
An unexpected event appears on your calendar claiming that a payment failed, a subscription renewed, or an urgent meeting requires your response. Before you click a link, call the listed number, scan a QR code, open an attachment, or reply, use this calendar invite phishing checklist to inspect the event safely.
Calendar invite phishing is a scam that uses a calendar event or meeting invitation to pressure you into clicking a link, scanning a QR code, opening a file, calling a phone number, joining a meeting, or sharing sensitive information.
The safest response is simple: stop, check, and verify through a separate trusted channel.
Do not use the link, QR code, attachment, phone number, reply address, or login button inside a suspicious invitation to prove that it is genuine. Verify the request outside the event.
What Is Calendar Invite Phishing?
Calendar invite phishing is a form of social engineering delivered through a meeting invitation, calendar event, event-notification email, or attached calendar file. The event may pretend to be a work meeting, security alert, invoice, appointment, purchase notice, subscription renewal, delivery update, or social invitation.
The scam becomes dangerous when it tries to move you from the calendar into another action. That action may be clicking a fake login page, calling a fraudulent support number, scanning a QR code, opening an attachment, approving a sign-in request, installing remote-access software, or sending money.
A calendar platform can deliver an invitation without guaranteeing that the organizer or message is trustworthy. An event appearing inside a familiar calendar app does not prove that its contents are safe.
Judge the invitation by its organizer, context, destination, requested action, and independent verification—not merely by the calendar service displaying it.
Some invitations arrive as ordinary calendar requests. Others are added through email, connected applications, calendar subscriptions, or .ics files. A calendar file is not automatically malicious, but an unexpected file or event deserves careful inspection before you interact with anything inside it.
Use the STOP–CHECK–VERIFY Framework
The following original three-step framework helps you slow down an urgent-looking invitation before it controls your next action.
STOP
Do not click, call, scan, download, accept, reply, pay, enter a password, or approve a login prompt.
CHECK
Inspect the organizer, full email address, domain, event title, timing, attendee list, links, files, phone number, and requested action.
VERIFY
Contact the supposed organizer through a saved number, known email thread, company directory, official app, or another trusted channel.
| Unexpected event | Safer verification method |
|---|---|
| Work meeting | Message the organizer through your normal workplace chat or company directory. |
| Subscription renewal | Open the provider’s official app or manually visit the website you normally use. |
| Delivery or appointment | Check your existing account, confirmation email, or previously saved contact. |
| Family or social invitation | Contact the supposed host using a saved number or existing conversation. |
| Account-security warning | Open the account directly and review its security page without using the invitation. |
Calendar Invite Phishing Checklist: 12 Checks
One warning sign does not always prove that an invitation is fake. Look at the full pattern. Multiple mismatches—especially an unexpected sender, urgent demand, unfamiliar destination, and request for credentials or payment—should increase your caution.
-
Were You Expecting the Invitation?
Start with context. Did you discuss this meeting, appointment, renewal, delivery, or event before it appeared? Does the timing match something you actually arranged?
An unexpected invitation is not automatically malicious, but it should not receive the same trust as a meeting you already planned.
-
Do You Recognize the Organizer’s Full Address?
Do not rely only on the display name. Open the event details and inspect the organizer’s full email address without clicking any embedded content.
Watch for misspelled domains, unrelated personal accounts, extra words, unusual subdomains, or a sender address that does not match the person or organization named in the event.
-
Does the Event Create Artificial Urgency?
Phishing invitations often try to prevent careful thinking. Common pressure language includes:
- Payment required today
- Account will be closed
- Final warning
- Subscription already renewed
- Security breach detected
- Immediate cancellation required
A genuine issue can still be urgent, but urgency should never replace independent verification.
-
Does It Claim You Were Charged for Something?
Be cautious when an unexpected event claims that you purchased software, renewed antivirus protection, ordered cryptocurrency, upgraded cloud storage, or started a costly subscription.
Do not call the number in the event to dispute the charge. Open the relevant account independently and check whether a real transaction exists.
-
Does It Ask You to Call a Phone Number?
A fraudulent phone number can be the main phishing payload even when the invitation contains no obvious malicious link or file.
During the call, an impersonator may ask for a card number, password, verification code, gift-card payment, or permission to install remote-access software. Find the organization’s official number independently instead.
-
Does It Contain an Unfamiliar Link?
