Calendar Phishing, or Calphishing, is back with a new variation.
Fortra Intelligence and Research Experts (FIRE) are tracking a shift in Calphishing attack delivery methods, with threat actors targeting key employees as an initial trust access point to their intended victims. Posing as prospective customers, the actors ask to be connected with a sales representative and provide a meeting-booking link to share internally. By leveraging employees as unwitting intermediaries, the attackers transform the lure into what appears to be a credible inbound opportunity, increasing trust and improving the chances that the target will engage.
If the attacker successfully gains access to an targeted account, they have the ability to read business emails, access sensitive information, and impersonate the employee to target colleagues or customers. For compromised organizations, this could mean data theft, fraud, lateral movement, and operational disruption.
Threat Summary
A prospect-style request reaches a non-sales employee, earns a helpful internal forward, and lands with sales as a trusted booking request. The calendar page is where the real phishing flow begins. This is not cold sales targeted phish, it is tiered trust abuse.
In this case, CalPhishing uses a routine booking workflow to turn a scheduling action into a phishing event.
The attacker does not start with the main target. They pose as a prospective buyer and contact someone outside the sales team, asking for the right person to speak with. It can look like a normal request so the employee replies, tries to help, and becomes the trust bridge.
The next message carries a booking link and a simple request: please forward this to sales. Once that happens, the link arrives with internal social proof. To the sales recipient, it is a colleague’s handoff rather than a cold external approach.
That is the point of the attack. The attacker does not need to impersonate a known user or compromise an employee or customer mailbox; they only need someone inside to make the introduction.
How the Trust Chain Is Built
1. Prospect pretext. An external sender claims they want to buy and contacts a non-sales employee for the right point of contact.
2. Helpful response. The employee engages, asks for availability, and confirms that they can route the request.
3. Internal handoff. The sender provides a meeting-booking link and asks for it to be forwarded to sales.
4. Trusted delivery. Sales representative receives the email containing a “book a meeting” button embedded with a link, forwarded from a known colleague. The forward changes the recipient’s risk calculation.
5. Calendar pivot. The booking page asks the user to choose a date and time, then introduces a Microsoft 365 work-or-school sign-in prompt, framed as necessary to complete or sync the booking.
The screenshots show a booking-style flow that looks operational until the last step. Time selection makes the page feel routine. The Microsoft 365 prompt turns that routine action into an authentication event.
Introduction
Lure delivery via Book A Meeting (Link embedded)
Lure delivery
Booking page
The Booking Page Is the Pivot
The booking page is what keeps the fake story going. It first presents available times and a familiar scheduling journey. Time selection makes the page feel routine and operational.
In this case, the page first presents available times and a familiar booking journey. After the selection, it asks the user to confirm the booking through a Microsoft 365 work-or-school account. The booking flow appears to be the cover story; the sign-in prompt appears to be the likely objective.
Based on the material reviewed, the flow appears consistent with a likely credential-harvesting attempt using Microsoft 365 branding. What makes this effective is not a clever email alone. It is the trust chain: external sender, helpful employee, internal forward, sales recipient, booking page, sign-in prompt. Every step is individually familiar, so the full chain does not feel like a phishing chain.
Why It Works
The attack borrows trust from normal business behaviors.
Sales teams are expected to act on inbound interest. Non-sales employees are expected to help route it. Calendar invites links are common. Each step is individually familiar, so the full chain does not feel like a phishing chain.
The internal forward is the social proof. It removes the suspicion that usually makes a cold phishing email suspicious. The target sees the booking page, as the attacker has already inherited a colleague’s credibility, and the phishing goes ahead.
This is where the case fits the wider CalPhishing trend. Attackers are moving phishing into calendar, collaboration, and booking workflows where people expect to click, schedule, and connect a work account. Separate 2026 reporting has also described deceptive booking pages that lead to corporate calendar sign-in screens.
This sample should be presented as a booking-flow variant, not an .ics invite campaign.
What Defenders Should Look For
A routine booking flow on an unfamiliar external site normally should not require a work-account sign-in merely to book a meeting. That is the red flag.
Things to consider
External prospect requests that create an internal forward. The forwarder is not malicious; they are the bridge being used.
Booking links on unfamiliar or unrelated domains. Treat the destination as external even when the message arrives from an internal colleague.
Authentication after time selection. A request to sign in to Microsoft 365 to “sync” or “secure” a booking should be verified outside the page.
Cross-surface evidence. Investigations should correlate the original external email, the internal forward, the booking-domain click, and sign-in telemetry around the booking event.
Email filtering may not show the whole path. Investigations need to follow the handoff from inbox to internal mail to browser to authentication.
The simple rule is this: if a booking page asks someone to sign in to Microsoft 365 after they select a time, stop and verify it through a known channel.
The Operational Takeaway
An internal mail forward is not automatically a trusted email.
In this CalPhishing variant, the first email is not the end of the phish, it is the handoff. The attacker earns a small favor, turns it into an internal referral, and uses the calendar workflow to ask for the action that matters.
Train teams to validate the destination, not only the sender. A booking request forwarded by a colleague can still lead somewhere it should not.
Conclusion
CalPhishing works because the malicious action is hidden inside a workflow people already trust. In this variant, the attacker builds that trust before the booking link ever reaches the target. The key takeaway is simple: an internal forward can add credibility, but it does not make the destination safe. Verify the booking site and any unexpected sign-in request before entering a work account.
What starts as a forwarded sales enquiry could end in a compromised account, exposed business data or further phishing.