Calendar-based phishing attacks surge by 33,000% since May

Cybersecurity researchers at Sublime have reported a massive 33,000% increase in calendar-based phishing attacks between May and September 2026. These attacks exploit the .ics calendar file format to bypass standard email security filters, as they often originate from legitimate services like Gmail. By sending unsolicited calendar invites, attackers trick users into clicking links that lead to the installation of malicious Remote Monitoring and Management (RMM) tools, such as ScreenConnect. Once installed, these tools allow attackers to gain control over endpoints, facilitating the deployment of ransomware or infostealers. The researchers note that this method has moved into the mainstream due to its low cost and high success rate, even when initial emails are routed to spam folders. Experts advise users to remain vigilant, scrutinize all unexpected calendar invites, and verify the identity of senders before interacting with any embedded links or attachments.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
Researchers demonstrate InjectEave: A technique to intercept audio through walls
Researchers from HKUST (Guangzhou) and HK PolyU have unveiled 'InjectEave,' a sophisticated eavesdropping technique capable of extracting audio from h…
The article discusses an innovative approach to digital content authentication, proposing the use of 'spymarks' as a superior alternative to tradition…
Cybersecurity researchers at Zimperium have identified a sophisticated new Android malware strain dubbed RatHat. Unlike traditional malware that relie…


