Calendar Invite Phishing in Gmail and Outlook (2026), how to spot auto-added events and stop the spam

Reading Time: 5 minutes

You check your calendar and see a meeting you never scheduled. It has a Zoom link, a “payment required” note, or an HR-sounding subject line. Your first thought is often, “Did I forget this?” That hesitation is the trap.

Calendar invite phishing works because it turns your calendar into a to-do list you didn’t create. Instead of a sketchy email you can ignore, the scam sits on your schedule like it belongs there, waiting for the moment you’re rushed or distracted. This guide shows how to spot auto-added events in Gmail and Outlook, remove them safely, and change the settings that let spam stick.

Why calendar invite phishing is hitting harder in 2026

Attackers learned a simple truth: people trust calendars more than inboxes. A calendar entry feels like a commitment, not a message, and it often pops up later as a reminder when your guard is down.

Security researchers have also warned that invite-based attacks can slip past traditional email filters because they arrive as meeting objects (ICS invites) rather than a normal “pitch” email. Some campaigns have reportedly hit thousands of invites across hundreds of organizations in a short window, using Google Calendar lookalikes and realistic meeting templates.

What makes 2026 worse is how “normal” the lures sound. The subject lines read like routine work: onboarding, invoice review, “quick sync,” payroll changes. That matches a broader trend described in PhishDown’s analysis of what changed in 2026, where phishing feels less like a warning sign and more like everyday admin.

Some scams go beyond password theft. Reports have tied bad clicks to remote access sessions and real money loss, including bank transfers. And because the calendar entry persists, you might click it days later, long after you forgot where it came from.

For background on how these fake invites spread and why they can be tough to remove, see this Malwarebytes report on fake calendar invites.

How to spot auto-added spam events in Gmail and Outlook

A safe rule: treat an unexpected calendar event the same way you’d treat a strange login alert. Slow down, verify, and don’t click links inside it.

Start with the “who,” not the “what.” Open the event details and inspect the organizer’s email address and domain, not just the display name. “HR Team” can be anyone, but hr@yourcompany.com versus hr-payroll@yourcornpany.com (look-alike letters) tells a different story.

Next, scan the meeting body like a scam text message. Common tactics show up again and again:

  • Crypto bait: “Wallet flagged, verify seed phrase,” “airdrop eligibility,” “coinbase support meeting.”
  • Gift card pressure: “Need reimbursement today,” “CEO request,” “team appreciation cards.”
  • Fake delivery or travel: “Package held, pay redelivery fee,” “TSA pre-check issue,” “flight refund form.”
  • HR and payroll traps: “Direct deposit update,” “salary adjustment review,” “benefits re-enrollment required.”

Here are short examples of wording that should set off alarms:

  • “Action required: confirm payroll details before 5 PM today.”
  • “Delivery failed, reschedule here (link) to avoid return.”
  • “Zoom security upgrade, sign in to keep access.”
  • “Tax document ready, view attachment and verify.”

Red flags that often indicate calendar invite phishing:

  • You didn’t request it, and there’s no related email thread.
  • The location field is a link or a shortened URL.
  • The description pushes urgency (“final notice,” “account locked”).
  • The organizer domain is off by one character, or uses a free domain for “corporate” topics.
  • There’s an attachment you didn’t expect (even an .ics update can be used to keep re-adding events).
  • The time zone is odd, or it’s an all-day “reminder” meant to stay visible.

Outlook users sometimes notice these as “tentative” items that appear even before acceptance, depending on client settings and workplace policy. Gmail users may see invites show up on Google Calendar even if they never clicked “Yes,” depending on how invitations and email-based events are configured. If you want a real-world example of how recurring calendar spam can spiral, this Microsoft Q&A thread about ongoing phishing events captures what many users run into.

Stop calendar spam in Gmail and Outlook: removal, settings, and a 5-minute fix

The 5-minute fix checklist (printable)

  1. Don’t click embedded links in the event body, location, or attachments.
  2. Open the event and check the organizer email/domain carefully.
  3. If it’s suspicious, remove the event from your calendar (not just the email).
  4. Use your mail provider’s Report phishing option on any related message.
  5. Change calendar settings so invites don’t auto-add (or don’t show until you respond).
  6. Turn on multi-factor authentication (MFA) for your email account.
  7. For work accounts, tell IT if you see multiple events, or recurring invites.

Print that list and keep it near your desk. It’s faster than cleaning up after a bad click.

Remove the event safely (without triggering the trap)

Open the event details and look for options like Remove, Delete, Decline, or Report spam (wording varies by app). If you see “View details” buttons or a big “Join” link, ignore them. Your goal is to get the event off your calendar without interacting with anything inside the description.

If the event keeps coming back, check if it’s part of a shared calendar you didn’t mean to subscribe to, or if your account has an unwanted calendar subscription. In many apps, calendar subscriptions live under Settings ▸ Calendar ▸ Add calendar (look for “Subscribed calendars” or “Other calendars”).

Gmail and Google Calendar: stop auto-added events

In Google Calendar (web is easiest), go to Settings ▸ General (look for Event settings and Automatically add invitations). Set it to an option like Only show invitations to which I’ve responded. That prevents mystery invites from landing on your calendar as plans you “already have.”

Also review Settings ▸ Events from Gmail. If you don’t want purchases, reservations, or random email parsing to become calendar items, turn that feature off (or limit what shows).

For personal accounts, you control most of these options. For Google Workspace accounts, admins can enforce settings, and some toggles may be locked. If you can’t change them, document a few example events and send them to your IT team.

Outlook and Microsoft 365: reduce calendar invite spam (and stop auto-processing)

In Outlook on the web, open Settings ▸ Calendar and look for sections like Events and invitations and Events from email. Turn off email-to-calendar features you don’t need, and look for options that control whether invitations appear automatically.

In Outlook desktop, search Options for settings related to automatic meeting request processing (wording varies by version). In some workplaces, mailbox processing rules or server-side automation can cause invites to appear or be handled without you noticing.

For Microsoft 365 admins, user settings might not be enough. If a tenant needs to reduce automatic processing broadly, this Microsoft Q&A discussion on preventing external invites globally points to the Exchange-side controls often used in practice. Policy choices vary, and tightening them can affect legitimate scheduling, so changes should be tested.

If you clicked a link in the invite

Act like you just typed your password into the wrong site, because that’s often the goal.

  1. Close the tab and don’t enter more information.
  2. Change your email password (from a known, bookmarked login page).
  3. Turn on or re-check MFA, then sign out other sessions if your account offers it.
  4. If it’s a work account, report to IT/security with the organizer address and event text.
  5. If money or banking info was involved, contact your bank using a verified number.

Do and don’t table (save or print)

DoDon’t
Check the organizer’s email domainTrust the display name (“HR Team,” “Support”)
Remove the event using Delete/Decline/Report spamClick “Join,” “View invoice,” or any embedded link
Verify the meeting via a separate channel (call, chat, known address)Reply to the invite asking if it’s real
Inspect location, notes, and attachments for odd linksOpen unexpected attachments tied to an invite
Ask IT about org-wide controls if events keep reappearingAssume deleting the email removes the calendar event

Calendar spam is annoying, but the real risk is the one rushed click that turns a fake meeting into an account takeover. Treat unexpected invites like suspicious emails, verify the sender, and lock down auto-added events so your calendar stays yours.

Scroll to Top