A new report from cybersecurity firm Sublime indicates a sharp rise in malware attacks delivered through fake calendar invitations. The firm observed a 282% increase in June, 338% in July, and a substantial 1,216% surge in August compared to the previous month. Projections for September suggest an even greater increase of 2,852% over August's figures.
These attacks leverage a technique called ICS phishing, utilizing the iCalendar standard. ICS files, containing meeting details, are automatically added to users' calendars in many email programs such as Microsoft Outlook, Gmail, and Apple Mail, often before the user can accept or decline the invite. This bypasses typical email inbox security filters, as the event is added directly to the calendar.
The scams are effective because they target both the inbox and calendar, with calendar security often less robust than email security. Many attacks originate from trusted platforms like Google's and Microsoft's infrastructure, further aiding in evading detection. Scammers also utilize free services, incurring no cost for their operations. John Gallagher of Viakoo notes that the success of these attacks stems from the 'implied trust' in both the systems involved and the invitation itself, as calendar invites are generally less scrutinized than email phishing attempts.
Users are advised not to respond to suspicious calendar invites or their associated emails. Instead, they should report and delete them. The automatic addition of these events to calendars means users may be unaware of their presence until they access their calendar.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity firm Sublime reports a significant increase in calendar-based malware attacks, with a 1,216% rise in August and a projected 2,852% increase for September. These attacks exploit default settings in email programs like Outlook and Gmail, which automatically add malicious invites to users' calendars, bypassing typical email security measures.