AI News Feed
Market watch
Cybersecurity

ICS calendar phishing projected to jump about 33,000% from May to September

Sublime says .ics calendar phishing rose about 33,000% from May to September 2026.

Sublime described a simple and inexpensive method. An attacker uses a free service such as Gmail to send a calendar invite to a target. Because the service and the invite are legitimate, the messages bypass most email security filters and can be sent at scale at close to zero cost, the researchers said. The victim is exposed twice: once in the inbox and once in the calendar. A strange meeting or event may therefore remain visible even if the original email is sent to spam.

Inside the calendar invite is usually a link to download a maliciously configured remote monitoring and management tool, such as ScreenConnect, according to the report. Attackers can use the tool to take over the compromised endpoint, deploy second-stage malware such as infostealers or ransomware, and collect passwords, documents and other valuable secrets.

The growth figures cited by Sublime show a sharp acceleration. ICS phishing rose 282% from May to June and 338% from June to July. It increased 1,216% from July to August. In the first half of September alone, volume was 1,426% higher than the full month of August. Sublime projected that the full month of September would be 2,852% above August, producing a projected May-to-September increase of about 33,000%.

The researchers said ICS phishing began gaining popularity about a year ago but has picked up speed more recently. They described the August and September jumps as indicators that the attack type has finally hit the mainstream. TechRadar reported the findings from Sublime.

To defend against the attacks, Sublime recommended common-sense checks. Users should scrutinize suspicious invites, verify senders and treat ICS attachments with caution. The report also pointed to familiar warning signs, including suspicious calls to action, suspicious senders and financial urgency.

Editor's Summary

Calendar-based phishing that uses .ics invites has grown sharply in 2026, with Sublime projecting a roughly 33,000% increase from May to September. The technique exploits legitimate calendar services to bypass filters and often delivers RMM tools such as ScreenConnect, which can lead to ransomware or data theft. Defenses center on verifying senders and handling unexpected calendar invites and ICS attachments with caution.