Barracuda security researchers are warning of a growing form of phishing where malicious links, QR codes, and fake login pages are hidden in calendar invitations. The attacks can remain in the user's calendar even after the original email has been deleted or quarantined.
The calendar has become a central work tool for meetings, training, HR information, payroll matters and administrative reminders. This means that even unexpected calendar entries can be perceived as legitimate. At the same time, many security solutions have historically focused more on emails, links and attachments than on the calendar content itself. According to Barracuda, attackers are now exploiting this gap to create credible attacks that are harder to detect.
The calendar becomes a new target for phishing
The attack often begins with an email containing a calendar file in .ics format. The invitation may appear to come from HR, IT, or another internal function and may refer to, for example, a new policy, mandatory training, changed employee benefits, or an urgent payroll issue.
Once added to the user's calendar, the calendar entry gains a special persistence. It can continue to appear as a reminder even if the security system later deletes or quarantines the original email. This can expose the recipient to the malicious content multiple times, long after the initial delivery.
How the attack works via .ics files
An .ics file can contain much more than just time and location. Attackers can insert logos, formatted instructions, images, links, documents, and QR codes directly into the calendar entry. The design is often customized to resemble the company's normal communications and to create time pressure.
The link or QR code then leads to a fake login page. Barracuda describes how the attacks can use so-called adversary-in-the-middle phishing, AiTM. The technique places the attacker between the user and the legitimate service. If the victim enters their details and performs multi-factor authentication, the attacker can capture both the username, password and the already authenticated session.
This means that traditional MFA is not always sufficient. A stolen session cookie or security token can in some cases grant access without the attacker having to repeat the regular login. The consequence can be hijacked accounts, unauthorized access to cloud services, and further spread within the organization.
QR codes move the attack outside of corporate controls
QR codes create an additional problem because the true destination is not immediately visible. The user often scans the code with a personal or corporate mobile phone, which can move the activity outside the organization’s usual browser, network, and client security.
On a smaller mobile screen, it is also more difficult to check the entire URL and detect small discrepancies in the domain name. The combination of a credible calendar entry, an urgent message, and a QR code can therefore lower the threshold for following the attacker’s instructions.
Barracuda recommends reviewing the entire calendar entry
Barracuda recommends that calendar invitations be treated as active content, not as harmless metadata. Security checks should analyze the .ics file metadata, sender, embedded links and attachments, HTML content, and destinations behind QR codes.
- Identify unexpected .ics files from external senders.
- Pay special attention to urgent HR, payroll, and IT messages.
- Check links, attached documents, and QR codes in calendar entries.
- Link the delivery to anomalous logins and unexpected MFA requests.
- Delete both the original email and the calendar entry if a malicious .ics file is detected.
So it's not enough to just stop the first email. The organization needs to be able to track the entire attack chain, from delivered calendar file to clicks, login attempts, MFA events and any token usage. This is an important part of modern work with cybersecurity.
Phishing-resistant MFA strengthens identity protection
To mitigate the risk of AiTM attacks, Barracuda is highlighting phishing-resistant authentication methods like FIDO2 and WebAuthn. They tie authentication to the correct website and make it significantly more difficult to trick the user into approving a fake login.
Protection should be combined with conditional access, active session monitoring, rapid recall of suspicious sessions, and the ability to detect anomalous logins or security token misuse. Identity protection must include what happens even after an approved MFA request.
Training must include calendar invitations
Employees have long been trained to scrutinize unexpected emails and attachments. The same caution now needs to apply to the calendar. Unexpected invitations about salary, employee benefits, policy changes, or mandatory training should be verified through a separate and known contact channel.
A calendar invitation should not be considered safe just because it has been automatically added to the calendar or uses a well-known logo. QR codes and documents inside an .ics file should be treated with the same suspicion as the corresponding content in a typical phishing email.
About Barracuda Networks
Barracuda Networks develops solutions for cyber resilience and protection of email, data, applications and networks. The company's BarracudaONE platform combines security capabilities and managed services, including XDR, to help organizations prevent, detect and manage cyber threats.
The analysis of calendar-based phishing is produced by Soundharya Bharani Poomalai, Associate Threat Analyst at Barracuda. Read Barracuda Technical Analysis and the Swedish source information on Mynewsdesk.








