Don't RSVP to That Hack: How One Breached Inbox Can Take Down Your Whole Contact List

Taking the bait of an email invitation phishing scam

Don’t take the bait of fake event invitations- it’s a trap!

How one breached inbox turns into a contact-list-wide phishing attack — and what to do if you already clicked.

You get a calendar invite from someone you actually know — a friend, a coworker, your kid's soccer coach. No red flags, no weird subject line, just a normal-looking event popping into your calendar app the way invites always do. So you click to see what it's for. That click is the whole attack.

What's actually happening

Here's the pattern showing up again and again in client accounts this year: someone's email gets breached — usually through a reused or leaked password — and the hacker doesn't send an obvious scam email. They send a calendar invite to everyone in that person's contact list instead. It looks legitimate because it is coming from a real, familiar address. Click into the invite, and you land on a fake login page designed to look like Google, Microsoft, or whatever service you use — enter your password there, and now your account is breached too. The hacker repeats the process with your contacts. Rinse, repeat, spread.

This isn't a hunch — it's a documented trend. Calendar-invite phishing (attackers embedding malicious links or fake sign-in pages inside .ics calendar files) is up roughly 49% over the last six months, according to security researchers at Barracuda and Hoxhunt. It works so well because most email and calendar apps auto-process invites straight onto your calendar — no extra click required to make it look "real" — and a convincing fake login page can grab not just your password but your active MFA session, meaning even two-factor authentication doesn't always save you if you type your code into the wrong place.

How to spot a fake invite before you click

Check who it's actually from, not just the display name — tap or hover on the sender to see the real address. Be suspicious of urgency or vagueness — "Important Meeting," "Please Confirm ASAP," or an event with no real description is a common shape for these. Don't enter your password from a link in an invite; if you need to log into Google, Microsoft, or anything else, go to the site directly instead of clicking through. And a weird invite from someone you know is a bigger red flag, not a smaller one — it usually means their account, not yours, has already been compromised.

If you already clicked — or think your account's compromised

  1. Change that account's password immediately, from a device you trust, not the one you might have just typed it into.

  2. Check your MFA/session settings and sign out of all active sessions — this kicks out anyone who grabbed your session token along with your password.

  3. Look at your sent items and calendar for invites or emails you didn't send — that's the tell that your account is actively being used to spread the attack further.

  4. Give your contacts a heads-up so they know not to click anything that "came from you."

Late to the party beats losing your whole contact list. If you want a second set of eyes on your account security before (or after) something like this happens, let's get you on the calendar — the real kind.

Book a session with Chris →

Previous
Previous

It's Not You, It's Me. No, Wait — It's You: How to Break Up With Every Data Broker in California at Once

Next
Next

Massive Password Leak: Take Action Now