AI News Feed
Market watch
Cybersecurity

Barracuda warns of phishing threats hiding in calendar invites

Barracuda analyst warns phishing attacks hide in calendar invites and .ics files, evading traditional email security.

Traditional email security systems scan message bodies, subject lines and attachments, but .ics files often slip through as calendar objects and do not receive the same level of inspection, Poomalai said. “It is significant, and it’s something many organisations haven't accounted for,” she added.

The problem is that .ics files contain much more than a date and time. They can include event descriptions, organiser details, locations, attachments, URLs and custom metadata fields, any of which can be used to hide phishing content. Once the calendar app renders that content, recipients see corporate branding, instructions or a QR code that looks legitimate. If a victim enters credentials and completes multi-factor authentication, attackers can intercept the username, password and session data, giving them full access to the account.

Poomalai explained that calendar phishing is not a new technique but an evolution of existing social-engineering and evasion methods. QR codes, brand impersonation and adversary-in-the-middle attacks are familiar, but wrapping them inside a calendar invite places them where security tools pay less attention.

Organisations need to redefine what constitutes malicious content, she said. Any workflow that can display or trigger content on a user's behalf is a potential attack surface. Calendar files should receive the same scrutiny as traditional attachments: parsing metadata fields, analysing embedded links or attachments, inspecting HTML-rendered content, and decoding QR codes.

However, .ics files were built for interoperability, allowing rich content to move across Outlook, Google Calendar and Apple Calendar, which makes consistent inspection at scale difficult. Also, a calendar entry can sit in a user's diary for days or weeks before a link becomes relevant, so security checks must hold up over time, not just at the point of delivery.