Fraudsters have found a new way to steal one-time passcodes (OTPs): bogus calendar invitations that look urgent and official. These invites can slip into your calendar, trigger pop-up reminders, and push you to call a number, click a link, or reply with a code. If you respond, the attacker can bypass your account security and take over email, banking, social, or cloud accounts. This guide explains how these calendar-invite spoofs work and gives you concrete steps to block, detect, and recover from them.
What Is a Calendar-Invite Spoof?
A calendar-invite spoof is a phishing attempt delivered as a meeting request or event invite. Attackers exploit how calendars display invitations by default—often showing the event on your calendar or sending alerts before you accept. The invite usually includes:
- Urgent pretext: “Security Alert,” “Payment Review,” or “Delivery Exception” with a meeting title that implies immediate action.
- Deceptive location/description: A phone number to call, a link to “secure your account,” or instructions to text or email back a code.
- Timing tricks: Events set for “now” or the next 10–30 minutes to create panic.
- Recurring reminders: Repeats that generate repeated notifications until you act.
The goal is to push you into revealing a one-time code sent to your phone or app. Once the scammer has the code, they can log in as you.
How Attackers Steal Your One-Time Codes with Invites
Here’s a common playbook attackers use:
- They send a calendar invite from a throwaway email address or compromised account. The invite looks like it’s from a bank, email provider, or delivery service.
- They trigger the real OTP by starting a login to your account using your email or phone number—data often found in breaches or data-broker profiles.
- Your device receives a genuine OTP by SMS, email, or authenticator app.
- The invite (or follow-up call/text) instructs you to “verify” by reading back the code or entering it on a fake site.
- They use the code immediately to complete the login and take over your account.
Variations include voice calls (vishing), texts (smishing), and “MFA fatigue,” where repeated prompts or invites wear you down until you approve one.
Red Flags That an Invite Is a Scam
- Asking for a code: Any invite, message, or caller that requests your OTP is malicious. Real companies never ask for it.
- Urgent countdowns: “Your account will be locked in 10 minutes” is classic pressure.
- Free email domains or odd addresses: Slight misspellings, extra characters, or unrelated senders.
- Clickable phone numbers or shortened links: “Tap to secure your account” in the event location or description.
- Time-zone or formatting inconsistencies: Strange locale settings, grammar errors, or mixed branding.
- Invites you never initiated: Banks and government agencies almost never use calendar invites for security issues.
Immediate Steps If You Receive a Suspicious Calendar Invite
- Do not click links or call numbers in the invite or reminders.
- Do not reply with any code to email, text, or phone callers.
- Decline the invite or delete the event. If your calendar shows it without acceptance, remove it.
- Report the sender as spam/phishing in your email or calendar platform.
- Check recent activity in your key accounts (email, bank, cloud storage, social). If you see unknown logins, change passwords and revoke sessions.
How to Stop Calendar-Invite Spam at the Source
Google Calendar
- Open Google Calendar (web) > Settings (gear icon) > Event settings.
- Set “Add invitations to my calendar” to Only if the sender is known or When I respond to the invitation.
- Under “View options,” uncheck “Show declined events.”
- In Gmail Settings > General > Smart features and personalization, consider turning off automatic features that may create events from emails.
- Use Gmail filters to send suspicious invites to Spam or Trash.
Microsoft Outlook/Exchange
- In Outlook (web) > Settings > Calendar > Events from email: turn off automatic event creation you don’t need.
- Enable junk email filtering and block the sender’s domain.
- Set meeting request processing to require manual acceptance before adding to your calendar.
Apple Calendar (iCloud)
- In iCloud Calendar (web), click the gear > Preferences > Advanced > Invitations: choose Email to your address instead of in-app notifications to filter easier.
- Right-click the invite and choose Report Junk or move it to a new “Junk” calendar, then delete that calendar to avoid sending acceptance notifications.
Harden Your Accounts Against OTP Theft
- Use phishing-resistant MFA where available, such as hardware security keys (FIDO2/WebAuthn) or passkeys. These codes are bound to the site and can’t be read back to a caller.
- Avoid SMS codes when possible. Prefer an authenticator app or hardware key. If SMS is your only option, treat every code as secret and one-time.
- Turn on login alerts for new devices, locations, or password changes.
- Review and prune recovery options (backup emails, phone numbers, trusted devices) so attackers can’t reset your password easily.
- Unique, strong passwords with a password manager. Never reuse email or banking passwords anywhere else.
- Lock down email first. Your email is the key to everything. Enable strong MFA and review recent sign-ins.
Block the Multi-Channel Trap
Calendar-invite scams rarely stand alone. Attackers chain channels to build trust.
