‘You have a meeting’: the calendar phishing scam growing exponentially

Read the original at The Guardian ↗
The Guardian · collected 2026-10-11 · by Hilary Osborne

Quick Summary

A new type of phishing scam is growing exponentially, where fraudsters add fake meeting invitations to victims' Google calendars without their consent, tricking them into clicking links that lead to websites asking for personal information. Luke Wescott from Sublime Security notes the rapid increase in such scams, which can appear legitimate due to automated calendar app features and may even use real platforms like Zoom to send invites. Max Gannon of Cofense warns that these tactics make it difficult for security systems to block them effectively without also filtering out genuine invitations.
Written locally by qwen2.5:14b on 2026-10-11, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

Scammers are increasingly using Google Calendar and legitimate platforms like Zoom to insert fake meeting invitations into victims' schedules. According to Max Gannon from the cybersecurity firm Cofense, these scams have become more convincing as they trick users into clicking on links that ask for login credentials. Luke Wescott of Sublime Security notes an "exponential growth" in such attacks recently. Once a user provides their details, scammers can sell this information or use it to gain unauthorized access to work emails and impersonate legitimate institutions like banks. The scam typically involves sending an email with a calendar attachment that, when accepted, places a meeting request on the victim's digital calendar, often leading them to a fake login page designed to steal their credentials.

Written for “Calendar Phishing Scam” on 2026-10-11, grounded in this article and the 0 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
37
claim-shaped sentences
Uncertain
11%
4 of 37 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
68.5
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
1
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-10-11 · how these are computed

Story

📰 Calendar Phishing Scam
Technology · 1 article(s) covering the same event.

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

Nothing to compare against. No article is close enough to this one for the pipeline to have linked or judged the pair.

Publisher

The Guardian · 1619 article(s) · 4 correction(s) detected
Running correction rate · 4 correction(s)
2026-10-03
Tennessee’s top prison official resigning after botched execution of Christa Pike
2026-10-01
Tennessee governor suspends all executions after Christa Pike’s lethal injections fail
2026-09-28
Extra 1,000 prison beds announced in NSW as union warns against arresting ‘our way out of domestic violence’
2026-09-05
Australia’s housing prices are trending down. See which suburbs have had the biggest falls

Who wrote this

Hilary Osborne
2 article(s) here · 1 carrying a prediction
🔮 You have handed your name and password to fraudsters who will sell it on in a batch with other people’s details, use it to break into your work email, or to persuade you that they are contacting you from your bank, or another institution.
🔮 She said: “Average fixed mortgage rates rising back to three-year highs will be disastrous news for borrowers.
Also by Hilary Osborne
Nothing else under this byline is closely related to this article, so these are simply their most recent.

Topics

Cofense Google Google Calendar Sublime Security Zoom

Subjects

Wescott PERSON · 5× Gannon PERSON · 2× Google ORG · 2× PayPal ORG · 2× Cofense ORG · 1× Guardian ORG · 1× Luke Wescott PERSON · 1× Max Gannon PERSON · 1× Microsoft ORG · 1× Sublime Security ORG · 1×

Narrative

Max Gannon, an intelligence analysis manager at the cybersecurity company Cofense, says some scammers are using legitimate platforms such as Zoom to send the invitations, making them look more convincing to the recipients, and to security software.
framing: assertive · carried by 1 article(s) · first seen 2026-10-11
🔮 You have handed your name and password to fraudsters who will sell it on in a batch with other people’s details, use it to break into your work email, or to persuade you that they are contacting you from your bank, or another institution.
2026-10-11 · The Guardian
‘You have a meeting’: the calendar phishing scam growing exponentially · assertive framing

Claims (37 extracted, 4 hedged)

