lab5280
JournalCybersecurityCalendar scam

The fake voicemail on your Google Calendar: a phishing scam that skips your inbox

An event you never accepted appears on your schedule: "Missed voice message." It passed every spam filter, because Google itself delivered it.

Lab 5280 — Denver, CO
The short version

Scammers send calendar invites instead of emails. Because the notification comes from Google's own servers, it passes the checks spam filters rely on, and the event can land directly on your calendar. The fix takes two minutes: in Google Calendar settings, make sure "Add invitations to my calendar" is set to "Only if the sender is known", never click or RSVP to a suspicious event, and use Report as spam to remove it.

Google Calendar phishing is the rare scam that doesn't need you to open an email. A fake event simply appears in your schedule, often titled something like a missed voice message, an unpaid invoice, or an expiring password, with a link or a phone number in the description. For the many small offices across Denver, Boulder and Arvada that run on Google Workspace, the calendar is a place people trust by reflex: if it's on the schedule, it must be real. That reflex is exactly what this scam rents.

Why calendar invites sail past your spam filter

When anyone invites you to an event, the notification is generated and sent by Google Calendar itself. Researchers at the security firm Check Point documented a campaign of more than 4,000 of these phishing invites hitting about 300 organizations in four weeks, and showed that the messages passed all three standard email authentication checks (SPF, DKIM and DMARC — the tests that confirm a message really came from the server it claims). They did come from Google, so the tests pass, and the invite lands looking as legitimate as a meeting request from a client.

The links inside are dressed up the same way. In the campaigns Check Point analyzed, the event linked first to a legitimate Google service, such as a Google Forms or Google Drawings page, and only from there to the actual credential-stealing site, often behind a button disguised as a security check. So the first thing you'd hover over looks safe.

The voicemail version, and its cousins

The variant making the rounds now is a calendar event styled like a voicemail notification: a "voice message received" title, a plausible duration, and a play button or link. Fake missed-voicemail lures have been used for years to steal Google account passwords; moving them into the calendar just gives them a more trusted delivery route. Security teams have also catalogued the other common costumes:

One more trap worth naming: responding at all. Clicking Yes, No or even Maybe on a scam invite tells the sender your address is active and watched, which earns you a spot on better-targeted lists. The same logic applies to fake invoices by email, which we covered in our guide to business email compromise: never use a phone number or link the scammer supplied.

Google quietly fixed the default. Check yours anyway.

For years, Google Calendar's default was to add every invitation to your calendar automatically, whoever sent it. That's the setting this scam fed on. As of December 1, 2025, Google changed the default for new invitations to "Only if the sender is known": events are only auto-added when the sender is in your contacts, in your organization, or someone you've emailed before. Anything else arrives as an email only, and is added to your calendar just when you choose.

So why is this still worth your attention?

A ten-minute checkup for your office

  1. Check the setting on every account. In Google Calendar on a computer: gear icon → Settings → under General, Event settings → Add invitations to my calendar → choose "Only if the sender is known" (or the stricter "When I respond to the invitation in email").
  2. Workspace admins: set it company-wide. Google added admin controls in 2026 so the invitation behavior can be managed centrally from the Admin console instead of user by user.
  3. Teach the one rule: don't touch suspicious events. No links, no listed phone numbers, no Yes/No/Maybe.
  4. Report, then it's gone. Open the event, click the three-dot More actions menu, choose Report as spam. Reporting removes the event (the whole series, if it repeats) and helps Google catch the sender.
  5. Verify voicemails where voicemails actually live. A real missed message shows up in your phone system or voice app. Open that app directly; never "listen" through a calendar invite.

The habit behind the fix

Every version of this scam, the calendar voicemail, the fake invoice, the urgent password alert, works by moving you onto the scammer's path: their link, their phone number, their sign-in page. The counter-habit is to always travel your own path: your voicemail app, your vendor's number on file, typing the site address yourself. That habit is free, and it beats most of what lands this year.

At Lab 5280 we spend our days automating how Front Range businesses run, and we work with your team, not just for you — which includes setting sane defaults like this one across your Google Workspace or Microsoft 365 accounts while we're in there, so the safe way is the path of least resistance.

Want your calendar and email defaults checked?

We'll review the settings that let scams like this through — calendar invites, mail forwarding rules, multi-factor authentication — across your whole office, with you on the call.

Talk to Lab 5280