---
title: "Calendar Ransomware: Malicious Meeting Invites | StartCloud"
description: "How attackers plant fake meeting invites in business calendars, how the links inside lead to ransomware, and the settings and habits that stop it."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": [
        "LocalBusiness",
        "ProfessionalService"
      ],
      "@id": "https://startcloud.au/#business",
      "name": "StartCloud",
      "legalName": "Start Technologies Pty Ltd",
      "alternateName": "StartCloud Australia",
      "identifier": {
        "@type": "PropertyValue",
        "propertyID": "ABN",
        "value": "17 676 121 449"
      },
      "slogan": "Go Beyond",
      "description": "StartCloud is Perth's cybersecurity-first AI MSP: managed IT, Essential Eight security, Microsoft 365 and cloud, networking, and practical AI for Australian businesses with 5 to 50 staff.",
      "url": "https://startcloud.au",
      "logo": "https://startcloud.au/og-image.png",
      "image": "https://startcloud.au/og-image.png",
      "telephone": "+61862850001",
      "email": "web@startcloud.com.au",
      "priceRange": "$$",
      "currenciesAccepted": "AUD",
      "paymentAccepted": "Invoice",
      "foundingDate": "2023",
      "contactPoint": {
        "@type": "ContactPoint",
        "telephone": "+61862850001",
        "contactType": "customer service",
        "areaServed": "AU",
        "availableLanguage": "English"
      },
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "Ground Floor West, 6 Gibberd Road",
        "addressLocality": "Balcatta",
        "addressRegion": "WA",
        "postalCode": "6021",
        "addressCountry": "AU"
      },
      "geo": {
        "@type": "GeoCoordinates",
        "latitude": -31.8648813,
        "longitude": 115.8095638
      },
      "openingHoursSpecification": [
        {
          "@type": "OpeningHoursSpecification",
          "dayOfWeek": [
            "Monday",
            "Tuesday",
            "Wednesday",
            "Thursday",
            "Friday"
          ],
          "opens": "07:00",
          "closes": "16:30",
          "description": "General support hours"
        },
        {
          "@type": "OpeningHoursSpecification",
          "dayOfWeek": [
            "Monday",
            "Tuesday",
            "Wednesday",
            "Thursday",
            "Friday",
            "Saturday",
            "Sunday"
          ],
          "opens": "00:00",
          "closes": "23:59",
          "description": "Security Operations Centre (SOC) with 24/7/365 threat monitoring"
        }
      ],
      "areaServed": [
        {
          "@type": "City",
          "name": "Perth"
        },
        {
          "@type": "State",
          "name": "Western Australia"
        },
        {
          "@type": "Country",
          "name": "Australia"
        }
      ],
      "serviceArea": {
        "@type": "GeoCircle",
        "geoMidpoint": {
          "@type": "GeoCoordinates",
          "latitude": -31.8648813,
          "longitude": 115.8095638
        },
        "geoRadius": "50000"
      },
      "knowsAbout": [
        "Cybersecurity",
        "Managed Security Services",
        "Essential Eight",
        "Microsoft 365",
        "Microsoft Azure",
        "IT Support",
        "Network Security",
        "Disaster Recovery",
        "Compliance Management",
        "Microsoft Copilot",
        "AI Readiness",
        "AI Governance",
        "AI Agent Development"
      ],
      "hasOfferCatalog": {
        "@type": "OfferCatalog",
        "name": "IT and Cybersecurity Services",
        "itemListElement": [
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Cybersecurity Services",
              "url": "https://startcloud.au/cybersecurity"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Managed IT Services and Support",
              "url": "https://startcloud.au/technology"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Microsoft 365 and Cloud Solutions",
              "url": "https://startcloud.au/cloud"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Managed Networking",
              "url": "https://startcloud.au/networking"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "AI and Automation",
              "url": "https://startcloud.au/ai"
            }
          }
        ]
      },
      "sameAs": [
        "https://www.linkedin.com/company/startcloudau",
        "https://www.facebook.com/startcloudaus/",
        "https://www.cloudtango.net/providers/12375/startcloud",
        "https://clutch.co/profile/startcloud",
        "https://abr.business.gov.au/ABN/View?abn=17676121449",
        "https://www.yellowpages.com.au/balcatta-wa/bpp/startcloud-581735301",
        "https://www.truelocal.com.au/balcatta-wa/tlp/startcloud-581735301",
