Google Calendar Invitation Phishing: How Attackers Abuse Calendar Invites for Social Engineering

๐Ÿ“… Published 06-07-2026 ยทphishingsocial-engineeringawarenessthreat-research

Written By Aryan Giri

Google Calendar is designed to make scheduling meetings simple, but the same convenience can also be abused by attackers as part of phishing campaigns.

Unlike traditional phishing emails that rely solely on convincing email content, this technique leverages calendar invitations to deliver phishing lures directly into a victim's calendar. Since many users inherently trust notifications coming from applications like Google Calendar, these invitations can appear more legitimate than ordinary spam emails.

This is not a vulnerability in Google Calendar. Instead, it is a social engineering technique that abuses legitimate calendar invitation functionality.

Disclaimer

All email accounts used during this demonstration were created solely for testing purposes and have since been deleted.


Attack Overview

The attacker creates a calendar event containing a convincing title and description, then sends it as an invitation to the target.

If the victim's Google Calendar settings allow invitations to be added automatically, the event appears inside their calendar without requiring manual approval.

When the event time approaches, Google Calendar sends a notification to the victim, potentially increasing the credibility of the phishing attempt.


Demonstration

Step 1 โ€” Creating the Malicious Event

From the attacker's Google Calendar account, create a new event.

For this demonstration the event title was:

Your Account Has Been Hacked

Inside the event description, a fake recovery message and phishing URL were included.

The phishing message used in this demonstration was intentionally obvious and easy to identify. In a real attack, attackers can use AI-generated content to create far more convincing messages that closely resemble official communications.

Screenshot 2026-07-06 081013

Step 2 โ€” Sending the Invitation

After inviting the victim, Google generates a normal invitation email containing an .ics calendar attachment.

The email itself appears completely legitimate because it is a genuine calendar invitation.

Screenshot 2026-07-06 081033 Screenshot 2026-07-06 081200 Screenshot 2026-07-06 081212

Step 3 โ€” Automatic Calendar Entry

On the victim account, the invitation was automatically added to Google Calendar.

No manual calendar creation was required.

WhatsApp Image 2026-07-06 at 8 50 14 AM

Step 4 โ€” Notification on the Victim Device

When the scheduled time arrived, Google Calendar generated a push notification on the victim's phone.

Because the notification originated from the Calendar application itself, it appeared more trustworthy than a standard phishing email notification.

WhatsApp Image 2026-07-06 at 8 24 54 AM

Step 5 โ€” Opening the Event

Opening the notification displayed the event details, including:

If the victim trusts the notification and follows the provided instructions, they may be redirected to a credential harvesting website.

WhatsApp Image 2026-07-06 at 8 24 54 AM (1)

Why This Works

Many technically experienced users immediately become suspicious when receiving an unexpected calendar invitation.

Typical questions include:

However, attackers are not targeting only technically experienced users.

Several psychological factors make this attack surprisingly effective.

Trust in the Application

Users generally trust notifications from installed applications more than random emails.

A notification coming from the Calendar app often feels official.


Context Matters

Attackers rarely use obvious event names.

Instead, they may choose titles such as:

These subjects create urgency or curiosity that encourages victims to open the event.


Mobile Behavior

Many people quickly tap phone notifications without carefully inspecting:

The smaller screen also reduces visible context.


Workplace Habits

Employees often receive dozens of legitimate calendar invitations every week.

An unexpected invitation is therefore less unusual than receiving an unexpected email.

Attackers abuse this normal workplace behavior.


Phishing Doesn't Need Everyone

Most phishing campaigns expect low success rates.

If:

the campaign may still be profitable.


MITRE ATT&CK Mapping

Technique Description
MITRE ATT&CK T1566 Phishing
Social Engineering Overall attack strategy
Credential Phishing Goal of stealing login credentials

The calendar invitation is simply the delivery mechanism.

It does not exploit a security vulnerability in Google Calendar.


Mitigation

Google allows users to control how invitations are automatically added to their calendars.

Change Calendar Invitation Settings

  1. Open Google Calendar (Web)
  2. Click Settings
  3. Navigate to General โ†’ Event settings
  4. Locate Add invitations to my calendar
  5. Change the option from From everyone to one of the following:

Only if the sender is known (Recommended)

Invitations are automatically added only when the sender is:


When I respond to the invitation in email (Most Secure)

Calendar events are not added automatically.

The invitation only appears after you explicitly accept it from the email.

This provides the strongest protection against unsolicited calendar invitations.


Alternative Calendar Applications

Google Calendar is not the only option.

Privacy-focused alternatives such as Proton Calendar require users to explicitly import or accept calendar events rather than automatically adding them from incoming invitations, reducing the likelihood of this particular social engineering technique succeeding.

As with any calendar application, users should still verify invitations before accepting them.


Key Takeaways