While phishing remains the most common and damaging cyber threat, with 3.4 billion phishing emails sent daily, the methods are evolving.
Now phishing attacks are taking advantage of people’s busy work lives via their calendars.
Called calendar phishing (calphishing), this new kind of social hacking involves delivering malicious content directly into an employee’s calendar, aiming to trick victims into visiting fake login pages, approving authentication requests, or phoning the hackers directly – only to fall for a social engineering scam.
The end goal, as with most kinds of phishing, is to capture login credentials, obtain authenticated access, or steal money directly from the victim. Some clever campaigns of this sort also target session tokens – the credentials that maintain a user’s logged-in state – to bypass multi-factor authentication and access internal systems without triggering additional verification protocols.
For overburdened healthcare employees who don’t have time to vet every calendar event, this new evolution of phishing could prove catastrophic.
The blind spot we failed to notice
One study found calphising attacks are up by 49 per cent just this year. This is uncharted territory for many health sector organisations, who haven’t prepared their systems or employees for these types of phishing campaigns.
Calphishing is effective because they abuse a blind spot: phishing security programs currently remain centred on email protection. Similarly, employee cyber security training often focuses on suspicious email characteristics such as poor grammar, unexpected attachments, or spoofed sender addresses.
Recognising that vulnerability, hackers have adapted to exploit it. With an eye towards exploiting trust, calphishers create invitations that appear to come from legitimate services. With the default setting for calendar apps to tentatively accept the appointment and place it on the users’ calendars, the adversary can take advantage of this long-standing configuration gap.
Without warning, the malicious appointment pops into the calendar. When the appointment is opened by the end user, they’re more likely to fall for the scam it contains, letting their guard down because it was information on their calendar.
Such attacks take advantage of a simple assumption: people trust their calendars. Employees routinely accept invitations from colleagues, vendors, patients, and external partners, but without scrutinising them the way they would an unexpected email.
These malicious calendar invites may contain a link to a fake login page designed to steal credentials. They could also redirect users to a fraudulent authentication flow, or prompt them to approve access to an attacker-controlled application. Because the invitation itself looks to be generated through a legitimate calendar service, it may even bypass traditional email security controls.
For health sector organisations, the risk is amplified by the volume and urgency of digital communication. Clinicians and administrators manage packed schedules, coordinate across departments, and frequently interact with vendors through shared calendars and collaboration tools. An invitation that appears to be related to patient care, internal operations, or a vendor meeting can easily blend into normal workflows.
Seek to defend beyond the inbox
As phishing evolves to abuse various user apps, healthcare organisations must rethink how they defend their employees, identities, and cloud environments. Traditional email security remains a fundamental line of defence, but organisations must build in protocols assuming that attackers may reach users through legitimate platforms and cloud services.
The first priority should be to disable automatic calendar invitation processing. Enterprise email administrators should disable the automatic processing of external calendar invites and require users to manually review and accept external appointments.
For your personal email and calendar, you should follow the same advice!
Next, security teams should expand visibility beyond email and ensure their enterprise security controls also monitor calendar platforms, collaboration tools, and identity providers for suspicious activity.
Integrating telemetry on identity, endpoint, and cloud touchpoints into a centralised security operations platform will enable security teams to identify attacks that span multiple services instead of having to study each event in isolation. Don’t treat authentication as a one-time event.
Employee training also needs to evolve. Help hospital staff understand how meeting invitations, shared documents, collaboration requests, and authentication prompts can all serve as attack vectors.
Recognise that phishing abuses human behaviour
With its roots in social hacking, phishing has always been about taking advantage of psychology, behaviour, habits, and trust to fool people. And with AI tools lowering the cost and technical bar for such campaigns, we’re only going to see phishers manipulating trust within even more legitimate cloud services.
Fortunately, cyber security professionals don’t have to figure this out on their own. Networking platforms, security associations, and information-sharing communities can help with new trends in threats and vulnerabilities, best practices, and more.
For health sector organisations, where access to systems directly impacts patient care and sensitive information, defending against phishing requires a change in mindset: Recognise that email was just the first frontier, and the best defence is ultimately a solid security foundation.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.