        "https://www.google.com/maps/place/StartCloud/@-31.8648767,115.8069889,739m/data=!3m2!1e3!4b1!4m6!3m5!1s0x2a32a5b5d9e864b5:0x9f02690968f0e50c!8m2!3d-31.8648813!4d115.8095638!16s%2Fg%2F11vzbgtytj"
      ]
    },
    [
      {
        "@context": "https://schema.org",
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://startcloud.au/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Resources",
            "item": "https://startcloud.au/resources"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Deep Dives",
            "item": "https://startcloud.au/resources/deep-dives"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Calendar Ransomware",
            "item": "https://startcloud.au/resources/deep-dives/calendar-ransomware"
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "FAQPage",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "A meeting I never accepted has appeared in my calendar. What should I do?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Do not click any links in it and do not decline it, because declining sends a reply that tells the attacker your address is real. Report it as phishing if your mail client allows, then delete the event. If you already clicked a link or entered your password, tell your IT provider immediately so they can reset the account and check for suspicious sign-ins."
            }
          },
          {
            "@type": "Question",
            "name": "Can a calendar invite really install ransomware?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Not by itself. The invite is the lure, not the payload. The danger is the link or QR code inside it, which leads to a fake login page that steals your credentials or a download that gives the attacker remote access. Either one is the foothold a ransomware attack starts from."
            }
          },
          {
            "@type": "Question",
            "name": "Why don't spam filters catch malicious invites?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Calendar invite files (.ics) are plain text, and receiving invites from people outside your business is completely normal, so many email filters give them an easy ride. Worse, some calendars process the invite and create the event even if the email itself is never opened, so the lure lands in your diary regardless."
            }
          },
          {
            "@type": "Question",
            "name": "How do I stop invites adding themselves to my calendar?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Both Outlook and Google Calendar have settings to only add invitations from known senders, or only after you accept. In a business, these settings are best applied centrally so every staff member is covered, which is something your IT provider can do in minutes."
            }
          },
          {
            "@type": "Question",
            "name": "Do the usual defences still work against this?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes. Phishing-resistant multi-factor authentication, patching, endpoint detection and tested backups all still apply. Calendar invites are a new front door for the same attack, so the same layered basics that beat email phishing beat this too."
            }
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "WebPage",
        "url": "https://startcloud.au/resources/deep-dives/calendar-ransomware",
        "speakable": {
          "@type": "SpeakableSpecification",
          "cssSelector": [
            ".deep-dive-question",
            ".deep-dive-answer"
          ]
        }
      },
      {
        "@context": "https://schema.org",
        "@type": "BlogPosting",
        "headline": "Calendar ransomware: the meeting invite you shouldn't trust",
        "description": "How attackers plant fake meeting invites in business calendars, how that leads to ransomware, and the settings and habits that stop it.",
        "author": {
          "@type": "Organization",
          "name": "StartCloud",
          "url": "https://startcloud.au"
        },
        "publisher": {
          "@type": "Organization",
          "name": "StartCloud",
          "url": "https://startcloud.au",
          "logo": {
            "@type": "ImageObject",
            "url": "https://startcloud.au/startcloud-logo.png"
          }
        },
        "datePublished": "2026-07-14",
        "dateModified": "2026-08-13",
        "image": "https://startcloud.au/og-image.png",
        "inLanguage": "en-AU",
        "isAccessibleForFree": true,
        "timeRequired": "PT7M",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://startcloud.au/resources/deep-dives/calendar-ransomware"
        },
        "about": {
          "@type": "Thing",
          "name": "Calendar Ransomware"
        }
      }
    ]
  ]
---

