Beware of Google Calendar Phishing Scams

An image of the Google calendar logo with a "phishing" hook

Image generated by Google Gemini

What are Google Calendar phishing scams?

Unlike traditional phishing scams that are sent through email, attackers have started to leverage Google services such as Google Calendar to deliver malicious links and documents. This scam involves fake invitations to meetings or invitations to calendar events that often contain malicious links, attachments such as files or Google docs, or instructions that may lead to a compromise or exposure of sensitive data. Google Calendar phishing scams often combine Google Calendar invitations with other phishing techniques to convince you into falling for the scam.

How to spot a Google Calendar phishing scam?

  • Look for unusual senders or invitations originating from a non-hawaii.edu accounts, especially ones that you didn’t request.
  • Identify impersonation of authority figures. Scammers will often claim to be or impersonate a person of authority such as your supervisor, dean/director, or even the UH president. In some cases, scammers may spoof a real hawaii.edu user or utilize a compromised account.
  • Identify the “lure”. Scammers use urgent or alarming titles to trick you into clicking. Watch out for events with titles containing “Security Alert,” “Invoice Processed,” or “Urgent Action”.
  • Recognize unusual requests. Scammers often ask you to perform unusual tasks such as purchasing gift cards, paying in cryptocurrency, copy-paste content into your computer, asking you to “verify” your account, or asking you to call a number.
  • Scammers know who you are. Scammers will often research their targets and create targeting phishing based on their job or role. Do not assume that references to you, your colleagues, your job/role, or UH operations and policies means that the invitation is legitimate.

Examples of Google Calendar phishing

Example 1: A Google Calendar invite was sent to an individual asking them to complete a Docusign to update a contract. Note the unusual sender and the link to “view documents” which is a malicious link.

Example of a google calendar phish asking the victim to complete a docusign

Example 2: A Google Calendar invite was sent to an individual claiming that their membership plan for McAfee has been activated and is set to renew automatically. The invite contains a contact number that belongs to the scammer.

Example google calendar phishing attack claiming that the victim's antimalware membership was activated.

What to do if you suspect a Google Calendar phishing scam?

If you see a suspicious Google Calendar invitation that you are not expecting:

  • Immediately stop and do not click on any links
  • Do not open any documents attached to the invitation. Often, malicious Google Calendar invites will include some kind of document that contains the real phishing threat inside.
  • Do not click “Accept,” “Maybe,” or “Decline”. Clicking any of these tells the scammer that your email address is active and “real,” which will lead to even more spam.
  • Report the suspicious Google Calendar invite by forwarding it to phishing@hawaii.edu, or sending a screenshot of what you received.