Google Calendar invite phishing bypasses spam filters to steal credentials
Impersonating: Google / Gmail
What is this scam?
Google's June 2026 fraud advisory highlights a significant surge in Calendar invite phishing affecting UK users, where attackers send fake Google Calendar invitations containing links to phishing pages. Because the invites are delivered through Google's own Calendar infrastructure, they bypass most spam and phishing filters and appear as genuine event notifications. Victims who click the embedded link are taken to convincing fake sign-in pages designed to steal Google account credentials, payment card details, or personal information.
Example scam message
Red flags to look out for
- The message creates urgency — threatening a fine, missed delivery, or account closure.
- Links lead to unofficial domains that don't match the real company's website.
- You weren't expecting this message and can't verify the event it references.
- It asks you to confirm payment details or personal information via a link.
- The sender's number or email address doesn't match the company's official contact.
What to do if you receive this
- Do not call any numbers or click any links in the message.
- Log in to your account directly via the official website or app to check for any real alerts.
- Forward the message to 7726 or email report@phishing.gov.uk.
- Report it to Action Fraud at actionfraud.police.uk.
Not sure if your message is a scam?
Check it instantly with our free AI-powered detector.
Check a message nowSource: NCSC