Phishing scams are constantly emerging in new variations, but the latest method to come to light is particularly worrisome. This time, scammers are taking advantage of Apple's iCloud Calendar to send out deceptive emailsthat look perfectly legitimate and manage to get past spam filters. The reason? The messages are sent directly from Apple's servers, which means they carry all the necessary digital "certificates" that make them look authentic.

The fraud step by step
The campaign that was uncovered began with a phishing emailinforming the recipient that a $599 charge had been made to their PayPal account. The message was accompanied by a support phone numberthat they could supposedly call to cancel or dispute the transaction.
See also: Creating a spam or malicious email detection model
Here's the danger: when the victim calls, the scammers convince them that their account has been compromised and instruct them to install remote access software on their computer. This way, they gain control of the device and have the ability to either steal banking informationor install malware to steal data.
The iCloud Calendar trick
While the “fake charge” method is not new, the original element is that the scammers used the iCloud Calendar invitation system to send the messages. In practice, the scam information was placed in the “Notes” field of a calendar event, which was then sent as an invitation.
Thus, the email arrived at the recipient via the official email.apple.com, carrying a valid DKIM signature and successfully passing SPF and DMARC checks. This means that the message is recognized by most email systems as trustworthy and secure, dramatically increasing the chances of it reaching the user's inbox without being marked as spam.

Leveraging Microsoft 365
Another element that makes the scam more complex is the use of Microsoft 365. The invitation was sent to an account that appeared to be a mailing list, which then forwarded the message to multiple recipients. Thanks to re-subscription mechanisms (SRS), the email would pass authentication checks again, maintaining the appearance of legitimacy.
See also: Hackers exploit Google Calendar APIs via MeetC2
Why is it so dangerous?
While the content of the phishing scam is not much different from other well-known scams, the infrastructure Apple's makes this technique particularly dangerous. To the end user, the email appears to come directly from Apple, a company considered one of the most trusted in the technology world. This is enough to mislead even the most suspicious users.
The broader issue of reliability
The incident highlights a more serious problem: the reliability of email authentication standards is not absolute. SPF, DKIM, and DMARC were designed to prevent sender spoofing, but in this case the security tools work normally — it's just that the sender himself is "legitimate," since the message actually came from Apple's servers.
This raises critical questions: how can tech companies prevent abuse of their own systems? And what additional measures can be taken to protect users from such deceptive practices?

What users can do
Experts advise that any unsolicited or suspicious calendar invitation should be treated with suspicion. If you receive a message claiming to be about a charge or payment, never call the number listed or download any software that the supposed support representatives ask you to download.
On the contrary:
- Check your account (e.g. PayPal) directly through the official app.
- Delete the invitation from the calendar.
- Report the incident to Apple or your email provider.
See also: GhostRedirector hackers compromise Windows Servers with malicious IIS Module
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This new iCloud Calendar phishing technique shows how creative fraudsters are getting to bypass security filters. By using infrastructure from giants like Apple and Microsoft, they are able to give legitimacy to suspicious messages, putting millions of users at risk.
The phenomenon doesn't just affect Apple; it affects the entire digital security landscape, as attacks on the chain of trust of major platforms are becoming more and more common. And as users continue to blindly trust the logo of a major brand, fraudsters will find ways to exploit it.
Source: www.bleepingcomputer.com