[![StartCloud](/assets/StartCloud-Logo-ByZE1kzP.svg "StartCloud: Cybersecurity-First Managed IT Services Perth")](/ "StartCloud | Managed IT Services Perth")

-   Cybersecurity
-   AI Solutions
-   Cloud
-   Technology
-   Networking
-   Explore

[Contact Us](/contact "Contact StartCloud, Perth IT Support")

Open menu 

Overview 

Short Answer 

Short Version 

What It Is 

How It Unfolds 

Why It Slips Through 

How to Defend 

Verdict 

FAQs 

Related 

A plain-English deep dive into calendar ransomware and calendar invite phishing for small and mid-sized businesses. Explains how attackers abuse calendar invite files (.ics) to plant fake meetings directly into staff calendars, often with no click required, how the links and QR codes inside lead to credential theft or malware that opens the door to ransomware, why these invites slip past email filters, and the calendar settings, habits, MFA, and monitoring that shut the vector down.

[Home](/)[Resources](/resources)[Deep Dives](/resources/deep-dives)Calendar Ransomware 

Threat Guide Deep Dive

The attack hiding in your diary

# Calendar ransomware: the meeting invite you shouldn't trust 

A meeting appears in your diary. You never accepted it, but there it is, reminder set and counting down. Calendar invites have become one of the fastest-growing ways attackers get that first click, and a first click is all ransomware needs.

StartCloud Published 14 July 2026 Last updated 13 August 2026 7 min read 

The short answer 

## Can you get ransomware from a calendar invite?

A calendar invite cannot encrypt your files on its own, but it is an effective delivery route for the phishing link or attachment that starts the attack, and because many mail systems add invites to your calendar automatically the malicious entry can appear without you ever opening the email.

StartCloud's verdict:  A new front door for the same attack, and the same basics beat it

The short version 

## The short version

**Attackers send calendar invite files that many calendars add automatically, no click needed.** The fake meeting sits in your diary looking legitimate, and its reminders keep resurfacing the lure.

**The invite itself does not encrypt anything.** The link or QR code inside it leads to a fake login page or a malicious download, and that stolen account or foothold is where the ransomware attack starts.

The fix is refreshingly boring: calendar settings that stop unknown invites auto-adding, staff who treat invite links like email links, MFA with conditional access, and monitoring for when someone clicks anyway.

The threat 

## What calendar ransomware actually is

Calendar ransomware is not a new strain of malware. It is a new delivery route for the same old attack: phishing that arrives as a meeting invite instead of an email. Attackers craft calendar invite files (the .ics format every calendar app understands) and send them out looking like Teams meetings, payroll briefings, or urgent admin alerts.

Here is the part that surprises most people. Depending on how your calendar is configured, that invite can add itself to your diary as a tentative event without you opening the email, let alone accepting anything. Delete the email and the event can still sit there. Then the reminders start firing, ten minutes before the fake meeting, putting the attacker's link in front of you again and again through an interface you trust completely: your own calendar.

We covered how ransomware behaves once it is inside in our [ransomware deep dive](/resources/deep-dives/ransomware-how-it-works). This is about the front door, because the invite in your diary is step one of that same playbook.

1 Reminder 

### Payroll Update: Action Required

Tentative 1 

Today, 2:30 PM - 3:00 PM

IT Service Desk <servicedesk@m365-security-check.com> 2 

Reminder: 10 minutes before

Join meeting 

https://m365-verify.login-check.com/join?u=you 3 

Accept Tentative Decline 

A mock-up of a typical malicious invite, the kind that appears in Outlook or Google Calendar on its own. Three tells, all easy to miss at 2:20 on a busy afternoon.

-   1 The event added itself as 'Tentative'. Nobody accepted anything. 
-   2 The organiser's domain is not your company, and it is not Microsoft either. 
-   3 The 'join' link goes nowhere near teams.microsoft.com. 

The attack 

## How the attack unfolds

The sequence is simple. An invite lands and slides into your calendar. A reminder pops up. You click the meeting link, or scan the QR code, because that is what you do a dozen times a week. What loads is not a meeting: it is a fake Microsoft 365 sign-in page, sometimes already pre-filled with your email address, or a download pretending to be a meeting client.

