Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake Calendar Invites Surge, Delivering Malware via Automatic Calendar Additions

Attackers are abusing default calendar‑invite handling to drop malicious links, with a 1,216 % increase in August and a projected 2,852 % jump for September. The rise highlights gaps in user awareness and configuration controls that continuous audit programs must address.

LiveThreat™ Intelligence · 📅 September 19, 2026· 📰 zdnet.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
3 recommended
📰
Source
zdnet.com

Fake Calendar Invites Surge, Delivering Malware via Automatic Calendar Additions

What Happened — Attackers are sending malicious iCalendar (.ics) files that many email clients (Outlook, Gmail, Apple Mail) automatically add to a user’s calendar before the invite is accepted. The embedded links or QR codes can download malware the moment the victim clicks the calendar entry.  Sublime’s research shows a 1,216 % month‑over‑month rise in August and a projected 2,852 % jump for September.

Why It Matters for Trust & Control Assurance

  • The scenario exploits a default configuration that bypasses traditional email‑gateway controls, highlighting the need for continuous monitoring of application‑level settings as part of a control‑assurance program.
  • It underscores the importance of security‑awareness training that covers non‑email phishing vectors, providing defensible evidence that users are educated on emerging tactics.
  • Detecting and logging calendar‑event creation can supply audit‑ready evidence that the organization is actively monitoring for anomalous behavior.

Who Is Affected – Any organization that relies on electronic calendars, especially:

  • Technology and SaaS providers
  • Financial services firms
  • Healthcare and life‑science enterprises
  • Large enterprises with distributed workforces

Recommended Actions

  • Review and harden calendar‑invite settings (disable automatic addition of .ics files).
  • Deploy security‑awareness modules that specifically cover “ICS phishing” and calendar‑based attacks.
  • Enable logging of calendar‑event creation and integrate alerts into your SIEM for anomalous patterns.
  • Validate that email‑gateway and endpoint solutions inspect calendar attachments for malicious content.

Technical Notes – Attack vector: malicious .ics files delivered via email (phishing). Payloads are typically links or QR codes that lead to ransomware, remote‑access tools, or credential‑stealing sites. No specific CVE is associated; the risk stems from default client behavior.

Source: ZDNet – Fake calendar invites can infect your system, and they’re surging – how to protect yourself

📰 Original Source
https://www.zdnet.com/tech/fake-calendar-invites-malware/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →