
An unfamiliar appointment suddenly appears on an employee’s calendar. It might claim that a payment was processed, a document needs attention, an account will be suspended, or a customer wants to discuss an urgent problem.
The invitation includes a convenient link or phone number. Because it appears in a familiar calendar application, the employee may assume it has already been checked and is safe.
That assumption is exactly what criminals are trying to encourage.
Security researchers are reporting a significant increase in phishing attacks delivered through calendar invitations. In a September 17 report, Sublime Security said its detection team had observed a greater than 1,000% month-over-month increase in calendar-based attacks since August. The company also projected that September activity could be roughly 33,000% higher than May within its observed data.
Those figures come from one security provider rather than the entire email market, but the trend is still important: malicious calendar invitations are becoming much more common.
Calendar phishing uses meeting invitations, sometimes delivered as .ics calendar files, to place fraudulent information in an employee’s inbox and calendar.
The invitation may contain:
Some email and calendar systems automatically add invitations to a user’s schedule. This means the event may remain visible even if the original email was moved to spam or quarantine.
That second appearance matters. Employees are accustomed to treating calendar reminders as routine work prompts, so an invitation displayed at the right time can feel more credible than an ordinary suspicious email.
A small business may not have a security team examining every invitation. Employees manage their own calendars, respond quickly to customers, and regularly receive meeting requests from people outside the company.
That creates several opportunities for an attacker.
A bookkeeper may receive a false payment notice. A manager may see an invitation that appears to come from a vendor. A salesperson may assume an unfamiliar meeting is from a new lead. An employee may call a fraudulent support number because the event claims that a business account needs immediate attention.
If the employee enters a password on a fake page, the attacker may gain access to business email, shared files, customer conversations, or financial information. If the invitation delivers unauthorized remote-management software, the attacker may obtain continuing access to the computer.
Employees should pause when an invitation:
One warning sign does not prove that an invitation is malicious. It does mean the request should be verified before anyone follows its instructions.
Do not click the invitation’s link, download its attachment, or call the number shown in the event.
Instead, verify the request through a separate channel. Contact the supposed sender using a known email address, established phone number, or existing conversation. Do not use contact details provided inside the suspicious invitation.
Report the event to the company’s IT provider or designated security contact. Include the organizer’s address, meeting title, scheduled time, and a screenshot when possible.
Employees should also avoid forwarding the invitation to coworkers as a warning. Forwarding can place the same dangerous content on additional calendars. Use a screenshot or a new message when alerting the team.
If someone already clicked the link, entered a password, installed software, or called the provided number, the business should contact its IT provider promptly. The employee should explain exactly what happened instead of deleting the event and hoping the problem disappears.
Technology should support employee awareness. Small businesses can ask their IT provider to review:
Multifactor authentication remains important, but it is only one part of the solution. Employees still need to recognize fraudulent prompts, and administrators need visibility into unusual sign-ins, new forwarding rules, and risky applications.
Employees have heard “do not click suspicious email links” for years. The same habit now needs to extend to calendar events.
A meeting invitation is a message from another person. Its appearance on a trusted calendar does not prove that its sender, links, attachments, or phone numbers are trustworthy.

Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day

Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety

I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!

I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.

Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.

It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.

Himala and his team from Cybernetic Networks, Inc. has been an integral part of our successful retail business for the past 20 years. He is extraordinarily knowledgable and always available for our IT needs. Thanks to Himala and his team we are always up and running.