Site icon Panda Security Mediacenter

The Rise of Calendar Phishing

The Rise of Calendar Phishing

Internet users have been reporting an increase in calendar phishing (CalPhishing). The scam technique has been on the rise over the last 24 months and consists of users receiving mysterious calendar invites that often encourage them to click on malicious links, open suspicious files, or install infected software. The increase in calendar phishing attempts is a result of the somewhat effective email and text filters implemented by email and wireless network service providers over the years.

However, bad actors never stop looking for ways to get into someone’s system, and over the last couple of years they’ve found a way to exploit vulnerabilities in calendar applications on many popular scheduling platforms, including but not limited to Outlook, Google, and Apple. Calendar invites often require immediate attention, and hackers rely on the fact that an increased sense of urgency often makes people more prone to making a mistake.

Key Takeaways

Are all unsolicited calendar invites a scam?

Not really. Some salespeople with questionable ethics have started deploying the technique too, hoping that the person receiving the email might accept the invite and end up attending a sales meeting. However, unsolicited calendar invites are just a small percentage – the majority of the attempts are cybercriminals trying to steal sensitive data so they can commit crimes, or sell the stolen information to other bad actors more capable of committing more sophisticated cybercrimes such as identity theft, ransomware attacks, financial scams and other types of internet fraud. Often, fraudsters are also hoping to receive a payment for a bogus bill or a fake invoice.

Hackers even attempt to steal active tokens: for example, users who click on an HTML calendar invite attachment are taken to a legitimate Microsoft device authentication page, allowing the hacker to capture the session token once the user authenticates.

How do bad actors even get the emails to the people they target?

Billions of records have been leaked online and/or on the dark web over the last few decades. The popular (and safe) online spot called Have I Been Pwned contains approximately 2 billion unique email addresses. Many millions more records are likely out on the dark web, awaiting discovery by white-hat hackers and cyber researchers. Often, after a data breach or ransomware attack, hackers attempt to sell the stolen info to the highest bidder or simply dump it on the dark web for everyone to access.

What should people NOT do when they receive CalPhishing attempts?

One of the most important things is to never interact with the calendar invites. Calendar users are advised not to accept or decline the calendar invite. People should also not click on any of the links in the invite. It probably won’t come as a surprise, but folks are also not supposed to open any of the file attachments, if any. Recipients are often tempted to reply to the senders, asking them to stop sending the invites or threatening them with law enforcement, but this is also considered a mistake.

All of these actions are inadvisable because they send a response to the attacker that confirms this is an active email. When hackers know the email is active, they may spend more time tricking the user, since this active email could also be a banking or crypto wallet login username. With so many stolen records and the ever-growing lack of quality password hygiene, often finding a possible password for an active account is just a few clicks away for hackers.

How to fight back against calendar phishing attempts?

Protecting the systems and adjusting the calendar settings so it is harder for cybercriminals actually to send those invites is really important. The exact settings required depend on the calendar platform used – Outlook, Apple Calendar, or Google Calendar. However, all of them generally allow you to stop invites from automatically appearing on a calendar. Users need to adjust settings so that calendar owners can manually approve events before they are added to the calendar. Deleting the invite and reporting it as junk is usually more than enough for users who wish to do their part in fighting back against the attackers.

Preventive measures also include protecting your personal information online. Reducing your digital footprint by removing active email addresses is as important as installing adequate cyber protection on all connected devices and adjusting the calendar settings. The only thing worse than having an email address included in random dark web lists is having it publicly displayed online for anyone to see and exploit.

Exit mobile version