We have seen Google Calendar phishing hitting businesses this week. Attackers send meeting invites containing credential harvesting links, fake voicemail notifications, or callback phone numbers, and those events land directly on your employees' calendars. Because the invites arrive from Google's own infrastructure, they pass email authentication checks and often bypass spam filters entirely.
The core defense is a Google Calendar setting called "Only if the sender is known," which prevents events from unknown senders from auto-adding to calendars. As of August 2026, Google Workspace administrators can enforce this setting organization-wide, so employees cannot override it and allow invitations from everyone.
Why Do Calendar Invites Bypass Email Suspicion?
Calendar invites evade user suspicion because they appear in a trusted context. According to Barracuda researchers in August 2026, attackers increasingly use calendar invites because they benefit from user trust, can evade traditional email detection, and persist long after the original email has disappeared. Unlike a suspicious email sitting in your inbox, a calendar event appears alongside legitimate meetings, complete with reminder notifications on your phone and desktop.
Google Calendar's default setting historically added all invitations automatically, meaning an attacker could send you a meeting invite and it would appear on your calendar without any action on your part. Sublime Security documented that even when email security solutions quarantine the message, the calendar entry often remains on the target's calendar. This creates a security gap that most organizations have not addressed. For a deeper look at the technical mechanism, see our earlier article on calendar injection attacks.
What Do These Phishing Calendar Invites Look Like?
According to IRONSCALES research from March 2026, attackers are sending Google Calendar invites with fake billing notifications (describing charges like "$399.77 CoreDefense Plus") and instructing recipients to call a toll-free number to dispute the charge. The links in these emails all resolve to legitimate calendar.google.com URLs, the .ics attachment has no executable payload, and DKIM passes because Google signed the message. The only indicator of compromise is a phone number.
We have seen fake meeting invites and fake voicemail notifications with credential-stealing links hitting our clients. Security researchers have documented additional lures:
- Billing or invoice alerts with callback numbers (such as the "$399.77 CoreDefense Plus" scam documented by IRONSCALES)
- Fake Zoom meeting invites with phishing links or RMM tool downloads (per KnowBe4 Threat Labs)
- HR policy and payroll notifications (per Barracuda)
The KnowBe4 Threat Labs report notes that calendar invite phishing has surged 49% over the past six months, with attackers embedding credential harvesting links, vishing phone numbers, and even remote monitoring and management (RMM) tool delivery in these invites.
How Do I Change Google Calendar to Only Accept Invites from Known Senders?
According to Google Calendar Help, individual users can change this setting by going to Settings, then Event settings, then Add invitations to my calendar, and selecting "Only if the sender is known." With this setting, events are automatically added only if the sender is in your contacts, part of your organization, or someone you previously interacted with. Unknown invitations arrive as email, and the event appears on your calendar only after you respond.
Google defines "known senders" as people in your contacts, part of your organization, or someone you previously interacted with.
If someone is not in one of these categories, their invitation will not automatically appear on your calendar. You will receive an email notification about the invite, and you can choose to respond or ignore it.
What Is the "I Know the Sender" Prompt in Google Calendar?
When you have the "Only if the sender is known" setting enabled and receive an invitation from someone who does not meet the known sender criteria, you will see a grey banner on the email notification that says "Unknown sender: not added to calendar yet." According to Calendly Help documentation and GoodTime Support, clicking "I know the sender" adds that email address to your calendar safe senders list, allowing all future invitations from that sender to appear automatically.
This is an important security consideration: clicking "I know the sender" on a phishing invite permanently adds that attacker to your allowed senders. If you accidentally click it, Google Calendar Help explains you can undo this by going to contacts.google.com, selecting "Other contacts" from the main menu, finding the contact, and deleting it.
Can Google Workspace Admins Enforce This Setting for Everyone?
Yes. On August 14, 2026, Google announced expanded admin controls for calendar invitation settings. Previously, administrators could only set the default value for new users. The new setting applies to new and existing users and allows admins to determine the least restrictive option available.
According to Google Workspace Admin Help, administrators can configure this in the Admin console by navigating to Apps, then Google Workspace, then Calendar, then Advanced settings. Admins can set both the default value and the "least restrictive level" that users can choose. By setting the least restrictive level to "Invitations from known senders," administrators prevent users from selecting "From everyone," effectively blocking unknown senders across the organization.
The setting affects future invitations only and does not remove events already on user calendars. Users may see a pop-up notification when the setting changes.
