How it works
The attacker emails a standard calendar invitation to your address. On many phones and webmail setups the default is to add invitations to your calendar automatically, so the event appears and a reminder pops up without you ever accepting anything.
The event title and notes contain urgent text and a link. When you tap it - often from a lock-screen reminder - you land on a page that imitates a bank, parcel service, or login screen and asks for your details or installs something.
Why it works and who is targeted
A calendar feels like your own private space, so an entry there carries an authority that a random email does not. The reminder arrives at an unexpected moment and creates a small jolt of urgency that pushes people to act before they think.
This is sent in bulk to any leaked email address, but it lands hardest with people who live by their calendar and with those less familiar with how invitations can be auto-added. No prior contact with the sender is needed.
Red flags in detail
An event you have no memory of creating, from a sender you do not recognise, is the first sign. The wording is typically urgent and threatening - an account closing today, a payment to confirm, a parcel held - paired with a single link.
Look at who organised the event and where the link actually points: mismatched or random domains, odd sender addresses, and generic greetings all mark it as fake rather than a real appointment.
What to do and how to stay safe
Do not tap any link in an unexpected calendar event. Delete the event, and where the option exists choose to report it as spam or junk rather than simply declining, since declining can confirm your address is active.
In your calendar settings, turn off automatic adding of invitations so new events only appear after you accept them from email. If a message claims to be from your bank or a delivery firm, check by opening their official app or site directly instead.