Your receptionist just received a calendar invite for "Q3 Benefits Enrolment Review" from HR. The meeting details include a link to review updated policies. She clicks it without thinking twice. It seems like a standard calendar invite, but the reality is more dangerous.
Wrong. That link leads to a fake login page, and now an attacker has her Microsoft 365 credentials. This scenario is playing out in Australian businesses every day, and simulated phishing attacks are one of the most effective ways to prepare your team before the real thing hits.
Why Attackers Love Calendar Invites
Email security has improved over the years. Spam filters catch obvious scams, and most staff know to be suspicious of emails from Nigerian princes. So attackers adapted. They started hiding their tricks inside calendar files (those .ics attachments that automatically create events in Outlook or Google Calendar).
Calendar invites work effectively for scammers because:
- Many calendar apps add events automatically without asking
- The invite stays in your calendar even if you delete the original email
- People check calendars on their phones, where security controls are weaker
- A meeting invite feels routine, not suspicious
The .ics file format works across every major platform. Outlook, Google Calendar, Apple Calendar. They all accept these files, and they can contain much more than just meeting times. Event descriptions can include images, formatted text, links, and even QR codes.
What a Calendar Phishing Attack Looks Like
The email itself is often simple. A subject line like "Updated: Staff Training Session" with nothing but an .ics attachment. Your employee opens it, and their calendar app displays a professional-looking event with your company logo (pulled from your website), instructions to "review the updated handbook," and a link.
The link might point to a convincing replica of your Microsoft 365 login page. Or it might contain a QR code instead of a clickable link. QR codes are particularly sneaky because video call invitations and calendar events commonly include them, and your staff can't see where the code leads before scanning it.
Common themes attackers use in these fake calendar events include:
- HR policy updates or handbook revisions
- Payroll changes requiring verification
- Compliance training deadlines
- Benefits enrolment reminders
- IT system maintenance notifications
Each of these sounds boring and routine. That's the point. Nobody gets suspicious about a compliance reminder.
Why Traditional Email Security Misses This
Most email security tools focus on scanning the email body and common attachment types like PDFs or Word documents. Calendar files slip through because they're designed for scheduling, not document delivery. Security tools might not inspect the content inside the .ics file as thoroughly as they would an email.
The location field in a calendar event can contain a URL. The description can contain formatted HTML with embedded images and links. Custom metadata fields can hold additional content. All of this gets rendered by the calendar application, not the email client, so email-focused security has limited visibility.
Mobile devices make the problem worse. Your staff might receive the invite on their work email but open the calendar on their personal phone, completely outside your monitored environment.
How Simulated Phishing Attacks Build Real Defences
The Australian Cyber Security Centre (ACSC) recommends regular training to mitigate business email compromise, as the best defence against calendar phishing is a workforce that recognises the warning signs before clicking. Research on email security testing shows that staff who experience simulated attacks become significantly better at spotting real ones.
Anti-phishing software that runs realistic simulations teaches your team through experience rather than boring slideshows. When someone clicks a link in a simulated attack, they get immediate feedback explaining what they missed. That lesson sticks far better than a once-yearly training video.
The research from Monash University on phishing awareness confirms this approach works. Simulated attacks followed by targeted training reduce click rates over time. Staff learn to pause and think before acting on unexpected requests, whether they arrive by email, calendar invite, or any other channel.
Warning Signs Your Team Should Know
Train your staff to watch for these red flags in calendar invites:
- The organiser's email address doesn't match your company domain
- The invite arrived with minimal or no email body text
- The event contains a QR code (especially for something that could be a regular link)
- Links in the event description don't match the organisation they claim to be from
- The event creates urgency around reviewing documents or updating information
- The formatting looks slightly off compared to genuine internal communications
None of these signs alone confirms a phishing attempt. But several together should trigger caution. When in doubt, contact the supposed organiser through a separate channel (not by replying to the invite) to verify.
What You Can Do Right Now
Start by adjusting calendar settings where possible. In Microsoft 365 and Google Workspace, you can configure calendars to not automatically add events from external senders. This forces staff to actively accept invites rather than having them appear silently.
Talk to your team about this threat. A five-minute conversation explaining that calendar invites can be exploited will put the idea in their heads. Next time they receive an unexpected invite with a link, they might pause instead of clicking.
Most importantly, test your team's readiness. The gap between what people think they would do and what they actually do under pressure is often wide. Simulated phishing attacks reveal that gap without the consequences of a real breach.
Making Email Security Testing Simple
Running simulated phishing attacks used to require technical expertise or expensive consultants. Modern AI-powered platforms handle the complexity for you. Add your employees, choose how often to test, and the system generates realistic scenarios automatically.
When someone falls for a simulated attack, they receive immediate training explaining what they missed. Over time, the platform adjusts difficulty based on each person's performance. Staff who struggle get more practice. Those who consistently spot the fakes face harder challenges.
You get clear reports showing who's improving and who needs extra attention. No technical skills required. No hours of setup. Just practical protection that fits around running your actual business.
Try It Yourself
The best way to understand how simulated phishing attacks work is to experience one. Sign up for a free trial and send yourself a test email. You'll see exactly what your staff would see, and you'll understand why this approach works better than traditional security awareness training.
Calendar phishing is just one of many tactics attackers use. Your team needs practice spotting all of them. A few minutes of setup now could save your organisation from a mandatory report under the Notifiable Data Breaches (NDB) scheme within Australia's Privacy Act later.