
Nowadays, cybercriminals have developed many methods and discovered various ways to deceive their victims. And recently, as Kaspersky reported, malicious actors have started using Google Calendar notifications to spread phishing links.
The attack exploits a setting in Google Calendar that automatically pulls events and invitations from the user's Gmail account
The user is then presented with a notification, urging them to click on a link to complete a survey or claim a cash prize. If the victim clicks on the link, they are taken to a fake website with a simple questionnaire. There, they will be asked to provide some personal information including their name, address, phone number and bank account details in order to be eligible to take part in the competition.
Once hackers obtain the information they need, they usually use it to steal money from their victims' accounts or to commit some other fraud.
This particular scam is particularly effective, as most users consider Google Calendar to be a trustworthy application and usually do not question the authenticity of the links presented there.
![]()
There are, of course, certain measures you can take to avoid falling victim to such a scam:
- Open Google Calendar Settings in a browser and go to Event Settings > Automatically add invitations . Select the option " No", only view invitations I have responded to.
- Under View Options , make sure “Show rejected events” is not selected .
- Do not open messages from unknown senders.
- Never accept invitations from someone you don't know.
- Don't click on links in messages you weren't expecting.
