What Google Calendar phishing spam is and why it keeps happening
Google Calendar phishing spam uses fake event invitations, reminders, or attachments to deliver malicious links, scams, or unwanted promotions.
Because calendar invites can appear legitimate and arrive through Google services, they often bypass the skepticism people reserve for email.
This type of spam matters because it can clutter your schedule, trick you into opening harmful URLs, and expose personal or organizational data.
Understanding how the abuse works is the first step in learning how to stop Google Calendar phishing spam before it keeps returning.
How Google Calendar spam reaches your calendar
Attackers typically exploit default calendar sharing and invite settings, often sending events to large lists of Gmail addresses.
If your Google Calendar is configured to automatically add invitations, spam can appear without your approval.
- Fake meeting requests with urgent subject lines
- Events containing shortened or obfuscated links
- Attachments that lead to credential theft or malware
- Invites routed through other Google accounts or compromised contacts
- Calendar notifications that mimic legitimate business or delivery notices
Because Google Calendar is tightly integrated with Gmail, Android, and Google Workspace, a single malicious invite can surface in multiple places.
That makes prevention settings especially important.
How to stop Google Calendar phishing spam at the source?
The most effective fix is to change how events are added to your calendar.
If you do not want invites appearing automatically, adjust the visibility and invitation settings in Google Calendar.
Turn off automatic event additions
In Google Calendar, open Settings, then locate event or invitation settings and disable automatic addition of invitations.
Choose the option that only shows invitations when you respond, rather than adding every invite to your calendar.
Block known spammers and report abuse
If the spam comes from a specific sender, block that address in Gmail and report it as phishing or spam.
Google uses these reports to improve filtering, and repeated abuse reports can reduce future delivery from the same source.
Remove unwanted calendars you did not subscribe to
Some spam appears through subscribed calendars rather than single events.
Review the left sidebar in Google Calendar and unsubscribe from any calendar you do not recognize, especially if it contains promotional or suspicious event titles.
Check sharing permissions
Review calendar sharing settings and make sure only trusted people can add events or manage your schedule.
In Google Workspace environments, administrators may also need to adjust domain-level sharing and external invite permissions.
Which Google Calendar settings reduce phishing risk?
Several Google Calendar and Gmail settings can limit exposure to malicious invites.
These controls do not remove all spam, but they significantly reduce how much reaches your inbox and calendar view.
- Set invitations to be added only after you respond
- Disable “automatically add invitations” where available
- Show declined events only if necessary
- Turn on Gmail phishing and spam filtering
- Use two-factor authentication on your Google account
- Review connected apps and third-party calendar access
If you use Google Workspace, ask an administrator to check whether external senders can invite users directly.
Tighter domain policies can prevent mass invite attacks from outside the organization.
How to identify a malicious calendar invitation?
Phishing calendar invites often rely on urgency, vague labeling, or confusing links.
A suspicious event may look like a package notice, a payment warning, a shared document request, or a fake Zoom or Teams meeting.
Common warning signs
- The sender is unknown or the display name does not match the address
- The event title uses urgent or alarming language
- The description contains a link that is shortened or misspelled
- The invite includes unexpected attachments
- The event appears on multiple dates without clear context
- The content asks you to log in, verify, pay, or download something
If an invite references a bank, shipping company, IT support desk, or government agency, treat it carefully and verify through an official website or phone number you already trust.
Do not use the contact details inside the invite unless you have independently confirmed them.
What to do if you already accepted a suspicious invite?
If you clicked accept, opened the attachment, or visited the link, act quickly.
Remove the event, inspect your account activity, and change credentials if you entered any sensitive information.
- Delete the event from your calendar
- Mark the invite as spam or phishing in Gmail
- Change your Google password immediately if you entered credentials
- Enable or recheck two-factor authentication
- Review recent sign-in activity in your Google Account
- Scan your device with reputable security software
If the event came with a link to a login page, check whether you submitted a password, recovery code, or payment information.
If you did, reset passwords on any related accounts right away, starting with email and financial services.
How to clean up recurring spam in Google Calendar?
Some calendar spam is persistent because the attacker keeps sending new invitations or uses synchronized calendars.
Cleaning up the problem requires removing the source and tightening your filters.
- Search Gmail for recurring sender names, subjects, or domains
- Unsubscribe from suspicious calendar subscriptions
- Remove delegated calendar access you no longer need
- Audit third-party apps with calendar permissions
- Clear browser cache and sign out of shared devices
On mobile devices, confirm that your Google account is not being synced into a secondary calendar app that re-imports spam.
This can happen when multiple apps have permission to read and write calendar data.
How to stop Google Calendar phishing spam on Android and iPhone?
Mobile users often notice spam through push notifications first.
The fix usually involves the same account settings, but it also helps to check app-level permissions and notification behavior.
On Android
Open the Google Calendar app, review account settings, and confirm that invite handling is set to manual approval where available.
Also inspect Google account security, since Android devices often sync calendar data across multiple Google services.
On iPhone
If you access Google Calendar through the app or Apple Calendar sync, remove any suspicious subscribed calendars and ensure only trusted Google accounts are linked.
If you receive repeated spam notifications, confirm that the invites are not coming through another connected calendar account.
Best practices for businesses and teams
Organizations should treat Google Calendar phishing as part of broader email security and identity protection.
A compromised inbox can be used to distribute malicious events to coworkers, customers, or vendors.
- Require phishing-resistant authentication where possible
- Restrict who can invite users outside the domain
- Train employees to inspect sender addresses and event links
- Use secure email gateways and Google Workspace alerting
- Review calendar sharing and delegation regularly
Security awareness training should include calendar abuse examples, not just email phishing.
Attackers count on users trusting calendar reminders more than suspicious-looking messages.
When to escalate to IT or Google support?
If spam continues after you block senders, remove subscriptions, and change settings, escalate the issue.
Persistent abuse may indicate a compromised account, a misconfigured Workspace policy, or a third-party app with excessive permissions.
Contact IT or Google support if you notice any of the following:
- Unknown events are being added after you delete them
- Your account shows unfamiliar sign-ins
- Calendar invitations are sent from your account without permission
- Multiple users in a domain report the same spam pattern
- Third-party apps keep restoring unwanted events
Fast reporting helps protect both your account and everyone else who might receive the same malicious invite.