvest dressed up as a meeting platform. She told Sarah she would delete the event, but she stops herself and leaves it exactly where it is. It is evidence now, and SOC will want the organizer address, the join URL and the delivery timestamps straight off the invite. Reporting comes first; the event can be removed once the security team has the details.

  8. Sign In To The Portal

    Alice signs in to the security portal using her stored credentials.

  9. File The Incident Report

    Alice files the report with the details SOC needs first: the spoofed organizer address, the suspicious join URL, and a short narrative of what happened and how she caught it.

  10. What Makes The Report Useful

    The portal echoes Alice's submission back so she can review it before the SOC analyst picks it up. Three sections do most of the SOC's work for them - the spoofed organizer, the spoofed join URL, and the narrative of how Alice detected and contained the attempt.

Security Framework Coverage

MITRE ATT&CK

  • T1566.002 Phishing: Spearphishing Link

CIS Controls

  • CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind