KUALA LUMPUR, Sept 30 — It starts with getting a calendar invite for something you know you shouldn’t be getting, usually from a familiar name, most of the time, a colleague.
Then the invite that you didn’t even click “Yes” to has taken up space in your entire calendar.
If you’ve been unlucky enough to get your email in your Google Workspace it won’t just be you, but your colleagues as well.
Your boss, your juniors, even the cleaning lady now have their whole calendars full of this random invite.
This is the new phenomenon of spam calendar invites that can hijack your entire organisation’s calendars and even disrupt emails.
In most cases it’s an attempt at phishing, convincing you to try and join a meeting created especially to steal your information.
ZDNet reported that according to cybersecurity firm Sublime, these calendar-based attacks have seen a dramatic rise.
Attacks rose by 282 per cent in June from the previous month, increasing further to 338 per cent in July and then a terrifying 1,216 per cent in August.
It doesn’t stop there. Sublime predicts that by this month, September, cases could increase by a massive 2,852 per cent compared to last month.
A simple enough fix
The site MalwareBytes has a long list of recommendations depending on your type of email system that you can refer to here.
Here’s a short list of tips to prevent this from happening to you in future:
- No matter what operating system or email service you use, this should be a wakeup call to you to check your Calendar settings.
- Make sure that not just anyone or any app can access or subscribe you to calendars.
- Check the list of calendars you’re subscribed to in case there are any suspicious looking ones.
- Gmail is particularly irksome in this regard -- toggle the “Show events automatically created by Gmail” to off.
How safe is your workplace or family group?
Whether it’s just administrating your office or your less tech savvy relatives’ email and calendars, it’s easy to take things like calendars for granted.
Especially with spams targeting the vulnerable, vigilance is unfortunately the only protection, and with rogue LLMs being allowed to break containment due to lax security standards on both the LLM and client-side, it’s going to be even trickier in future.
The best advice I can give to you in situations like this is to always have one or ideally two “safe” people you can get advice from in case you think you have been targeted.
That person could be your office’s IT firm. Your friend who majored in cybersecurity. Just make sure it’s someone you trust and see in person because, sadly, you never know if their identities could be compromised in this world so full of deep fakes.
Just stay calm, understand that this kind of malware attack is solvable and fixable quickly, at least on the user side.
It might take a bit more time to fix things should this malware run rampant in your colleague’s calendars but follow the steps in the link from Malwarebytes and you should be protected, at least for a while, from further calendar-based breaches.
You May Also Like