Calendar Invites Are the New Phishing Email: How Attackers Are Using Scheduling Tools to Trick You

Cybercriminals are always looking for new ways to get around security tools, and their latest tactic may surprise you: calendar invites.

Over the past few months, multiple organizations — including government agencies — have warned about a growing social engineering scheme in which scammers use phone calls and fake scheduling links to impersonate legitimate representatives. One of the most recent alerts involved threat actors posing as staff from the New Jersey Division of Pensions and Benefits, calling individuals and then following up with Calendly invites to “verify” personal details.

In another variation, attackers first compromise someone’s email account, then use it to send fraudulent calendar invites to their contacts. Because the invite comes from a familiar name — and bypasses many email filters — it looks credible.

Calendar invites have become an appealing tool for attackers because they often land directly in your inbox without the same scrutiny as traditional email messages. And if a user accepts the invite or clicks a link inside it, the damage can begin.

Here\’s an example that we saw firsthand at TNTMAX.

\"\"

Why Calendar Invites Are Being Used for Social Engineering

Cybercriminals love tools that look legitimate, and scheduling platforms like Calendly have become a prime target. Here’s why:

1. They bypass common email filters

While phishing emails are increasingly filtered out, calendar invites often go straight through — especially if they come from a well-known tool or a compromised account.

2. They carry a sense of urgency and legitimacy

People are used to clicking “Accept” or “View Event Details” without thinking twice. Attackers exploit that instinct.

3. They can disguise malicious links

A Calendly or other scheduling link can hide a redirect to a malicious website designed to steal credentials or drop malware.

4. They look like normal workflow

If someone regularly schedules calls, appointments, or onboarding meetings, a calendar invite doesn’t raise suspicion — which makes it more dangerous.

What Attackers Hope to Gain

The goals behind these calendar-based attacks vary, but the most common motivations include:

  • Identity theft: Harvesting personal details to use or resell.

  • Credential theft: Capturing login information for email, financial accounts, or internal systems.

  • Financial scams: Convincing a victim to transfer funds or “verify” account information.

  • Remote access: Getting the user to install remote-control tools or malware.

  • Widespread compromise: Using one person’s inbox to target their entire contact list.

Once a criminal gets even a small foothold — a single click — the damage can escalate quickly.

How to Spot and Avoid Calendar-Based Phishing Attempts

A few practical steps can significantly reduce your risk:

1. Treat unexpected invites the same way you treat suspicious emails

If you didn’t request a meeting, don’t open the link — especially if the invite pressures you to act urgently.

2. Verify directly through known channels

If the invite claims to come from a government agency, HR representative, or vendor, contact them via their official phone number or email, not the one in the invite.

3. Inspect the scheduling link

Hover over the link before clicking. If the URL looks unusual, uses misspellings, or redirects through multiple domains, it’s likely malicious.

4. Do not download attachments from calendar invites

Most legitimate scheduling tools don’t require attachments. Treat unsolicited files as red flags.

5. Enable multifactor authentication (MFA) everywhere possible

If attackers gain your credentials, MFA can stop them from getting into your accounts.

6. Report suspicious invites to your IT provider immediately

If something feels off, it probably is — and reporting early can protect your entire organization.

What TNTMAX Recommends

Calendar-based phishing is part of a broader trend: attackers are shifting to tools people trust. To stay protected, businesses should:

  • Implement advanced email and calendar scanning tools that flag suspicious scheduling links.

  • Train employees on new social engineering methods — including fake calendar invites.

  • Regularly review and secure email account settings to prevent account takeover.

  • Use IT policies that limit the installation of unauthorized remote-access tools.

Threat actors evolve quickly. Staying secure requires awareness, up-to-date protections, and a team that can respond immediately when something doesn’t look right. If your organization needs help strengthening its cybersecurity posture or investigating a suspicious incident, TNTMAX is here to advise.

more News