Skip to content
Tech News
← Back to articles

Fake calendar invites can infect your system, and they’re surging – how to protect yourself

read original get Yubico YubiKey 5C NFC Security Key → more articles
Why This Matters

Cybercriminals are increasingly abusing calendar invite files (ICS) to slip malware and phishing links past email security filters and directly into users' calendars, since many programs like Outlook, Gmail, and Apple Mail auto-add invites before a user even responds. This matters because it exposes a blind spot in security software that typically focuses on inbox threats, leaving calendars as an under-protected attack surface with attack volume reportedly skyrocketing by over 1,000% in recent months.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — As calendar-invite phishing surges, hardware security keys add a strong layer of protection against account takeover even if you click a malicious link. The YubiKey supports FIDO2/U2F for Microsoft, Google, and other accounts, making it much harder for attackers to hijack your email or calendar after a phishing attempt. It's a simple, durable way to harden your accounts against the exact kind of social-engineering attacks described in the article.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Lance Whitney/ZDNET

ZDNET’s key takeaways

Fake meeting invites can infect your system with malware.

Many email programs may automatically add invites to your calendar.

Don’t respond to the email or invite. Instead, report them and delete them.

Have you ever received a calendar invite via email that turned out to be fake and even malicious? I’ve gotten these in Microsoft Outlook. Many email programs automatically add an invite to your calendar before you can even accept or decline it. That means you may not be aware that the event information is now in your calendar, waiting for you to access it.

A new report from cybersecurity firm Sublime highlights a dramatic rise in these calendar-based malware attacks. Over the past few months, such attacks rose by 282% in June over the prior month, by 338% in July, and by a whopping 1,216% in August. For September, the firm projects a 2,852% increase over August.

Also: Inside Google’s faster Chrome patch strategy to block AI attacks on your browser

These scams are gaining in popularity for a couple of reasons. They’re relatively easy to pull off. And they take advantage of a default setting for calendar invites in many email programs.

To pull off these attacks, scammers use a technique that Sublime calls ICS phishing. Part of the iCalendar standard, an ICS file contains the details for a meeting or appointment invitation. In programs such as Microsoft Outlook, Gmail, and Apple Mail, an ICS file sent via email can automatically be added to your calendar before you even decide to accept or decline the invite.

... continue reading