Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May — and they work even if the email is sent to spam

https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1920-80.jpg
  • Sublime researchers warn ICS phishing via calendar invites is surging ~33,000% since May 2026
  • Attacks bypass filters, trick users into installing RMM tools like ScreenConnect for full compromise
  • Defenses: scrutinize suspicious invites, verify senders, and treat ICS attachments with caution

ICS phishing - the type of phishing that abuses calendar files (.ics) is set to increase by around 33,000% between May and September 2026. This is according to a new report by cybersecurity researchers Sublime, who argue that this type of phishing has finally “hit the mainstream”.

The methodology is simple - the attacker uses a free service, such as Gmail, and sends a calendar invite to the target. Since both services are legitimate and free, the attacks bypass most email security filters and can be done at scale with close to zero cost.

Furthermore, the victim is exposed to the attack twice: once in the inbox, and once in...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more