【Poland】

2025-06-26 18:54:07 539 views 976 comments

Scammers are Polandphishing in a new pond.

As identified by Kapersky Labs in a report from Wired, bad actors are taking advantage of a Google Calendar setting that lets anyone place event invites in another user's calendar.

In the scam, an event will pop up in a user's Google Calendar; the description will invite them to take a survey or claim a cash reward. That includes a link, prompting users to enter personal and financial information.

Google Calendar's architecture unfortunately gives these schemes the ring of legitimacy, since simply having an event on your calendar could trigger notifications about it. Users have to be diligent about knowing whether they or someone they know has placed the event on the calendar, or if it's from an unknown source.

Mashable employee Dana Froome recently received a phishing event invite. Froome is diligent about her personal Google Calendar, using it to manage "everything outside of work." So when she got an event invitation for something she clearly had not placed there, she was confused, and then disturbed.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

"I live by my personal calendar," Froome said. "I was taken aback by what it was. It felt invasive."

SEE ALSO: Google bans embedded in-app sign-ins to curb phishing attacks

Froome searched her Gmail for the event invitation, but could find nothing there, so she deleted the invitation.

As Wiredpoints out, users can guard against the attack by changing their Google Calendar privacy settings:

"Open Google Calendar's settings on a desktop browser and go to Event Settings > Automatically Add Invitations, and then select the option 'No, only show invitations to which I've responded.' Also, under View Options, make sure that 'Show declined events' is unchecked, so malicious events don't haunt you even after you decline them."

Google makes it easy to invite people to events without the need for tedious logistical email chains. But where there's a public setting, there's a scammer ready to exploit it.


Featured Video For You
Scammers use tax-themed emails to infect PCs with malware

Topics Cybersecurity

Comments (385)
Style Information Network

Best soundbar deal: Get $50 off the Amazon Fire TV Soundbar Plus

2025-06-26 18:40
Progress Information Network

The Whimper of Democracy

2025-06-26 18:27
Transmission Information Network

White Nationalism’s New Clothes

2025-06-26 18:24
Reality Information Network

Weather app glitch makes it look like hell is basically freezing over

2025-06-26 17:08
Search
Newsletter

Subscribe to our newsletter for the latest updates.

Follow Us