- Smishing: A text message may arrive just before or after the invite to reinforce urgency. Do not tap links.
- Vishing: A “support agent” may call you while you see the invite reminder. Hang up. Call the company back using the number on its official website or card.
- Email: Matching emails can spoof sender names. Check the full address and message headers if unsure.
- Social DMs: Never share codes in chats regardless of who asks.
What to Do If You Shared a Code
- Immediately change the password on the affected account from a known-safe device.
- Revoke active sessions and sign out of all devices in account security settings.
- Rotate MFA: remove old authenticators, add a new authenticator app or hardware key, and update backup codes.
- Check linked accounts (email forwarding rules, recovery emails/phones, third-party app access) for tampering.
- Monitor financial accounts and consider placing a fraud alert or security freeze with the credit bureaus if you suspect broader compromise.
- Report the incident to the platform’s security team and, if money or sensitive data was stolen, to your bank and local authorities.
Reduce Your Exposure That Fuels These Attacks
Attackers get your contact info and partial credentials from data breaches, paste sites, and data brokers. Reducing your exposure makes you a harder target.
- Opt out of data brokers that list your name, phone, email, and addresses. Remove exposed records to cut down targeted smishing and vishing.
- Use email aliases for banks, shopping, and newsletters to spot where leaks start and to limit cross-targeting.
- Change passwords after breaches and watch for breach notices affecting your email or phone number.
- Limit public profiles and adjust privacy settings on social networks to hide contact details.
Device and App Settings That Help
- Silence unknown callers on your phone. Let suspicious numbers go to voicemail.
- Limit lock-screen previews for messages, calendar, and email so codes don’t display on the screen.
- Use spam filters and caller ID protection provided by your carrier or device.
- Keep OS and apps updated to patch phishing-related exploits and improve fraud detection.
- Review app permissions for calendar, contacts, and SMS to reduce exposure to malicious apps.
How to Verify Urgent Account Notices Safely
- Use a second channel you control: If the invite claims to be from your bank, manually type the bank’s URL or use the official app. Never use links or numbers in the invite.
- Check account notifications: Most services show security alerts in the app or website under Security or Notifications.
- Call the published number: Use the number on the back of your card or the provider’s website, not the one in the invite.
- Look for internal consistency: Real notices reference recent activity you recognize and don’t ask for codes.
When Credit and Identity Monitoring Helps
Calendar-invite spoofs often target your primary email and financial accounts. If attackers gain access, they can open new accounts, redirect funds, or change recovery info. Ongoing monitoring can help you catch suspicious changes faster and respond quickly. If you want a consolidated view of credit changes, identity-related alerts, and tools to manage disputes, consider a dedicated monitoring service such as SmartCredit for privacy, credit monitoring, and identity protection.
Frequently Asked Questions
Can a scammer add events to my calendar without my permission?
Depending on your settings, yes. Some platforms display tentative events or auto-add events from email. Adjust your calendar settings to require manual acceptance and disable automatic event creation where possible.
Is reading back a one-time code to a support rep ever legitimate?
No. Real support agents and companies will never ask for your one-time code. Codes are for you and your device only.
What if the invite comes from a colleague’s or friend’s account?
Their account may be compromised. Verify out of band—call or message them using a known number—and avoid clicking links in the invite.
Are authenticator apps safe?
Yes, when used correctly. They’re stronger than SMS, but you must still protect the code. Phishing-resistant options like hardware security keys or passkeys provide even better protection.
I declined the invite but still see reminders. What now?
Change settings to hide declined events, delete the event entirely, and report the sender. In some apps, creating a temporary “Junk” calendar and deleting it removes lingering spam without sending acceptance notices.
A Quick, Repeatable Response Plan
- See it: Unexpected invite with urgency.
- Stop: Don’t tap links or call numbers in the invite.
- Verify: Use the official website or app—not the invite.
- Secure: Change passwords, check sessions, and tighten MFA.
- Reduce: Limit data exposure and lock down calendar settings.
- Monitor: Watch accounts and credit for signs of misuse.
Conclusion
Calendar-invite spoofs are designed to blend into your daily routine and create urgency at the exact moment a real security code arrives. By changing calendar settings to block auto-added events, refusing to share one-time codes with anyone, and upgrading to phishing-resistant authentication, you can shut down this attack before it starts. Combine those steps with good password hygiene, reduced public exposure, and active monitoring so you can spot and stop misuse quickly if it ever occurs.
Good to Know
If a message or calendar invite pressures you to read back a code “to verify you,” it is almost certainly a scam; legitimate companies will never ask you to share your one-time code with a human.