The nastier versions proxy your real login behind the scenes, so the page works exactly as expected while the attacker captures your password and your signed-in session. Done that way, even an account with MFA turned on can be hijacked. From there it is the standard ransomware playbook: look around, find the backups, spread, encrypt, extort.

### Fake meeting links

A 'Join meeting' link that looks like Teams or Zoom but leads to a fake login page, or a download dressed up as a meeting app.

### QR codes in invites

A QR code moves you to your phone, away from your company's security tools, and onto a sign-in page already pre-filled with your email address.

### Urgent 'admin' events

Payroll updates, policy reviews, missed voicemails. Anything that makes a calendar reminder feel routine and worth clicking.

The blind spot 

## Why it slips past your filters

Email security spent years learning to distrust attachments and links. Calendar files snuck under that radar. An .ics file is plain text, invites from outside your business are perfectly normal, and plenty of filters wave them through with barely a look. Some campaigns never even need the email to be read, because the calendar processes the invite on its own.

**The reminder is the weapon.** A phishing email gets one chance in a crowded inbox. A calendar event gets a dedicated pop-up, delivered by your own device at a moment you are primed to click "join". That is why this vector converts so well for attackers.

There is one more trap worth knowing: declining the invite feels like the polite fix, but a decline sends a response straight back to the attacker, confirming your address is real and actively used. That puts you on the list for the next round.

The defence 

## How to shut it down

None of this requires new tools you have never heard of. It is a settings change, a habit, and the same layered controls that stop the rest of the phishing family.

### Tighten calendar settings

Outlook and Google Calendar can both be set to only add events from people you know, or after you respond. Your IT provider can enforce this across the whole business.

### Delete and report, never decline

Declining sends a reply that confirms your address is live and watched. Report the invite as phishing and remove it instead.

### MFA and conditional access

Strong MFA and conditional access limit what a stolen password, or even a stolen session, can actually do with your account.

### Email security and monitoring

Modern email security inspects calendar files, not just attachments and links. EDR and a monitored SOC catch the follow-on activity when someone clicks anyway.

The account takeover side of this, and why MFA plus conditional access matters so much, is covered in our deep dive on [MFA and business email compromise](/resources/mfa-business-email-compromise). And if a click does turn into something worse, tested backups are what turn a crisis into a recovery, which we unpack in [business continuity and disaster recovery](/resources/business-continuity-disaster-recovery).

Verdict 

## The takeaway

Calendar ransomware is not a new kind of ransomware. It is a new front door for the same attack, chosen because your calendar is the one place you never expect to be lied to. Close the door with sensible calendar settings, teach your team that an unexpected invite deserves the same suspicion as an unexpected link, and keep the layers behind it strong.

Getting those settings enforced across every mailbox, and having someone actually watching for the sign-in that should not be there, is exactly what our [managed security service](/cybersecurity/mssp) does. If a strange meeting has already shown up in someone's diary, that conversation is worth having today rather than after the reminder fires.

[Explore managed cybersecurity](/cybersecurity-perth)[Try the free Essential Eight checklist](/cybersecurity/essential-eight-checklist)

Common questions 

## Calendar Ransomware: the questions we get asked

### A meeting I never accepted has appeared in my calendar. What should I do? 

Do not click any links in it and do not decline it, because declining sends a reply that tells the attacker your address is real. Report it as phishing if your mail client allows, then delete the event. If you already clicked a link or entered your password, tell your IT provider immediately so they can reset the account and check for suspicious sign-ins.

### Can a calendar invite really install ransomware? 

Not by itself. The invite is the lure, not the payload. The danger is the link or QR code inside it, which leads to a fake login page that steals your credentials or a download that gives the attacker remote access. Either one is the foothold a ransomware attack starts from.

### Why don't spam filters catch malicious invites? 

Calendar invite files (.ics) are plain text, and receiving invites from people outside your business is completely normal, so many email filters give them an easy ride. Worse, some calendars process the invite and create the event even if the email itself is never opened, so the lure lands in your diary regardless.

### How do I stop invites adding themselves to my calendar? 

Both Outlook and Google Calendar have settings to only add invitations from known senders, or only after you accept. In a business, these settings are best applied centrally so every staff member is covered, which is something your IT provider can do in minutes.

