Lance Whitney/ZDNET
ZDNET’s key takeaways
Fake meeting invites can infect your system with malware.
Many email programs may automatically add invites to your calendar.
Don’t respond to the email or invite. Instead, report them and delete them.
Have you ever received a calendar invite via email that turned out to be fake and even malicious? I’ve gotten these in Microsoft Outlook. Many email programs automatically add an invite to your calendar before you can even accept or decline it. That means you may not be aware that the event information is now in your calendar, waiting for you to access it.
A new report from cybersecurity firm Sublime highlights a dramatic rise in these calendar-based malware attacks. Over the past few months, such attacks rose by 282% in June over the prior month, by 338% in July, and by a whopping 1,216% in August. For September, the firm projects a 2,852% increase over August.
Also: Inside Google’s faster Chrome patch strategy to block AI attacks on your browser
These scams are gaining in popularity for a couple of reasons. They’re relatively easy to pull off. And they take advantage of a default setting for calendar invites in many email programs.
To pull off these attacks, scammers use a technique that Sublime calls ICS phishing. Part of the iCalendar standard, an ICS file contains the details for a meeting or appointment invitation. In programs such as Microsoft Outlook, Gmail, and Apple Mail, an ICS file sent via email can automatically be added to your calendar before you even decide to accept or decline the invite.
... continue reading