Your employees know to be suspicious of strange emails. They hover over links. They check sender addresses. They've been through the training. But here's the uncomfortable truth: the attackers know this too — and they've already moved on to your calendar.
Fake calendar invites are now one of the fastest-growing social engineering tactics targeting businesses, and they're being turbocharged by artificial intelligence. The result is a threat landscape that is evolving faster than most organisations can track. This post breaks down exactly what's happening, why it's working, and — most importantly — what your organisation can do about it right now.
The Numbers Don't Lie: Social Engineering Is Exploding
Before we get into the mechanics of the attack, it's worth understanding just how dramatic the surge has been.
The total volume of phishing attacks has exploded by 4,151% since the advent of ChatGPT in 2022.
That's not a typo.
In 2025, analysts documented a watershed moment: a malicious email attack every 19 seconds — more than doubling from 2024's pace of one every 42 seconds.
And the human cost is real.
Phishing remains one of the top causes of security breaches, with the "human element" involved in 68% of breaches.
Perhaps most alarming is the AI angle.
Hoxhunt data shows AI-generated phishing surged roughly 14 times at the end of 2025, climbing from under 5% to 56% of detected attacks in a single month.
According to ISACA's 2026 Tech Trends report, AI-driven social engineering has overtaken ransomware to become the single biggest cybersecurity concern, with 63% of surveyed IT professionals flagging it as their top threat.
The stakes couldn't be higher — so let's look at how the attacks actually work.
What Is Calendar Phishing — and Why Is It So Effective?
Calendar phishing is a social engineering tactic in which cybercriminals trick someone by delivering fake calendar invites that often contain malicious links or attachments designed to steal data or install malware.
The reason it works so well is simple psychology.
Calendar phishing is dangerous because you don't expect something as ordinary as a calendar event to be a phishing attempt. It hides in plain sight, often behind the names of trusted tech platforms used by millions of people, so it is often overlooked as a threat.
A suspicious email might be ignored, but a calendar invite can land directly on a schedule, create a reminder, and appear alongside legitimate meetings — even if the original email would have been skipped.
That's the genius of it: attackers aren't fighting your email filters anymore. They're exploiting the tools you rely on to stay organised.
How the Attack Unfolds
The mechanics are straightforward but effective:
Attackers send fake calendar invites, taking advantage of Google's default setting that automatically adds invitations to your calendar.
When a user receives an invite, even from an unknown sender, the event appears in their calendar, often with an urgent message in the description.
Once a user clicks a link or calls the number, the attacker can try to steal login credentials, financial information, or gain remote access to the computer.
These invitations bypass traditional email filters by embedding phishing content within calendar events that automatically appear in Outlook calendars.
Typical subject lines include urgent prompts like "Final Notice: Payroll Acknowledgment Required" or "Invoice Payment Overdue."
We're seeing a surge in phishing calendar invites that users can't delete, or that keep coming back because they sync across devices.
The AI Upgrade: Why These Attacks Are Harder to Spot Than Ever
Traditional phishing emails often gave themselves away — grammatical errors, awkward phrasing, obviously fake sender names. AI has largely eliminated those tells.
Machine learning models can generate fluent, personalised emails that lack the tell-tale errors of old-school scams. Attackers feed these models with stolen data — corporate emails or social media — to craft messages that read as if a colleague or vendor wrote them.
AI enables attackers to generate thousands of unique, personalised phishing messages per hour at a quality no human operator could match at scale.
Worse still,
criminal marketplaces now sell AI-powered social engineering toolkits with voice synthesis and deepfakes for under $100/month.
The convergence with deepfake technology adds another terrifying dimension.
Attackers are deploying AI-generated voice and video that can impersonate executives in real-time. Criminals have used deepfake audio on phone calls to convincingly pose as a CEO or CFO, tricking employees into executing large wire transfers.
Attackers can now generate highly convincing phishing emails in roughly 5 minutes, compared to 16 hours manually — a 192x increase in speed — and AI-generated phishing achieves a 54% click-through rate, compared to about 12% for traditional phishing.
That gap is devastating.
Real-World Campaigns Targeting Your Organisation Right Now
This isn't theoretical. Active campaigns are being documented across platforms.
