What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A meeting that appears unexpectedly in your calendar may be a phishing attempt. Treat it like a suspicious email: don’t click its links, call numbers in it, scan its QR codes, or open its attachments. Verify any claimed meeting or charge using a contact method you already trust. The event appearing by itself does not mean your account or device has been compromised.
What is calendar phishing?
Calendar phishing is ordinary phishing delivered through a calendar invitation or event. A scammer uses a familiar-looking meeting, renewal notice, payment alert, voicemail notification, signature request, or domain-expiry warning to prompt you to act. The goal may be to steal a password or authentication token, trick you into authorizing access, defraud you, or deliver malware.
The event might contain a link to a fake sign-in page, a phone number for fraudulent “support,” a QR code, or a file to download. Some lures impersonate well-known services or appear to concern a meeting you supposedly forgot.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Why did an event appear when I never accepted it?
Some calendar services and clients can add or display invitations without a clear accept action. As Luke Wescott, a threat detection engineer at Sublime Security, told The Guardian: “Calendar apps, such as Google Calendar, can add invitations automatically without users even accepting them.” Invitations may arrive through an ICS attachment, and an entry can remain visible even if a related email is filtered or deleted.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
That is why an event can show up even when you cannot find its email in your inbox. It does not establish that you accepted the invitation, nor does its presence alone show that your account was accessed.
Is the meeting invite real?
Don’t decide based on the calendar entry alone. Check whether you expected the meeting and whether the organizer, subject, and details make sense. If it claims you owe money or need to sign in, open the relevant service directly using its official app or a saved address, or contact the organization using a number you already know. Do not use the event’s link or phone number to verify its own claims.
Rank #2
- FIDO2 + FIDO U2F certified and supported USB security key
- Secured by NXP semiconductors
- Works in every browser and application without installing any drivers
- Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
- Unexpected urgency: A charge, account alert, document signature, or expiring-domain warning pressures you to act immediately.
- Unexpected instructions: The event asks you to sign in, authorize access, call support, scan a QR code, or download a file.
- Unfamiliar context: You do not recognize the meeting or sender, or the event does not fit your work or personal schedule.
These are reasons to verify independently, not proof that every unfamiliar invitation is malicious. Legitimate invitations can also be unexpected or filtered incorrectly.
Why are calendar phishing scams getting attention?
The “growing exponentially” description refers to one security company’s observations, not a verified industry-wide rate. The Guardian reported that Wescott described Sublime Security’s experience as “exponential growth.” Sublime’s 2026 figures show reported changes in its observed calendar-based attacks: 282% over May in June, 338% over June in July, and 1,216% over July in August. It reported a 1,426% increase in the first half of September compared with the full month of August, then projected 2,852% growth for September over August and roughly 33,000% growth from May to September. The September comparison covers only half a month, and the latter two figures are projections, not completed-month results. These are vendor-reported observations, not independent estimates of all attacks.
Rank #3
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
Mimecast Threat Research reported more than 4,000 QR-code phishing campaign incidents and 43,000 emails abusing calendar invites within a month in a particular May 2026 campaign. Those counts describe that campaign, not calendar phishing as a whole. No independently verified, population-wide incidence figure is established by these reports.
How do calendar phishing attacks work?
A scammer sends an invitation to a work or personal address, sometimes as an ICS file. Depending on the calendar service and client, the event may be displayed or added without an obvious acceptance step. Its familiar location can make it seem more trustworthy than an unsolicited email, while the associated email may be filtered or removed separately.
Rank #4
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
The event then tries to move you to another channel or action. A link may lead to a fake Google, Microsoft, PayPal, or document sign-in page; a number may connect to a fraudulent support line; a QR code may hide a destination; and a download prompt may deliver malware. The harmful step is engaging with the lure—such as entering credentials, authorizing access, calling the number, or downloading a payload—not merely seeing an event.
Examples of documented techniques
- Sublime Security described a Google Calendar invitation that linked to a page delivering a maliciously configured ScreenConnect remote-monitoring installer. This is one reported incident, not a claim that calendar scams generally use that software.
- Mimecast documented QR codes concealed in deliberately malformed calendar attachments, a technique intended to frustrate QR-code extraction.
- Fortra described a separate campaign combining calendar phishing with ConsentFix, a device-code phishing technique.
These examples show that campaigns vary; not every suspicious calendar event uses automatic insertion, QR codes, Google Calendar, or the same credential-theft method.
Best Value
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
What should you do with a suspicious calendar invitation?
- Do not interact with it. Don’t click its links, call its number, scan its QR code, open its attachment, or download a file. The FBI’s 2020 Portland Field Office guidance says not to click links or open attachments—or, in this case, calendar invitations—you aren’t expecting or don’t recognize.
- Verify the claim elsewhere. Check your schedule with the supposed organizer through a known work channel. For a charge or account alert, visit the service directly or use contact details from a trusted source, not the event.
- Report or remove the event carefully. Use the calendar service’s reporting controls if available. The Guardian cautions that declining a suspicious invitation can signal that your address is active; avoid using “decline” as your response to a suspicious invite.
- Review invitation handling. Check your calendar’s settings for controls on automatic invitation handling. The Guardian notes that Google Calendar offers options to limit automatic acceptance, and the FBI advises reviewing calendar permissions. Product labels and options vary by service and account, so consult the current official instructions for your calendar before changing a setting.
- Act if you already engaged. If you entered a password or authentication code, or authorized access, contact the account provider or your workplace IT team through a trusted route. If you downloaded or opened a file, tell workplace IT if it is a work device. The appropriate recovery steps depend on what happened and the account or device involved.
What should organizations check?
Email filtering alone may not address an event that has already been created or remains after its message is remediated. Security teams should assess whether their controls inspect calendar objects and ICS content, handle QR codes and image-only content, and remove or remediate calendar entries as well as email.
When evaluating defenses, check whether they:
- Inspect the calendar event or ICS attachment, not just the email carrying it.
- Address events that persist after email filtering or remediation.
- Handle QR codes and malformed calendar files.
- Fit the organization’s deployment and administration capacity.
- Avoid blocking legitimate invitations through overly broad filtering.
The Guardian reports that broad filtering of invitations from legitimate platforms can block real meetings too. Security teams should evaluate vendor efficacy claims independently and weigh detection against disruption to normal scheduling.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

