'It is significant, and it’s something many organisations haven't accounted for': The phishing…

https://cdn.mos.cms.futurecdn.net/5SZMvKovSPYfFCNFA9RxaV-1280-80.jpg

Although many people would think of phishing as a malicious email containing a suspicious link or attachment, hackers have now moved far beyond this to target trusted business tools including calendars and meeting invites.

We spoke to Soundharya Bharani Poomalai, Associate Threat Analyst, Barracuda, to find out more.

  • Why are attackers increasingly turning to calendar invites and .ics files as phishing vehicles, and what has changed in the threat landscape to make this an attractive attack surface now?

Calendars have become part of daily business admin and are used far beyond meeting scheduling. People now get invites for things like policy acknowledgements, handbook reviews, benefits enrolment windows and compliance training reminders. A calendar invite referencing an HR update or a payroll action doesn't look out of place, and this allows attackers to blend in more easily than a suspicious email ever could.

There's also a structural advantage. Calendar entries get...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE