
Episode #14
CalPhishing: When Calendar Invites Become the Lure
Calendar invites have become part of the trusted infrastructure of daily life, and attackers are taking advantage. In this episode, the team examines the resurgence of CalPhishing, an attack technique that uses legitimate calendar workflows, HTML content, attachments, spoofed organizers, and trusted platforms to evade defenses and compromise accounts. Fortra security engineer and FIRE team member Daud Jawad joins hosts Josh Davies and Tyler Reguly to break down the calendar phishing techniques reaching users today. They explore why these attacks can bypass traditional email security controls, how trusted workflows lower users' defenses, and why organizations may need to reconsider how they process and test calendar invitations. Key takeaways How attackers use calendar invite bodies, HTML attachments, spoofed organizers, and legitimate vendor infrastructure to deliver phishing lures Why CalPhishing can evade email authentication, filtering, browser protections, and other established security controls How calendar-based attacks can target credentials, session tokens, OAuth consent, device codes, and trusted internal workflows How organizations can reduce exposure through calendar processing controls, user education, cross-channel verification, and calendar-based phishing simulations Read Daud's related blog on Fortra.com Don't let the next threat sneak onto your calendar. Subscribe to The Art of Security podcast.

