Microsoft 365 Calendar Phishing: Don’t Let Invites Fool You

Show Links

In this episode, we explore a rising phishing tactic targeting Microsoft 365 and Outlook users: fraudulent calendar invites that bypass email filters and land directly in your schedule. We’ll uncover how they work, why they’re dangerous—even without links—and what businesses can do to stay protected.

You’ll learn:

  • Calendar phishing using fake billing alerts (“Payment Failed,” “Account Suspended”)

  • How auto‑accept invite settings and Outlook behaviors enable these scams

  • Why responding—even to delete—can confirm account activity to attackers

  • Safe handling strategies: ignore, report, verify via official channels

  • Tools and awareness measures to boost business resilience

Episode Transcript

Every day, legitimate calendar invites pop up—meetings, reminders, appointments—but what if one of those invites wasn’t what it seemed? Imagine opening your calendar to find an alarming entry: “Payment Failed” or “Account Suspended,” seemingly from Microsoft 365. You didn’t accept it—but there it is. It automatically appeared, pushing you to act fast. This is a growing phishing tactic that slips past inbox filters, exploits auto‑accept calendar settings, and uses your trust in familiar tools against you. We’ll unpack how it works, why it matters to your business, and what you can do to stay safe. Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.
Cybercriminals are using seemingly genuine Microsoft 365 calendar invites—claiming things like failed payments or license renewals—to slip phishing attempts into users’ calendars without requiring clicks or interaction. These can include fake billing alerts or malicious attachments, appearing automatically via .ics files
How It Happened & Why It Matters
These scams exploit default behaviors in Outlook and Microsoft 365: invites may be auto‑added to your calendar even if you haven’t accepted them, bypassing email filters like Microsoft Defender Common triggers: urgent titles (“Account Suspended,” “Payment Failed”) and familiar branding crowd your calendar with urgency, prompting quick—but risky—decisions. If you try to delete or decline the invite, some versions of Outlook send a response, confirming your account is active and making you a more valuable target. Many users don’t realize Microsoft won’t send billing notices through calendar invites—any unsolicited billing event should be treated as phishing
Take Action
Avoid interacting with suspicious calendar events—do not click links, open attachments, or even decline them. On the newer Outlook clients, where “delete without response” is unavailable, your safest approach often is to leave the event untouched and, if possible, use the “Ignore” function from your inbox to handle the associated email without notifying the sender. In Classic Outlook, you may delete the event using “Do not send a response” to avoid signaling you’re active. Always verify any billing claims directly through official channels like the Microsoft 365 Admin Center or your MSP—not via calendar events. Encourage users to report phishing invites and consider advanced tools that monitor calendar and collaboration platforms—not just email—for suspicious content.
That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.
Until next time—stay safe, stay informed, and don’t be a sitting duck!
This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.