Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A meeting appeared in your calendar by itself. Don't follow the link

An unfamiliar invitation can imitate an urgent message from a bank, courier or IT team. Learn how to check and remove it without following the trap.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
9 September 2026
READING TIME
7 min read
TOPIC
Human Security
A meeting appeared in your calendar by itself. Don't follow the link

You open the calendar and find “Account will be suspended” or “Unpaid invoice” between ordinary meetings. You do not remember anyone asking for your time. The alert still feels genuine because it comes from an application you use every day.

An entry inside the real Google Calendar or Outlook does not authenticate its sender. Depending on your settings, invitations from strangers can appear automatically before you accept them. A scammer can use the trusted app as a noticeboard for their own link or telephone number.

The event title is designed to create urgency

The entry may imitate a bank, courier, technical support team, cryptocurrency exchange or employer. Its title and description combine a problem with a rapid solution: “call now”, “confirm your account” or “open the document”. A reminder set for a particular time adds to the feeling that you must act immediately.

Do not follow the link, call the number in the description or reply merely to ask what is happening. Check the organiser’s address first. If the message concerns a genuine service, open its app or type a known website address yourself. At work, confirm the meeting with the supposed organiser through a chat or number you have used before.

Remove the invitation as spam

Use the calendar’s option to report the event as spam. Simply deleting it may not tell the provider about the abuse, and with a recurring event you should check whether the whole series is being removed.

You can also restrict automatic additions in the calendar settings. Google Calendar offers an option to add invitations only when the sender is known — for example, someone in your contacts, organisation or previous interactions. This reduces clutter, although invitations from compromised accounts belonging to known people still deserve scrutiny.

At work, capture a screenshot or record the organiser, title and time, then report them to IT or the security team. Do not forward the suspicious event’s live link to colleagues.

Opening it does not always mean the account has been lost. Close the page and establish what information you entered and which permissions you granted. If you supplied a password, change it through the genuine service, end unfamiliar sessions and enable an additional authentication step. Tell IT promptly at work; an early report gives the team more options.

If you approved an application’s request to access mail, files or calendars, review connected applications and remove questionable permissions. Do not install a “clean-up tool” promoted in another meeting or pay someone to remove the event.

What the source says and what Breachroad recommends

Google’s official guidance explains how to report a suspicious invitation or event as spam. Reporting removes the event from the calendar and, for a recurring series, removes every event in that series. Google also lets people limit automatically added invitations to those from known senders.

Breachroad recommends treating a calendar entry like any other unexpected message. The calendar delivers an invitation; it does not vouch for the organiser’s intentions. Verify the claim outside the event using a known app, address or conversation channel.

We cover a similar lure in An unexpected shared-document invitation. We help organisations practise their response to everyday situations like these through cybersecurity training.

SHARE / COPY