### Do the usual defences still work against this? 

Yes. Phishing-resistant multi-factor authentication, patching, endpoint detection and tested backups all still apply. Calendar invites are a new front door for the same attack, so the same layered basics that beat email phishing beat this too.

Keep reading 

## Related pages

[

Deep dive 

### Ransomware: How It Works

What happens after the click: how ransomware spreads, and how to survive it.

Guide





](/resources/deep-dives/ransomware-how-it-works)[

Deep dive 

### MFA & Email Compromise

The account takeovers these invites are fishing for, and the controls that stop them.

Guide





](/resources/mfa-business-email-compromise)[

Deep dive 

### What a SOC Does

The 'someone actually watching' layer that catches the click you didn't see.

Guide





](/resources/deep-dives/what-is-a-soc)

![StartCloud](/assets/StartCloud-Logo-ByZE1kzP.svg "StartCloud: Cybersecurity-First Managed IT Services Perth")

Cybersecurity-led IT for Australian businesses. We manage security, compliance, and modern IT environments, so risk is governed, not guessed.

Ground Floor West, 6 Gibberd Road, Balcatta WA 6021 

[08 6285 0001](tel:+61862850001 "Call StartCloud on 08 6285 0001")

Serving Perth businesses from Balcatta, Western Australia.

![Microsoft Solutions Partner - Modern Work](/assets/microsoft-solutions-partner-DqvNMv91.png "Microsoft Solutions Partner: Modern Work")

### Services

-   [Cybersecurity](/cybersecurity "Cybersecurity Services Perth | StartCloud")
-   [AI Solutions](/ai "AI & Automation Services Perth | StartCloud")
-   [Cloud](/cloud "Cloud Services Perth | StartCloud")
-   [Technology](/technology "IT Services and Support | StartCloud")
-   [Networking](/networking "Business Networking Perth | StartCloud")
-   [Packages](/packages "IT Support Packages Perth | StartCloud")

### Company

-   [About](/about "About StartCloud, Perth IT Support Team")
-   [Company Facts](/facts "StartCloud Company Facts | Perth Cybersecurity-First AI MSP")
-   [Resources](/resources "IT Resources & Guides | StartCloud Perth")
-   [Service Areas](/it-support-perth "IT Support Perth | StartCloud")
-   [Contact](/contact "Contact StartCloud, Perth IT Support")

### Locations

-   [All Service Areas](/locations "Perth IT Support Areas | StartCloud")
-   [IT Support Perth](/it-support-perth "IT Support Perth | StartCloud")
-   [Cybersecurity Perth](/cybersecurity-perth "Cybersecurity Perth | StartCloud")
-   [MSP Perth](/managed-service-provider-perth "Managed Service Provider Perth | StartCloud")
-   [Industries We Serve](/industries "IT Support by Industry Perth | StartCloud")

© 2026 Start Technologies Pty Ltd trading as StartCloud. All rights reserved.

ABN 17 676 121 449

[](https://www.linkedin.com/company/startcloudau "StartCloud on LinkedIn")[](https://www.facebook.com/startcloudaus/ "StartCloud on Facebook")[](https://www.google.com/maps/place/StartCloud/@-31.8648767,115.8069889,739m/data=!3m2!1e3!4b1!4m6!3m5!1s0x2a32a5b5d9e864b5:0x9f02690968f0e50c!8m2!3d-31.8648813!4d115.8095638!16s%2Fg%2F11vzbgtytj "StartCloud on Google")

[Terms of Service](/terms-of-service "Terms of Service | StartCloud")| [Privacy Policy](/privacy-policy "Privacy Policy | StartCloud")| [Modern Slavery Policy](/modern-slavery-policy "Modern Slavery Policy | StartCloud")| [Cookie Policy](/cookie-policy "Cookie Policy | StartCloud")

StartCloud Assistant

Online

G'day! 👋 I'm the StartCloud Assistant. How can I help you today?

Tell me about your servicesBook a discovery callI need IT support

Find Your Solution