Kaspersky experts have detected multiple cases of a sophisticated scam targeting users through fraudulent, unsolicited Google Calendar notifications and luring them into giving away their personal information. This scam abuses a specific feature of a free online calendar service which adds invitations and events to users’ calendars automatically. The attacks happened throughout May.
Spam and phishing that exploit non-traditional attack vectors can be lucrative for criminals, as they can catch out experienced users who might not fall for a more common threat. This is particularly the case when it comes to trusted legitimate services, such as default e-mail calendar features, and these are exploited through so-called “calendar phishing”.
The detection of multiple, unsolicited pop-up calendar notifications during May turned out to be a result of a blast of sophisticated spam e-mails sent by scammers. The e-mails exploited a common default feature for people using Gmail on their smartphone: the automatic addition and notification of calendar invitations. The fraud occurs when the perpetrator sends an unsolicited calendar invitation carrying a link to a phishing URL. A pop-up notification of the invitation appears on the smartphone’s home screen and the recipient is encouraged to click on the link.
In most of the cases observed, the user was redirected to a website featuring a simple questionnaire with prize money on offer. To receive the prize, the user is asked for a “fixing” payment for which they need to enter their credit card details and add some personal information, such as a name, phone number, and address. This data goes straight to the scammers who exploit it to steal money or identity information.
To avoid falling victim to malicious spam, Kaspersky researchers advise users to:
Turn off the automatic adding of invites to your calendar: to do so, open Google Calendar, click the settings Gear Icon, then on Event Settings. For the ‘automatically add invitations’ option, click on the dropdown menu and select ‘No, only show invitations to which I’ve responded’. Below this, in the View Options section, make sure ‘Show declined events’ is NOT checked, unless you specifically wish to view these. If you are not sure whether a website you are redirected to is real and safe, never enter personal information