Phishers Spoof Google Calendar Invites in Fast-Spreading, Global Campaign
ID: e8e5c4c1-be87-5991-9974-94b623ded47c
STIX ID: report--e8e5c4c1-be87-5991-9974-94b623ded47c
Feed Name: Dark Reading
Date Published: 2024-12-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Check Point researchers discovered a fast‑spreading phishing campaign that spoofs Google Calendar invitations to bypass email protections and steer victims to Google Forms/Drawings and fake reCAPTCHA pages; the goal is credential theft and downstream financial scams. Analysts observed over 4,000 malicious messages in four weeks referencing about 300 brands, and recommended mitigations including enabling Calendar "known senders", deploying advanced email scanning and URL reputation checks, enforcing MFA, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
