Scammers are using hacked accounts to send real Google Calendar invitations with dangerous links. A familiar name doesn’t mean an invitation is safe. Before accepting an unexpected invite or clicking anything inside it, confirm with the sender by phone, not by replying to the email. You can further protect yourself by relying on passkey login for your Google account instead of typing your password.
Call the sender instead of replying
A phone call is best; text is another option. Use a number you already have for the person, not one supplied in the invitation. Ask whether they sent it and what it is for.
Don’t reply to the email to ask “Did you send this?” If scammers have taken over the person’s email, you would be asking the scammers instead of the person who got scammed.
What’s different about this scam?

Unlike the fake Punchbowl and Evite invitations I wrote about in July, this example really came through Google Calendar.
Evite and Punchbowl invitations might only arrive occasionally. Google Calendar invitations are part of everyday life for many of us. Whenever you book an appointment with me, you receive one, too. That familiarity conditions us to see them as legitimate, which makes this scam easier to trust.
The screenshot shows an invitation I received from someone I know. It came from their legitimate email address. It was titled “Important Voice message received - kindly listen now.” It had a meeting time, a genuine Google Meet link, and the usual Calendar formatting. Inside, it claimed I had a 41-second Google Voice message, but “Click Here to Listen” pointed to a suspicious website.
What happens if I click the link?
A scam link may open a fake Google sign-in page. If you type your password there, you’re giving it to the scammers. If they get into your account, they can send scam calendar invitations to your contacts using your name. The next person sees a familiar sender, falls for the same trap, and the cycle repeats.
Clicking the link alone doesn’t mean they have your password. Close the page without entering anything. If you already entered a password or approved an unexpected sign-in request, get help securing your account right away.
Why text message and app codes aren’t enough
Text message (SMS) and authenticator-app codes are better than a password alone, but they can still be phished. A fake sign-in page can ask for your password and then your code. The scammer immediately enters both on the real Google site before the code expires.
Passkeys and security keys work differently. Your browser checks which website you’re on, and your device or key proves it’s you. A fake Google page can’t use your Google passkey or security key to sign you in. A scammer on another computer can’t capture them through that page and reuse them like a password or six-digit code.
Use a passkey for Google, and don’t memorize your password
A password you know or a password you type is a password that can be hacked.
A passkey works only on the authentic website it belongs to, so a fake Google login page can’t use your Google passkey. Using a password manager such as Apple Passwords or 1Password will also help because they only autofill when the website address matches.
Any time you have to type or copy and paste your password, you should pause and make sure that you really are on the site you think you are on. So treat your password as a backup, not as your default. If you have a passkey enabled for Google and are using recent software, it’s possible you will never need your password again. For Google Workspace business accounts, that function needs to be enabled by your organization.
For even stronger account security, I encourage you to consider Google’s Advanced Protection Program. Logging in requires a passkey or security key. There are other limitations: certain security methods have minimum OS and browser requirements, some apps need to be approved by Google (Apple Mail is), and recovery is more involved if you lose your passkey. Because of the more involved recovery process, I recommend using a second passkey or a physical security key as a backup. I’ll be writing more about this option soon.
Google Workspace for business owners has another option. You can restrict the second authentication factor to a passkey or a physical security key organization-wide. If you use your own domain with Google, contact me for help setting this up.
Further reading




If you’d like help setting up passkeys, reviewing your Google account’s security, or deciding whether Advanced Protection is right for you, book an appointment. I’ll help you choose protections that work with your devices and apps.


