Barracuda researchers are warning organisations to treat calendar invitations as a phishing risk, as attackers increasingly abuse iCalendar (.ics) files to bypass controls that focus primarily on email bodies and traditional attachments.
In an analysis by Associate Threat Analyst Soundharya Bharani Poomalai, Barracuda said malicious calendar events can carry phishing links, QR codes and business-themed lures designed to direct recipients to credential-harvesting pages, including through adversary-in-the-middle (AiTM) phishing platforms.
The company said the approach works in part because calendars are now used for more than meetings, including reminders for training, compliance activities and corporate announcements, making non-meeting invitations appear routine. Barracuda also noted that calendar entries may be added automatically with little user interaction, can persist even if the original email is deleted or quarantined, and are commonly handled on mobile devices where some desktop-focused controls have limited visibility.
According to the researchers, attackers may send a minimal email containing an .ics attachment, with a subject line referencing routine internal processes such as HR policy updates, employee handbook reviews, benefits enrolment, compliance notifications, or payroll and administrative actions. Once opened, the calendar application renders content embedded in the event, which may include images, branding, instructions or QR codes intended to appear legitimate.
Barracuda said the .ics format is designed for interoperability across platforms such as Outlook, Google Calendar and Apple Calendar, and can contain event titles, descriptions, organiser details, locations, attachments, URLs and custom metadata fields. Those features can be abused by embedding phishing content in event descriptions, hiding links in location fields, attaching files, or using HTML-formatted content that is not inspected as thoroughly as the email body by some security tools.
The researchers also pointed to QR codes as a method to evade link-focused detection, arguing that security tools may not decode QR content by default, users cannot easily inspect the destination URL before visiting it, mobile devices may access links outside monitored environments, and redirect chains can obscure the final destination.
Barracuda advised security teams to look for signals across email, calendar and identity systems. The indicators it listed included messages with minimal content, unexpected .ics attachments, external senders and newly observed sending infrastructure; calendar invites containing rich HTML, embedded images or QR codes, links hidden in event fields, organiser mismatches and heavy use of custom fields; and identity events such as unfamiliar device sign-ins, unexpected MFA prompts, session creation shortly after invite delivery, OAuth consent activity and token reuse.
On mitigations, Barracuda recommended treating calendar invites as “active content” and inspecting .ics files with the same scrutiny as other attachments, including parsing metadata fields, analysing embedded links and attachments, inspecting HTML-rendered content and decoding QR codes. It also said incident response should remove both the delivery message and the associated calendar entry from affected mailboxes when a malicious .ics file is identified.
The analysis further recommended strengthening identity controls with phishing-resistant multifactor authentication such as FIDO2 or WebAuthn, conditional access policies, session monitoring and rapid revocation, and improving user awareness that calendar invites and QR codes can be used as phishing mechanisms.
Barracuda concluded that calendar invites “are no longer just scheduling tools”, arguing attackers are adopting them as phishing vehicles due to user trust, potential evasion of email-centric defences and persistence beyond the original message.

