A new phishing technique is targeting Microsoft 365 users, slipping past traditional spam filters and landing directly in calendars. Instead of arriving as an email, these scams show up as events marked “Payment Failed” or “Account Suspended”. Because they appear in your diary, many people assume they’re genuine.
This clever tactic is already fooling users worldwide. Understanding how it works and what to look out for is the first step to protecting yourself and your business.
Attackers are sending fraudulent meeting invites that automatically appear in Microsoft 365 calendars. These often contain attachments such as .ics or .htm files that imitate official billing pages, designed to trick you into entering login credentials or payment details.
The real danger is that many calendar platforms auto-accept invites, meaning malicious events land on your schedule even if you never open the related email. In some cases, declining the invite can alert scammers that your account is active, encouraging more attacks.
CyberGuy documented how one user’s calendar filled up with billing alerts, despite no suspicious emails in their inbox. The events looked urgent and convincing, but clicking through would have led straight to a phishing page.
Microsoft has published clear advice on spotting and avoiding phishing attempts, including an official video and support article. Key warning signs include:
These red flags apply not just to emails but also to calendar events, making them particularly useful when assessing whether an invite is genuine or fraudulent.
Calendar events are processed differently from emails. Even if a phishing email is blocked by your spam filter, the event itself may still slip into your diary. Attackers take advantage of this by sending calendar-based lures that appear to blend in with genuine meetings or reminders.
By disguising their messages as account alerts or subscription notices, scammers increase the likelihood that users will act without questioning the source.
The good news is that you can reduce your risk with a few practical steps:
We identified this scam affecting one of our clients, our team immediately took action. We reviewed their Microsoft 365 calendar and security settings, removed suspicious invites, and educated staff on recognising fraudulent events. Our proactive approach prevented potential credential theft and ensured no disruption to their workflow.
Our team monitors Microsoft 365 environments for unusual activity, implements layered security measures, and trains staff to recognise threats. This approach ensures that emerging scams, like calendar-based phishing, are addressed before they can impact your business.
To learn more about how we help businesses defend against evolving phishing threats, visit our cyber-security services page.
The M365 calendar invite scam is a reminder that attackers are always innovating. While these events may look official, they’re nothing more than phishing attempts in disguise. By staying alert, knowing Microsoft’s real communication methods, and reporting anything suspicious, you can avoid becoming the next victim.
Need help protecting your business from phishing attacks? Our team provides proactive cyber security services tailored to Microsoft 365 environments. Get in touch today or fill out the form below to secure your systems and safeguard your staff.
"*" indicates required fields
June 23, 2026
Does your business have Web filtering set up? Web filtering is a security tool that...
April 1, 2026
What is Cyber Essentials and why does your business need it? Cyber Essentials is a...
February 16, 2026
Microsoft Is Adding AI Search to the Windows 11 Taskbar https://sjsystems.co.uk/wp-content/uploads/2026/01/Ask-Copilot-is-coming-to-your-Taskbar.mp4 The Windows search...
Say hello