An ongoing phishing campaign impersonates popular brands such as Unilever, Disney, MasterCard, LVMH, and Uber in Calendly-themed lures to steal Google Workspace and Facebook business account credentials.
The campaign is highly targeted, with professionally crafted lures that create conditions for high success rates — and access to marketing accounts gives threat actors a springboard to launch malvertising campaigns, malware distribution, and further phishing attacks.
Threat actors are mimicking the appearance of Google Calendar invites to create a sense of familiarity. These invitations appear authentic at first because their format closely resembles legitimate Google Calendar invitations — however, upon closer inspection, it becomes evident that they are spoofed.
Social engineering and business email compromise (BEC) attacks increased from 20% to 25.6% from January through May 2025 compared to the same period in 2024, likely due to the growth in AI use for crafting convincing impersonations.
Red Flags: How to Recognise a Fake Calendar Invite
Training your team to spot the warning signs is one of your most powerful defences. Here's what to look for:
- Urgency-driven titles:
Event titles designed to cause urgency — such as "Invoice," "Payment Overdue," or "Crypto Purchase" — are a common red flag.
- Unusual sender domains:
Spoofed addresses usually differ slightly from the legitimate ones being impersonated — sometimes altering just a single character, e.g., "Micr0soft" instead of "Microsoft."
- Suspicious descriptions:
Event descriptions containing links, attachments, or phone numbers asking you to log in, pay, or provide personal information should trigger immediate suspicion.
- Uninvited invites:
Invitation emails or events from unknown senders that you didn't request are an immediate warning signal.
- Unfamiliar platforms:
The invite may contain a link to a fake meeting platform, a document, a login page, an invoice portal, a support page, or a file download.
Practical Tips: How to Protect Your Organisation Today
Understanding the threat is step one. Taking action is what matters. Here are the controls and habits your organisation should implement immediately:
Technical Controls
- Disable automatic calendar processing.
Organisations should configure calendar systems so that invites are not automatically added without user approval. Keeping invites as emails until accepted gives employees a chance to review them carefully.
- Restrict calendar permissions.
Limiting who can add events to calendars reduces exposure. Only trusted users and approved applications should have permission to create events automatically.
- Configure platform-specific defences.
In Microsoft 365, add suspicious sender domains to the Tenant Allow/Block List and add confirmed phishing URLs as block entries so future messages containing those links are treated as high-confidence phishing and stopped earlier in the delivery pipeline.
- Enable MFA — and consider upgrading it.
FIDO2 hardware keys reliably block credential-based social engineering, since cryptographic authentication resists AI-generated phishing attacks.
- Deploy AI-powered defences.
Invest in AI-powered defences that detect behavioural anomalies, not just content
— because attackers are already using AI to bypass signature-based tools.
Human and Process Controls
- Train specifically for calendar threats.
Regular security awareness training should specifically address calendar threats, teaching employees to recognise red flags like generic meeting titles or invites that bypass normal scheduling protocols. Show real examples and conduct simulated calendar phishing exercises to identify users who need additional training.
- Build a verification culture.
Remove urgency from your workflows — urgency is the attacker's most powerful tool, and removing it from your processes removes their leverage.
- Teach employees to report, not just delete.
Employees should know how to report calendar events — not just emails — when something looks wrong.
- Invest in ongoing phishing simulations.
KnowBe4's 2025 Phishing By Industry Benchmarking found a 33.1% baseline phish-prone percentage that drops to 4.1% after 12 months of training — an 86% reduction.
Consistent training pays off.
Conclusion: The Threat Is Real — Your Response Must Be Too
Calendar phishing and AI-powered social engineering aren't emerging threats on the horizon. They are active, escalating, and targeting your organisation right now.
87% of security leaders observed an increase in AI-based social engineering attacks in the past 24 months, and 83% of those leaders experienced at least one such attack in 2025.
The question isn't whether your organisation will be targeted — it's whether you'll be ready when it happens.
The organisations that come through 2026 intact will be the ones that treat social engineering as a business process problem, not just a security technology problem.
That means combining smart technical controls with a well-trained, vigilant workforce.
Don't wait for a breach to act. If you're unsure where your organisation stands against today's social engineering threats, now is the time to conduct a security assessment, review your calendar platform settings, and invest in up-to-date security awareness training. The cost of prevention is a fraction of the cost of a successful attack — and your calendar is already open for business.


