Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May — and they work even if the email is sent to spam

Phishing
(Image credit: Shutterstock)

  • Sublime researchers warn ICS phishing via calendar invites is surging ~33,000% since May 2026
  • Attacks bypass filters, trick users into installing RMM tools like ScreenConnect for full compromise
  • Defenses: scrutinize suspicious invites, verify senders, and treat ICS attachments with caution

ICS phishing - the type of phishing that abuses calendar files (.ics) is set to increase by around 33,000% between May and September 2026. This is according to a new report by cybersecurity researchers Sublime, who argue that this type of phishing has finally “hit the mainstream”.

The methodology is simple - the attacker uses a free service, such as Gmail, and sends a calendar invite to the target. Since both services are legitimate and free, the attacks bypass most email security filters and can be done at scale with close to zero cost.

Furthermore, the victim is exposed to the attack twice: once in the inbox, and once in their calendar. Inside the calendar invite is usually a link to download a maliciously configured remote management and monitoring (RMM) solution such as ScreenConnect. The attackers can use the tool to take over the compromised endpoint, deploying stage-two malware such as infostealers or ransomware, and grabbing passwords, documents, and other valuable secrets.

Latest Videos FromTechRadar

Spiking in popularity

ICS phishing started increasing in popularity roughly a year ago, but has been really picking up speed lately. Between May and June it increased 282%, and between June and July - 338%.

Between July and August it rose 1,216%, and in just the first half of September it rose 1,426% over the full month of August. Projections for the entire month of September, over August, are 2,852%, Sublime says.

“The jumps in August and September appear to be indicators that this attack type has finally hit the mainstream,” the researchers explained. “To really drive that point home, the increase from May to September is projected to be ~33,000%.”

Defending against these attacks is best done with a little common sense, the researchers conclude. Users should be mindful of the telltale signs, such as suspicious CTAs, suspicious senders, and the usual financial urgency.


Best antivirus software header
The best antivirus for all budgets

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.