Barracuda warns calendar invites are being used for phishing via .ics files

Cybersecurity firm Barracuda is warning organizations about a rise in phishing attacks that utilize malicious iCalendar (.ics) files. These files bypass traditional email security filters by embedding phishing links and QR codes directly into calendar invitations.
Why it matters
As organizations rely more on digital scheduling, this vector poses a significant threat to corporate security and credential protection.
Barracuda researchers are warning organisations to treat calendar invitations as a phishing risk, as attackers increasingly abuse iCalendar (.ics) files to bypass controls that focus primarily on email bodies and traditional attachments.
In an analysis by Associate Threat Analyst Soundharya Bharani Poomalai, Barracuda said malicious calendar events can carry phishing links, QR codes and business-themed lures designed to direct recipients to credential-harvesting pages, including through adversary-in-the-middle (AiTM) phishing platforms.
The company said the approach works in part because calendars are now used for more than meetings, including reminders for training, compliance activities and corporate announcements, making non-meeting invitations appear routine. Barracuda also noted that calendar entries may be added automatically with little user interaction, can persist even if the original email is deleted or quarantined, and are commonly handled on mobile devices where some desktop-focused controls have limited visibility.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in