Scam Defence

Calendar Invite Phishing: Why an Event Can Be a Scam

A surprise calendar event can carry fake renewal notices and support links. Verify the account directly and avoid interacting with the invitation.

Muhammad Azhar August 14, 2026 Reviewed August 21, 2026 3 min read

A malicious calendar invitation can appear authoritative because it sits inside a trusted calendar app. The event description may claim a subscription renewed, a payment failed or support must be called immediately.

The calendar is only the delivery channel

An invitation does not prove that the sender has access to your account or that a charge occurred. It can be sent to an email address like any other unsolicited message.

Safe response

  1. Do not call numbers or open links in the event.
  2. Check the claimed service through its official app or typed address.
  3. Report the invitation as spam using the calendar provider.
  4. Delete it without replying; a response may confirm the address is active.
  5. Review settings that automatically add invitations.

If credentials were entered

Change the password through the real service, end other sessions and review recovery details. Unexpected events can also arrive after an inbox compromise, so check forwarding rules and connected applications if other suspicious activity exists.

A calendar entry can create urgency, but it cannot verify a debt, renewal or security incident. Confirm the claim where the account is actually managed.

Prevent automatic clutter

Calendar providers can limit which invitations appear automatically or move unknown senders into a pending state. Review this setting without disabling legitimate meeting workflows. For organizations, external-invite banners and user reporting provide context without treating every outside event as malicious.

Do not click “unsubscribe” inside the event

That link is controlled by the sender. Use the calendar application's built-in spam and delete controls so the response does not confirm an active account.

Why declining can sometimes help the sender

A reply or decline may confirm that an address is monitored. Use the provider's report-spam function when available, then remove the event. Administrators should review whether external invitations appear automatically and whether suspicious events can trigger notifications across connected devices.

Inspect the account when events keep returning

Persistent spam can be ordinary unsolicited mail, but it can also indicate a connected application or mailbox rule. Review authorized apps, delegated calendars, forwarding and recent sessions. Do not grant a “calendar cleaner” broad access without checking its publisher and scopes.

The claimed renewal or invoice should be checked in the service's official account. A calendar event is not a billing record.

An event is not evidence of a charge

Calendar invitations can be delivered to an address without compromising the account. Attackers exploit the trusted calendar interface to display fake renewals, invoices and support numbers. Verify the claim inside the official service or through the original purchase record, not through a link or telephone number in the event.

Use the provider's report-spam function and remove the invitation without replying. Declining can confirm that the address is monitored. Do not use an “unsubscribe” link controlled by the sender.

Investigate repeated or internal-looking events

Persistent events may still be ordinary spam, but they can also come from a connected application, delegated calendar or mailbox rule. Review authorized applications, forwarding, recent sessions and sharing permissions. In an organization, preserve the invitation headers and check whether similar events reached other users.

If credentials were entered, secure the real account and revoke sessions. If a support caller received remote access or payment, treat those as separate incidents. The calendar is the delivery channel, not the full scope of the response.

Sources and further reading