How Do I Report a Suspicious Calendar Event?
If a suspicious event appears on your calendar, Google Calendar Help provides specific steps: open the event, click the three-dot menu (More actions) at the top right, and select "Report as spam." When you report an event, it is removed from your calendar, and if it recurs, all events in the series are removed. Note that you can only report events sent from Google Calendar; events created by other providers or apps cannot be reported through this feature.
Critically, do not click Accept, Decline, or Maybe on a suspicious calendar invite. Multiple security sources, including answers on Microsoft Q&A and Malwarebytes, warn that responding to spam invites can confirm your email address is active and monitored by a real person. This makes your address more valuable on spam lists and typically results in more spam, not less.
What Should Users Do When They Receive an Unexpected Calendar Invite?
Train your employees to treat unexpected calendar invites with the same suspicion as unexpected emails. This is a gap in most security awareness training programs. The Lawrence Berkeley National Laboratory Cyber Alert provides clear guidance:
- Do not click any links in the event description or location field
- Do not call any phone numbers listed in the event
- Do not click Accept, Decline, or Maybe (this confirms your email is active)
- Use Google's "Report as spam" feature to remove the event
- If you are unsure whether an invite is legitimate, verify directly with the supposed sender through a separate channel
If someone in your organization does click "I know the sender" on a suspicious invite, have them remove the contact from contacts.google.com under "Other contacts" to prevent future automatic additions from that sender.
What Settings Should Google Workspace Administrators Configure?
For Google Workspace administrators, here is a checklist based on Google Workspace Admin Help documentation:
- Open the Admin console: Navigate to Apps, then Google Workspace, then Calendar, then Advanced settings
- Set the least restrictive level: Change this from "Invitations from everyone" to "Invitations from known senders" to prevent users from allowing all invitations
- Set the default value: Set the default to "Invitations from known senders" so new users start with protective settings
- Consider organizational units: You can apply different settings to different organizational units or groups if needed
- Communicate the change: Inform users that external invitations from new contacts will appear as emails rather than automatically on calendars, and they will need to respond to add them
The setting applies to new and existing user calendars for future invitations. Users who have already customized their settings will see a pop-up when the admin setting changes.
What About Microsoft 365 and Outlook?
Microsoft 365 and Outlook have different controls for calendar spam, though they are less straightforward than Google's approach. According to answers on Microsoft Q&A, users can disable automatic processing of meeting requests by going to Settings, then Mail, then Automatic processing, and turning off "Automatically process meeting requests and responses." This prevents calendar invites from being automatically added but requires manual acceptance of all invites, including legitimate ones.
For Exchange Online environments, administrators can run a PowerShell command (Set-CalendarProcessing with AutomateProcessing set to None) to disable automatic calendar processing across mailboxes. However, an answer on Microsoft Q&A notes this requires manual acceptance for all meetings and may affect third-party calendar integrations. Microsoft does not document a "known senders only" option for Outlook as of October 2026.
What Should Business Leaders Take from This?
Calendar phishing exploits a gap that most security awareness training does not cover. Your employees have been taught to be suspicious of emails, but they trust their calendars. Attackers know this, and they are increasingly using calendar invites to bypass the vigilance you have built. As we have noted with AI-powered phishing, attackers constantly find new ways to exploit trust.
The fix is administrative. If you use Google Workspace, your IT team or managed IT provider can enforce the "known senders only" setting across your organization in the Admin console. This single change prevents unknown senders from placing events directly on employee calendars. It does not block legitimate invites from new contacts; those arrive as emails and appear on calendars after the user responds.
If you are unsure whether your Google Workspace environment has these protections enabled, take our free security assessment to identify gaps in your current configuration.
One Question to Ask Your IT Provider
Ask your IT provider or internal IT team: "Have we configured Google Workspace to only add calendar invitations from known senders, and have we set that as the least restrictive level so users cannot override it?"
If the answer is no, or they are not sure, this is a straightforward configuration change that can be completed in the Admin console within minutes. If your organization uses Microsoft 365 instead, ask whether automatic meeting request processing has been evaluated and what controls are in place to prevent calendar-based phishing.
This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Details about Google Calendar phishing are based on public documentation from Google, security researchers, and vendor disclosures as of the date of publication and may evolve as platforms update their controls. Organizations should consult qualified cybersecurity professionals before making operational changes based on this article.