logo

Fake Calendar Invitations Move to Microsoft Outlook

ID: 55063bb9-053f-5a78-abf6-2ef324e13a7c

STIX ID: report--55063bb9-053f-5a78-abf6-2ef324e13a7c

Feed Name: KnowBe4 Blog

Threat Score
45/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

A scam campaign abusing Outlook calendar invites was observed: the attacker sent a calendar invite and an email containing a PDF with a QR code that redirected to a development-site phishing page requesting Microsoft 365 credentials. The reporter analyzed email headers (showing DKIM authentication but alignment failure and an SPF failure at an intermediate hop), traced the QR/landing domain (a likely compromised or cheaply hosted dev site using CAPTCHA to evade automated detection), and provided mitigation guidance to disable automatic addition of events from email and to avoid opening attachments or scanning QR codes outside a safe environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.