A new phishing tactic is tricking victims by sending fake calendar reminders for appointments or renewals, prompting them to click on malicious links. The scam mimics legitimate services like Google, Microsoft, or PayPal, luring users into entering their login credentials on fraudulent websites. Once credentials are stolen, cybercriminals exploit them for identity theft, unauthorized access to accounts, or further deception. Security experts warn that even seemingly familiar calendar entries could be part of this growing digital scam.


Appointment or renewal reminder appears in victims’ calendar to lure them into logging in to fake Google, Microsoft or PayPal pageYou’re preparing for the week ahead and take a look at your Google calendar. There’s an entry for a meeting that you must have completely forgotten. The note that pops up when you click on it says you’ll be reviewing a project and includes a link to more details. Confused, you follow it to find out more; the website you land on asks for logon details, and you provide them.Unfortunately, this was not a failure of your memory but a calendar phishing scam. You have handed your name and password to fraudsters who will sell it on in a batch with other people’s details, use it to break into your work email, or to persuade you that they are contacting you from your bank, or another institution. Continue reading...