Apple’s iCloud Calendar service has become the latest target in a wave of sophisticated phishing attacks. Cybercriminals are abusing its invite system to send callback phishing emails disguised as payment notifications, making them appear to come directly from Apple’s own servers. Because these messages pass through official Apple channels, they are far more likely to bypass spam filters and reach unsuspecting users’ inboxes.
One recent example reported to BleepingComputer showed an email styled as a PayPal payment receipt for $599. Within the message, victims were prompted to call a listed phone number if they wanted to query or cancel the payment. The tactic is designed to create urgency, pressuring recipients into making the call and exposing themselves to further manipulation.
This development marks a worrying escalation in phishing methods, moving beyond traditional fake domains or misspelt email addresses and instead exploiting trusted communication platforms.
Why Calendar Invites Make the Attack Effective
Unlike conventional phishing emails, these malicious notifications are embedded within iCloud Calendar invites. This allows them to appear as automated messages from a legitimate Apple address, such as [email protected]. Because they originate from Apple’s infrastructure, they successfully pass critical email authentication checks like SPF, DKIM, and DMARC.
These safeguards are designed to stop fraudulent messages from reaching inboxes, but in this case, they confirm to spam filters that the emails are genuine. For recipients, the result is convincing: the source appears trusted, the formatting looks official, and the calendar delivery method creates an air of legitimacy.
Tim Ward, CEO and co-founder of security company Redflags, explained why this approach is so concerning:
The abuse of iCloud Calendar invites to deliver callback phishing emails disguised as legitimate purchase notifications and sent directly from Apple’s email servers demonstrates the evolving sophistication of social engineering threats in the wild.
By exploiting both human trust and technical validation systems, attackers have engineered a campaign that slips past many traditional lines of defence.
The Social Engineering Behind Callback Phishing
At its core, this phishing campaign is a form of social engineering. Rather than trying to trick victims into clicking malicious links or downloading attachments, it persuades them to dial a phone number under the illusion of resolving an urgent financial matter.
Once on the phone, attackers can apply psychological pressure, requesting sensitive information such as banking details, login credentials, or remote access to the victim’s computer. Because the call is initiated by the target, they may feel more in control and therefore less suspicious, when in reality they have already stepped into the scammer’s trap.
The use of a high-value payment, like the $599 PayPal charge, is no accident. Fraudsters deliberately choose amounts large enough to alarm recipients but not so extreme as to be immediately dismissed as implausible. The sense of urgency encourages quick action, often before the target has taken time to verify the legitimacy of the notification.
Building Resilience Against Phishing Threats
The emergence of calendar-based phishing underlines the need for both technical and human defences. Organisations must ensure email filtering and detection systems are updated to account for new abuse methods that leverage trusted services. However, technology alone cannot provide complete protection.
As Ward noted:
This trend highlights why organisations must stay vigilant and continue empowering users to question unexpected communications (especially those that try to create urgency around suspicious payments or demand direct contact via phone numbers).
For individuals, several practical steps can reduce the risk:
Treat unsolicited calendar invites with caution, especially if they contain payment or security-related content.
Avoid calling phone numbers provided in emails or invites without verifying them independently through official channels.
Report suspicious messages to your IT team, email provider, or Apple directly, rather than simply dismissing them.
Consider adjusting iCloud Calendar settings to block automatic invite additions, reducing exposure to this vector.
Maintaining awareness is critical. Even legitimate-looking notifications should be questioned if they arrive unexpectedly or demand immediate action. Phishing relies heavily on creating a sense of urgency; resisting that pressure is often the best defence.
>> Full story here: https://www.bleepingcomputer.com/news/security/icloud-calendar-abused-to-send-phishing-emails-from-apples-servers/
One of the Editors for Tech on the Go, I love covering mobile tech and social media. I also manage the reviews we cover so all the writers stay on my good side!



