logo

Calendar phishing attacks expanding across service providers · Blog · Sublime Security

ID: 258d9b0f-932b-5de6-8817-df3615008846

STIX ID: report--258d9b0f-932b-5de6-8817-df3615008846

Feed Name: Sublime Security Blog

Threat Score
60/100

Date Published: 2026-07-13

Date Updated: 2026-07-22

...
...

Sublime’s Attack Spotlight documents a widespread calendar/ICS phishing campaign in which attackers embed callback-phishing payloads (phone numbers and malicious mailto/URLs) inside meeting invitations sent via legitimate services (Teams, Trafft, Zoho, Calendly, Demio). These attacks bypass many email defenses because payloads persist on calendars even when emails are blocked; the report provides multiple real-world examples, indicators (sender domains, reply-to addresses, freemail addresses, phone numbers), and detection/mitigation guidance (AI-powered calendar scanning, input validation by providers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.