Calendar Phishing: The New Attack Hiding in Your Schedule
A phishing attack skipped the inbox and landed straight on a calendar as a fake "Invitation to Bid." Here's how calendar phishing works, why it bypasses spam filters, and exactly what to do if it reaches you.

You've trained yourself for years to spot a phishing email. Weird sender address, urgent subject line, a link that doesn't quite match the domain, you've seen it all, and you delete on sight.
So what happens when the scam skips your inbox entirely?
This week, a phishing attempt did exactly that. It didn't arrive as an email. It showed up as a multi-day event, sitting quietly on someone's Google Calendar, looking exactly like the kind of thing a busy professional would actually be waiting for: an Invitation to Bid.
A Scam That Never Had to Pass a Spam Filter
The event had all the right details. A reference number. A polished description. A link to "the documents." For anyone who works with RFPs, procurement, or vendor bids, this isn't a red flag, it's Tuesday. It's the exact email people scan for, click into, and forward to three colleagues before lunch.
Except it wasn't an email at all.
That distinction matters more than it sounds. A phishing email has to survive spam filters, sender authentication checks, and increasingly sharp employee instincts. A calendar invite skips all of that. It's generated by Google's own infrastructure, so it arrives already "verified" in the most technical sense and it lands directly on your schedule, no inbox required.
The attacker isn't exploiting a flaw in Google Calendar. They're exploiting the fact that we've spent a decade training people to distrust their inbox and implicitly trust everything else.
Why This Trick Works So Well
Three things make calendar phishing unusually effective:
It bypasses the tool built to stop it. Spam filters watch email. They don't watch calendar events the same way, so a malicious invite can walk straight past the defense you've come to rely on.
It borrows Google's credibility. The notification, the layout, the "Yes / No / Maybe" buttons, it's all rendered by a platform you trust completely, which makes the content inside feel trustworthy by association.
It targets people mid-task, not mid-scroll. Nobody idly browses their calendar the way they browse an inbox. If you're the person fielding actual bid invitations, this lands at exactly the moment you're primed to click without hesitating.
That last point is the real design behind the attack. It's not aimed at everyone, it's aimed at whoever's job makes an "Invitation to Bid" look completely unremarkable.
What to Actually Do If One Reaches You
If a suspicious event lands on your calendar, resist the two instincts that feel most natural:
Don't click the link. This one's obvious, but worth saying plainly, the "documents" are the entire point of the attack.
Don't hit Decline. This is the one people get wrong. Declining doesn't make the event disappear quietly. It sends a response, which confirms to the attacker that your email address is real, active, and worth targeting again.
Report it as spam instead. Open the event, look for the three-dot menu, and select "Report as spam." This removes it without confirming anything to the sender, and it feeds Google's filters so the next version of this attack is easier to catch.
If you want to cut these off before they ever reach your calendar, Google Calendar has a setting for exactly this. Under Settings → Event Settings → Add invitations to my calendar, switch it from "From everyone" to "Only if the sender is known." Invitations from contacts, coworkers, or anyone you've emailed before still land automatically. Everyone else gets routed to your inbox first, where you actually get a chance to evaluate them before they show up as a "confirmed" event on your schedule.
The Bigger Shift: Attackers Are Spreading Out
For years, "security awareness" basically meant "inbox awareness." That's no longer enough. The same tactics now show up on WhatsApp, in SMS, and — as we're seeing here — inside the calendar tools we treat as administrative background noise rather than an attack surface.
The common thread across all of it isn't the channel. It's the disguise. The most effective scams today don't look like scams at all. They look like the ordinary shape of your job: a bid request, a shipping update, a meeting reminder, a document your manager needs signed. The less it looks like an attack, the more effective it is.
Which is why the rule has to be simpler than "know the signs of phishing," because the signs keep moving. It's this instead:
Don't click unknown or suspicious links, no matter where they show up.
Not in your inbox. Not in a text. Not in a WhatsApp message from an unfamiliar number. And not in a calendar event that looks exactly like the thing you were already expecting.
Because that's the part attackers are counting on: that you'll keep guarding the door you already know about, while they walk in through the one you forgot was there.
Don't Rely on Habit Alone, Let Whiteknight Watch the Doors You Forget
Spotting a suspicious calendar invite once is easy in hindsight. Spotting it in the middle of a busy week, buried between three real meetings, is a different story and that's exactly the gap attackers are betting on.
This is where Whiteknight fits in. Instead of asking your team to manually audit every calendar invite, message, and link across every channel, Whiteknight monitors the surfaces attackers have started exploiting, calendar, chat, SMS, and beyond and flags the suspicious ones before they ever get a chance to look routine.
If this week's near-miss made you wonder what else might be slipping through, that's worth a five-minute look. Reach out to the us to see how it fits into your existing security stack.
A Malware doesn't end with the calendar alone, Read our blog: WhatsApp Malware Alert: A Growing Threat to Finance Teams to know how hackers reach you in whatsapp.


