Urgent.News

What's breaking now, across thousands of outlets.

Tech

Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May — and they work even if the email is sent to spam

ICS phishing has finally "hit the mainstream" as it keeps rising in popularity month over month.

Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May — and they work even if the email is sent to spam

Cybersecurity researchers Sublime have warned that calendar-based phishing attacks are surging by around 33,000% since May 2026. These attacks exploit calendar files (.ics) to trick users into downloading malicious remote management and monitoring (RMM) tools like ScreenConnect. Sublime's report indicates that this type of phishing has finally "hit the mainstream".

The attackers use free services like Gmail to send calendar invites to targets. Since both services are legitimate and free, the attacks bypass most email security filters and can be conducted at scale with minimal cost. The victim is exposed to the attack twice: once in their inbox and once in their calendar.

Inside the calendar invite, there is usually a link to download the malicious RMM tool. Once downloaded, the attackers can take over the compromised endpoint, deploying additional malware such as infostealers or ransomware, and stealing passwords, documents, and other valuable secrets.

The popularity of these attacks has been increasing rapidly. Between May and June, there was a 282% increase, and between June and July, a 338% increase. In just the first half of September, there was a 1,426% rise over the full month of August. According to Sublime, the increase from May to September is projected to be around 33,000%.

To defend against these attacks, users should be vigilant for suspicious calendar invites, suspicious senders, and other red flags such as financial urgency or pressure to act quickly.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

Tell Me Why cyber resilience is the need of the hour

After two decades at Apple, where security was engineered into products instead of being bolted on later, Nagesh Konduru saw a costly weakness across the wider industry: companies were investing heavily in cybersecurity without protecting their critical data or ensuring a quick recovery in case of a breach.

More from Friday 18 September →