Do not open a link merely to investigate it. Look for shortened URLs, misspelled company names, unrelated domains, unusual login requests, or text that describes one destination while pointing somewhere else.
Access the supposed service through its official app, a saved bookmark, or an address you type yourself.
-
Does It Contain a QR Code?
A QR code hides its destination until it is scanned. It may send your phone to a fake login, payment, delivery, or document-sharing page outside the protections available on another device or workplace network.
Do not scan a suspicious QR code to “see where it goes.” Verify the request separately.
-
Does It Include an Unexpected Attachment?
Be cautious with unexpected HTML files, PDFs, office documents, ZIP archives, or calendar files claiming to contain an invoice, agenda, receipt, security report, or meeting instructions.
A familiar file extension does not guarantee safe content. Ask the known organizer to confirm and resend the document through an established channel.
-
Does It Request a Password or Verification Code?
A normal event invitation should not require your email password, multifactor authentication code, password-reset code, or login approval merely to reveal basic event details.
The U.S. Federal Trade Commission has warned about fake invitations that request email credentials or special codes. Its advice is to resist clicking and confirm the invitation directly with the supposed host.
-
Are the Attendee List and Event Details Unusual?
Look for random external addresses, large groups of strangers, an unrelated organizer, inconsistent company names, a vague location, missing agenda, or attendees who do not fit the stated purpose.
Some legitimate public events have large attendee lists, so use this check with the rest of the evidence rather than treating it as proof by itself.
-
Can You Verify the Request Independently?
Contact the organizer in a separate conversation. For a company, open the official account or use a known support channel. For a friend, family member, coworker, client, or teacher, use a saved contact or established communication method.
Do not ask the suspicious sender to verify themselves through the same invitation.
-
Does the Event Make Sense Without Its Urgent Demand?
Remove the pressure mentally. Ignore the demand to click, call, scan, log in, or pay. Does the remaining event still look like a real meeting or appointment?
If the event has no believable purpose once the urgent action is removed, treat it as suspicious until independently verified.
A credible invitation should still make sense after you ignore its demand for immediate action. A scam often collapses once the pressure, payment request, phone number, or login button is removed.
What Should You Do With a Suspicious Calendar Invitation?
Do Not Use Its Embedded Contact Information
Avoid its links, phone numbers, QR codes, attachments, reply address, or login buttons. Even when the event impersonates a real organization, those details may lead directly to the scammer.
Report the Event as Spam When the Option Is Available
Google’s current Calendar guidance says that reporting an event as spam removes it from your calendar. If it is recurring, the series is removed. Google also notes that the reporting option applies to events sent through Google Calendar and may not be available for events created through another provider, application, or service.
Review Google’s official instructions for reporting suspicious Calendar events.
Remove It When Reporting Is Unavailable
Calendar interfaces and labels can change. Use your platform’s current official help instructions to remove or delete the unwanted event without interacting with the content inside it.
Avoid Unnecessary Replies
Do not accept, decline, or reply merely to confront the sender or ask whether the event is genuine. Response behavior differs by platform, but unnecessary engagement can create more communication and confusion.
Tell the Appropriate Person or Team
For a work or school account, report the invitation to the organization’s IT or security team. When the event impersonates someone you know, warn that person using a separate channel. Contact your financial institution promptly when payment information may have been exposed.
UC Berkeley’s Information Technology team similarly advises users not to click links or attachments or call numbers in unexpected calendar events and recommends reporting suspicious invitations before deleting them.
Read UC Berkeley’s calendar phishing guidance.
Click, Call, Scan, or Download? Use This Response Matrix
The safest response depends partly on the action the invitation wants you to take.
| The invitation asks you to… | Possible risk | Safer response |
|---|---|---|
| Click a link | Fake login, malware, data collection, or payment theft | Do not open it. Access the claimed service independently. |
| Scan a QR code | Hidden phishing or payment destination | Do not scan it. Verify the request through another channel. |
| Call a number | Callback fraud, impersonation, or remote-access pressure | Find the organization’s official number independently. |
| Open an attachment | Credential theft, unsafe scripts, or malicious software | Do not open it. Ask a verified organizer to resend it safely. |
| Join a meeting | Live impersonation, social engineering, or information gathering | Confirm the meeting and organizer before joining. |
| Approve a login | Account takeover | Deny it and review the account’s security activity immediately. |
| Send payment | Financial fraud | Check the transaction inside the official account and contact the institution directly. |
What to Do If You Already Interacted With the Invite
Do not panic, but act promptly. Choose the section that matches what happened.
