'It is significant, and it’s something many organisations haven't accounted for': The phishing threats hiding in your calendar invites
Barracuda explains why attackers are moving beyond the inbox and into calendar apps, and what security teams need to change to keep up.
Phishing attacks have evolved beyond malicious emails to target trusted business tools like calendars and meeting invites. This shift is due to calendars being an integral part of daily business administration, often used for beyond just meeting scheduling. Attackers can now blend in more easily by referencing HR updates, payroll actions, or compliance training reminders within calendar invites.
One major issue is the visibility gap between email security systems and calendar applications. While email security focuses on scanning message bodies, subjects, and attachments, calendar files can bypass this inspection as they often appear as calendar objects rather than email content. These .ics files can contain hidden event descriptions, organiser details, locations, attachments, URLs, and custom metadata fields that attackers can exploit to hide phishing content.
When a user views the calendar entry, it appears legitimate with corporate branding, instructions, or even QR codes. If the user enters their credentials and completes multi-factor authentication (MFA), attackers can intercept username, password, and session data, granting full account access. QR codes embedded in .ics files face the same evasion techniques as those in PDFs or email bodies because they avoid text-based detection and target security tools that pay less attention to these areas.
Organisations must redefine what constitutes "malicious content" to include calendar invites and their embedded content. Instead of focusing solely on email bodies and file attachments, security teams should consider any workflow that can display or trigger content on a user's behalf. Calendar files need thorough scrutiny, including parsing metadata fields, analysing embedded links or attachments, inspecting HTML-rendered content, and decoding any QR codes to check their destinations. This must be done consistently at scale to effectively combat these evolving threats.
In the event of a successful calendar phishing attack, deleting or quarantining the original email isn't sufficient. The malicious calendar entry may still remain active in the user's diary, posing a persistent threat. Incident response should involve removing both the delivery message and the associated calendar entry from every affected mailbox.
Additionally, monitoring identity activity around the time of the event and investigating signs of compromised credentials or session tokens is crucial. Containment measures must extend beyond cleaning up the calendar to address the full extent of the breach. To reduce exposure to calendar-based phishing, security and business teams should prioritize implementing robust calendar file inspection, monitoring identity activity, and enhancing incident response processes to address the unique challenges posed by these evolving threats.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.