The Meeting Invite That Isn’t What It Seems
You’ve trained yourself well. You hover over links before clicking. You squint at email addresses looking for the extra letter that gives a scammer away. You’ve even started asking “is this really from the bank?” out loud, to nobody in particular, in the kitchen. Good work. Truly.
But here’s the catch: while you’ve been busy watching your inbox like a hawk, scammers have quietly wandered round the back and let themselves in through your calendar.
Yes, your calendar. The place where you keep track of dentist appointments, the 2pm call with a supplier, and that recurring “team catch-up” nobody has cancelled since 2019. It turns out this quiet, trusted little app is now one of the more appealing doors for criminals to try.
Why your calendar makes an easy target
Think about the kind of invites that land in your diary without a second thought. A reminder to complete your annual policy sign-off. A prompt to review the staff handbook. A “benefits enrolment window is now open” notice from HR. None of these raise an eyebrow, because they’re the everyday admin of running or working in a business.
That’s exactly why they’re useful to a scammer. An invite that looks like it’s about payroll or HR doesn’t stand out the way a dodgy “claim your prize” email would. It blends straight into the background noise of a normal working week.
There’s also a quieter, more structural reason calendar invites are so handy for attackers: your calendar app usually adds the event automatically, often before you’ve even opened the email it came from. And crucially, if you later delete or your IT provider quarantines that email, the calendar entry frequently stays exactly where it is. The dodgy link is still sitting there in your diary, patiently waiting for a quiet Tuesday when you’re clicking through your day without thinking too hard.
Add in the fact that a good chunk of us glance at calendar notifications on our phones, often away from the more robust protections built into a work laptop, and you can see why this has become an attractive route in.
The bit your security tools don’t see
Most email security is designed to check the message itself: the subject line, the body text, any attachments. A calendar file, however, often gets treated as, well, just a calendar file, rather than something worth a closer look.
The trouble is that a calendar invite can carry a surprising amount of hidden content: descriptions, locations, organiser details, attachments, links and even QR codes, all tucked into fields that were really only designed to say “meeting, Tuesday, 10am.” Once your calendar app displays that content, it can look every bit as convincing as a real internal announcement, complete with familiar logos and formatting.
If someone follows that link or scans that QR code and types in their username, password and MFA code on the page that appears, the damage is already done. The attacker isn’t guessing a password; they’re being handed the working session on a plate.
None of the individual tricks here are new, incidentally. QR codes hiding a destination, brand impersonation, and fake “log in again” pages have all been around the block before, usually via email. What’s changed is where they’re hiding: not in the inbox you’re already wary of, but in an area that has had far less scrutiny.
What this actually means for a small business
You don’t need an IT department the size of a small country to be sensible about this. It mostly comes down to treating calendar invites with the same healthy scepticism you (hopefully) already apply to email:
- Be wary of unexpected HR, payroll or “urgent action needed” invites, especially ones asking you to scan a QR code or follow a link to “verify” something.
- Don’t scan QR codes inside calendar invites on autopilot. If in doubt, go directly to the source (your actual HR system, your actual supplier portal) rather than the link provided.
- If something looks off, don’t just delete the email. The calendar entry can quite happily live on even after the original email is long gone, so it’s worth removing the event itself too, and letting us know so we can check nothing else has slipped through.
- Keep an eye on anything unusual after the fact — an unexpected MFA prompt, a login notification from a device you don’t recognise, or a sign-in at a strange hour. These are all worth flagging to us straight away rather than assuming it’s nothing.
Where we come in
This is exactly the kind of thing that’s much easier to stay ahead of with the right support in place, rather than trying to keep track of every new trick attackers dream up on your own. Behind the scenes, this is what proper protection looks like: mail and calendar filtering that doesn’t stop at the inbox door, sensible access controls, and a plan for acting quickly if something has slipped through, rather than hoping it hasn’t.
If you’d like us to take a look at how invites and calendar data are currently handled across your business, or you just want a second opinion on something that’s landed in someone’s diary looking a bit too “corporate HR” to be true, get in touch. It’s a much better use of five minutes than finding out the hard way.
VCI Systems
☎ 0118 976 7111
✉ hello@vcisystems.co.uk
🌐 www.vcisystems.co.uk
Right from the start.