You’re preparing for the week ahead and take a look at your Google calendar. asserted
You → prepare → calendar
There’s an entry for a meeting that you must have completely forgotten. asserted
you → ’ → that
The note that pops up when you click on it says you’ll be reviewing a project and includes a link to more details. asserted
you → pop → details
Confused, you follow it to find out more; the website you land on asks for logon details, and you provide them. asserted
you → follow → them
You have handed your name and password to fraudsters who will sell it on in a batch with other people’s details, use it to break into your work email, or to persuade you that they are contacting you from your bank, or another institution. asserted
they → hand → bank
Luke Wescott, a threat detection engineer at Sublime Security, says calendar phishing is still relatively new but the company has seen “exponential growth”. asserted
company → say → growth
The scam takes several forms, including a fake meeting, or a prompt to renew a service you pay for. asserted
you → take → service
In all, an entry appears in your electronic calendar. asserted
entry → appear → calendar
It ends up there after scammers send an email to your work, or personal address, with a calendar request. asserted
scammers → end → request
It doesn’t matter if you miss it, or it ends up in your spam folder. asserted
it → matter → folder
“Calendar apps, such as Google Calendar, can add invitations automatically without users even accepting them,” Wescott says. asserted
Wescott → add → them
“So scammers don’t even need you to open an email. asserted
you → need → email
And while you may not look twice at one from someone whose name you do not recognise, when something turns up in your calendar you may treat it differently. uncertain
you → look → it
“It can create a borrowed credibility by showing up in the same place as your dentist appointment or a weekly 1:1 with your boss,” he says. asserted
he → create → boss
Max Gannon, an intelligence analysis manager at the cybersecurity company Cofense, says some scammers are using legitimate platforms such as Zoom to send the invitations, making them look more convincing to the recipients, and to security software. asserted
them → say → software
“That makes it really hard to block,” he says. asserted
he → make → ?
“Even AI-backed blockers struggle.” asserted
blockers → back → ?
If you set up something to filter out invitations from these platforms, he says “that would also block any legitimate meeting invitations”. asserted
that → set → invitations
What it looks like You will receive an email and see an entry in your calendar. asserted
You → look → calendar
The titles vary: examples seen by the Guardian include fake meetings, notifications of voicemail messages, and software renewals. asserted
examples → vary → messages
Wescott says this is standard. asserted
this → say → ?
“We typically see stuff like ‘New voicemail received’, ‘Payment receipt confirmation – $298.99’, ‘PayPal unusual activity’ warnings, ‘Your auto-payment will be processed within 24 hours’, and invitations to bid on a contract,” he says. asserted
he → see → contract
Gannon says the invitation could look like it has come from within your company. uncertain
it → say → company
“If they want to they could make it look like an internal invitation,” he says. uncertain
he → want → invitation
“They can customise the content, may be adding the logo of your company.” uncertain
They → customise → company
The event description will typically contain a link, or a phone number. asserted
description → contain → link
Wescott adds: “Either they want you to click a link to a fake login page like Microsoft, Google or PayPal, and enter your password, or to call a ‘support’ number to cancel a charge that never actually happened.” asserted
that → add → charge
Until you click on this, or make a call, you are not compromised. asserted
you → click → call
The scammers do not have access to everything in your calendar – they are just trying to lure you to a place where you will hand over your details. asserted
you → have → details
As Wescott says, “it sounds familiar to typical phishing, it’s the same technique, just using a different delivery method”. asserted
it → say → method
What to do Don’t panic if you see an unexpected meeting or reminder in your calendar. asserted
you → panic → calendar
Treat it as you would an unexpected email asserted
you → treat → email
“My number one advice is people just need to be paranoid,” Gannon says. asserted
Gannon → need → ?
“It doesn’t matter if the invitation has come from someone two desks down, you’ve got to be suspicious of everything.” asserted
you → matter → everything
Wescott advises turning off automatic accepting. asserted
Wescott → advise → accepting
In Google Calendar you can go into settings and opt to only accept invitations from known senders, or when you have accepted. asserted
you → go → senders
He adds: “Don’t click ‘decline’ on suspicious invites as it can tell the sender that your address is ‘live’. asserted
address → add → sender
💬Give feedback
🕘History 🎫Support