You Only Viewed the Event
- Do not use any link, code, file, phone number, or reply address inside it.
- Report or remove the event.
- Review your calendar invitation settings.
- Watch for follow-up emails, texts, calls, or login prompts.
Viewing basic event details is different from opening embedded content, but no universal guarantee applies to every platform, file, vulnerability, or device.
You Clicked a Link but Entered Nothing
- Close the page.
- Do not download or install anything.
- Do not approve any unexpected notification or login request.
- Update your browser, operating system, and trusted security software.
- Run a reputable security scan when appropriate.
- Watch for unfamiliar account activity.
You Entered a Password
- Open the real service independently and change the password.
- Change the password anywhere else you reused it.
- Sign out of unfamiliar or active sessions.
- Enable or review multifactor authentication.
- Check recovery email addresses and phone numbers.
- Review forwarding rules, connected apps, and delegated account access.
You Shared a Verification Code or Approved an MFA Prompt
- Change the account password immediately.
- Revoke active sessions and unfamiliar devices.
- Review authentication methods, passkeys, security keys, and backup codes.
- Remove any recovery details you do not recognize.
- Contact workplace or school IT when the account is managed by an organization.
You Downloaded or Opened a File
- Do not open or run the file again.
- Use trusted device-security tools.
- Contact IT before making major changes to a managed work or school device.
- Preserve basic details needed for a report without forwarding the suspicious file to other people.
- Change exposed credentials from a device you trust when compromise is possible.
You Called the Number
- End the call.
- Do not install remote-access software.
- Remove unfamiliar remote-access tools if you installed any.
- Change passwords or codes you disclosed.
- Contact your bank or card issuer when financial information was shared.
- Have the device reviewed by trusted support when someone remotely accessed it.
You Paid or Shared Banking Information
- Contact the bank or card issuer using the official number on its website, app, statement, or the back of the card.
- Ask whether the transaction, card, or account should be frozen, disputed, monitored, or replaced.
- Review recent activity and enable transaction alerts.
- Preserve receipts, event details, messages, and call records for reporting.
- Follow the institution’s fraud-recovery instructions.
A supposed support agent does not need control of your computer merely to cancel a calendar event or investigate a charge. End the call and contact the real organization independently.
The FTC advises people who may have exposed account information to act quickly, change the affected password, use two-factor authentication, and follow appropriate identity-theft recovery steps.
Read the FTC’s official warning about fake invitations that steal login information.
How to Reduce Fake Events in Google Calendar
Settings cannot stop every phishing attempt, but they can reduce the number of unknown invitations that appear automatically.
- Open Google Calendar on a computer.
- Open Settings.
- Under General, select Event settings.
- Find Add invitations to my calendar.
- Review the available options and consider Only if the sender is known.
Google currently defines known senders as people in your contacts, people in your organization, or people you have previously interacted with. Google also warns that selecting this setting may reveal to a sender that they are not in your contacts. Updated settings generally affect new invitations rather than events already on the calendar.
Another available option is to add an event only after you respond to its email invitation. Choose the setting that best fits how you use your calendar and consult the current official instructions because labels and interfaces can change.
See Google’s official invitation-management options.
Review Connected Applications and Calendar Access
If unwanted events continue, review which applications can access your calendar. Remove access you no longer recognize or need. Also review subscribed calendars, shared calendars, browser extensions, and connected services.
Secure the Account Behind the Calendar
- Use a unique password.
- Enable multifactor authentication.
- Review active sessions and connected devices.
- Keep recovery details current.
- Remove unfamiliar third-party access.
- Keep devices and browsers updated.
What About Outlook and Apple Calendar?
The same core safety rules apply across calendar services:
- Do not interact with suspicious embedded content.
- Verify the organizer through a separate channel.
- Report junk or phishing through the associated email service where available.
- Remove the event using the platform’s current official instructions.
- Check for unknown subscribed or shared calendars.
- Review connected applications and account security.
Platform controls change over time, so use current official Microsoft or Apple support guidance rather than relying on old screenshots or menu paths.
