'It is significant, and it’s something many organisations haven't accounted for': The phishing threats hiding in your calendar invites
Although many people would think of phishing as a malicious email containing a suspicious link or attachment, hackers have now moved far beyond this to target trusted business tools including calendars and meeting invites.
We spoke to Soundharya Bharani Poomalai, Associate Threat Analyst, Barracuda , to find out more.
Why are attackers increasingly turning to calendar invites and .ics files as phishing vehicles, and what has changed in the threat landscape to make this an attractive attack surface now? Calendars have become part of daily business admin and are used far beyond meeting scheduling.
People now get invites for things like policy acknowledgements, handbook reviews, benefits enrolment windows and compliance training reminders.
A calendar invite referencing an HR update or a payroll action doesn't look out of place, and this allows attackers to blend in more easily than a suspicious email ever could.
There's also a structural advantage.
Calendar entries get added automatically with little or no interaction from the recipient, and they tend to persist even if the original email is deleted or quarantined.
Mobile adds another layer to this.
A lot of calendar notifications get handled on phones, which often sit outside the reach of desktop-focused security tools.
How significant is the visibility gap between what an email security system can inspect and what is rendered by a calendar application? It is significant, and it’s something many organisations haven't accounted for.
Traditional email security is built to scan the message body, subject line and attachments, whereas an .ics file often slips through as a calendar object and doesn’t receive the same level of inspection.
The problem is that .ics files carry much more than a date and time.
They can include event descriptions, organiser details, locations, attachments, URLs and custom metadata fields, and any of these can be used to hide phishing content.
Once the calendar app renders that content, the recipient sees corporate branding, instructions or a QR code that looks entirely legitimate.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.