Google Calendar, with over 500 million active users worldwide and availability in 41 languages, has long been celebrated for its efficiency in organizing schedules and managing time. However, its popularity has also made it a prime target for cybercriminals.
Cybercriminals are leveraging the inherent user-friendly features of Google Calendar and Google Drawings to launch phishing attacks that impersonate legitimate sources.
According to recent findings by cybersecurity researchers at Check Point, malicious actors are manipulating trusted Google tools, including Google Calendar and Google Drawings, to execute sophisticated phishing campaigns.
Researchers observed that attackers modify sender headers, making phishing emails appear as though they originate from Google on behalf of known and trusted individuals.
This tactic has affected around 300 brands, with over 4,000 phishing emails detected in a single four-week period.
The initial wave of phishing attacks exploited Calendar invites, often connecting users to malicious Google Forms links. However, as cybersecurity tools started flagging these invites, attackers shifted strategies to utilize Google Drawings.
These malicious emails often carry links disguised as urgent actions, such as fake reCAPTCHA or support buttons.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
The ultimate goal of these phishing campaigns is to deceive users into clicking malicious links or attachments, leading to the theft of sensitive personal or corporate data.
Once this information is compromised, it can be used for fraudulent activities, including credit card fraud, unauthorized transactions, and bypassing account security measures.
The attack is typically executed in stages. It starts with a phishing email containing a Calendar invite file (.ics) or a link to Google Drawings.
Users are encouraged to click on additional links, which redirect them to fraudulent websites masquerading as cryptocurrency mining platforms or bitcoin support pages.
These fake websites prompt users to complete authentication processes, provide personal details, or enter payment information, ultimately enabling financial scams.
To counter these rising threats, both organizations and individuals must adopt robust cybersecurity measures. Below are practical recommendations for safeguarding against such phishing attacks:
For Organizations:
For Individuals:
Addressing the issue, Google strongly advises users to enable the “known senders” setting in Google Calendar. “This setting helps defend against phishing by notifying users when they receive invitations from someone unknown or not listed in their contacts,” Google stated.
As cybercriminals continue to refine their tactics, prioritizing email and collaboration security in 2025 will be crucial for organizations and individuals. Upgrading to advanced security solutions and remaining vigilant against phishing attempts can mitigate risks and protect valuable information.
For organizations seeking enhanced security, Google recommends exploring solutions like Harmony Email & Collaboration. For a demo and consultation on upgrading email security, visit their official site.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…
Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…
A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…
OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…