Three Examples of Legitimate and Suspicious Invites
These fictional examples show how context matters more than a polished design or perfect grammar.
Example 1: A Project Meeting
More Credible
- The organizer is a coworker you recognize.
- The project was discussed earlier.
- The date and attendees make sense.
- The agenda is specific.
- The meeting link uses your normal company platform.
More Suspicious
- The organizer is an unknown external address.
- The title says “Mandatory Account Verification.”
- The link uses an unrelated domain.
- The event demands your email password.
- No known coworker can confirm it.
Example 2: A Subscription Renewal
More Credible
- You have an active subscription.
- The renewal date matches your records.
- The charge appears inside the official account.
- No unknown phone number is required.
More Suspicious
- You do not recognize the subscription.
- The event claims a very large charge.
- It promises an immediate refund by phone.
- The only contact method is the event’s number.
Example 3: A Family Invitation
More Credible
- The host confirms it using a saved contact.
- The date matches a known plan.
- The invitation does not request login credentials.
- The venue and guest list make sense.
More Suspicious
- A familiar name appears with an unfamiliar sender address.
- You must log in to see basic details.
- The page requests your email password or one-time code.
- The supposed host cannot confirm the invitation.
Two-Minute Calendar Safety Audit
Use this quick checklist to reduce avoidable risk:
- Unknown invitations are restricted where practical.
- Unfamiliar subscribed calendars have been removed.
- Third-party calendar access has been reviewed.
- The calendar account uses a unique password.
- Multifactor authentication is enabled.
- Recovery email and phone information are current.
- Active sessions and connected devices have been reviewed.
- Important services are opened through saved apps or bookmarks.
- Family members or coworkers know to verify unusual invitations separately.
- Suspicious events are reported before removal when reporting is available.
Final Rule: Verify Outside the Invitation
The most important rule is also the easiest to remember:
Do not trust its link, QR code, attachment, phone number, reply address, meeting room, or login prompt. Open the real service independently or contact the supposed organizer through a trusted channel.
When an unexpected event appears, use STOP–CHECK–VERIFY: stop before interacting, check the complete context, and verify somewhere outside the invitation.
Frequently Asked Questions
Can opening a calendar invite infect my device?
Viewing basic event details is different from clicking an embedded link, opening an attachment, or downloading a file. However, no action is universally risk-free across every device, application, file type, or security vulnerability. Avoid unnecessary interaction and keep your software updated.
Should I decline a suspicious calendar invitation?
Use the platform’s report-as-spam option when available, then remove the event according to current official guidance. Avoid accepting, declining, or replying merely to confront the sender or ask whether the event is genuine.
Why did a fake event appear automatically on my calendar?
Calendar settings may allow invitations from many senders to appear automatically. Events may also be created from email, connected applications, calendar subscriptions, or imported calendar files. Review invitation settings and connected access.
Can a calendar invite steal my password?
The event may direct you to a fake login page or manipulate you into sharing a password, one-time code, recovery code, or login approval. A normal invitation should not need your email password to reveal basic event information.
Is an invite safe because it appears in Google Calendar, Outlook, or Apple Calendar?
No. A legitimate calendar service can display content created by an untrustworthy organizer. Evaluate the sender, context, requested action, destination, and independent verification.
What should I do after clicking a calendar phishing link?
Close the page, avoid downloads, deny unexpected login prompts, update your device and browser, and monitor account activity. If you entered a password or code, change the password through the real service and revoke unfamiliar sessions.
How do I stop unknown people adding Google Calendar events?
Review the “Add invitations to my calendar” setting. Google currently offers options including adding invitations only from known senders or adding an event after you respond by email. These settings generally apply to new invitations.
Can a fake calendar invite contain only a phone number?
Yes. A callback scam may place a fake charge, renewal, or security alert in the event and instruct you to call a fraudulent support number. Never use that number to verify the claim; find the official contact independently.
Keep this guide available for the next unexpected calendar alert, and share it with a family member, coworker, student, freelancer, or small-business owner who may react quickly to an urgent invitation.
Last reviewed: July 24, 2026.
Disclaimer: This guide provides general digital-safety information and is not a substitute for professional cybersecurity, legal, or financial advice. Calendar features and reporting options can change. For a work or school account, follow your organization’s security procedures. Contact your financial institution promptly if payment or banking information may have been exposed.




