{"id":422710,"date":"2026-10-04T03:50:12","date_gmt":"2026-10-04T03:50:12","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=422710"},"modified":"2026-10-04T03:50:12","modified_gmt":"2026-10-04T03:50:12","slug":"calendar-booking-phishing-scam-coworker-forward","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/calendar-booking-phishing-scam-coworker-forward\/","title":{"rendered":"Calendar Booking Phishing Scam: How a Coworker&#8217;s Forward Builds False Trust"},"content":{"rendered":"<p>A potential customer wants to book a meeting. Their message reaches sales through a coworker who simply forwarded it to the right person.<\/p><div id=\"mwtad3198572639\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That sounds like an ordinary workday handoff. The trouble begins when the booking process asks the salesperson to take one more step.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-422711 lazyload\" alt=\"Illustrative reconstruction of a colleague forwarding a meeting request, not an actual campaign email\" title=\"\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-hero.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-hero.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-hero-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-hero-1024x683.png 1024w\"><\/figure>\n<div id=\"mwtad1715941358\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The lure arrives with an internal recommendation<\/h3>\n<p>Fortra reported a calendar-booking phishing attempt that used a real coworker&#8217;s forward to make an external prospect&#8217;s link feel safer.<\/p><div id=\"mwtad4041968089\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The attacker first contacted someone outside the sales team. That employee was asked to pass a meeting request to the right salesperson.<\/p>\n<p>By the time the salesperson received it, the message had an ordinary internal wrapper: a familiar colleague and a plausible request for customer contact.<\/p>\n<h3>The dangerous step is not the meeting itself<\/h3>\n<p>The recipient was directed to a booking page. After selecting a time, the page presented a Microsoft 365-style work or school sign-in prompt.<\/p><div id=\"mwtad491478297\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Fortra described that prompt as consistent with credential harvesting. Its public account documents an attempted phishing chain, not a confirmed loss of credentials by a named victim.<\/p>\n<p>The case is not evidence that legitimate calendar services are unsafe. It shows how an external booking flow can be used to make a login demand seem routine.<\/p>\n<h3>What an employee should do<\/h3>\n<p>Verify the prospect and destination before entering work credentials. A coworker forwarding a request does not automatically approve every link inside it.<\/p><div id=\"mwtad2742742419\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ul>\n<li>Confirm the meeting request through the prospect&#8217;s independently found business contact.<\/li>\n<li>Inspect the complete booking and sign-in addresses before using them.<\/li>\n<li>Report a surprise work-account login after selecting a time.<\/li>\n<li>Use your organization&#8217;s established scheduling tool when possible.<\/li>\n<\/ul>\n<p>Microsoft and the coworker are not the perpetrators in this scenario. Their familiarity is what the attacker tried to borrow.<\/p>\n<div id=\"mwtad2240577216\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why an Internal Forward Changes the Reader&#8217;s Judgment<\/h2>\n<p>Many security warnings teach people to distrust unexpected external email. This attempt bends that rule by adding a trusted internal person to the delivery path.<\/p>\n<div id=\"mwtad3519449047\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The first recipient may not work in sales. Passing a customer inquiry along can feel helpful, even responsible, particularly when the request seems relevant to the business.<\/p>\n<p>The coworker may add a line such as \u201cCan you handle this?\u201d That line is genuine, but it does not validate the stranger&#8217;s original link.<\/p>\n<p>When the salesperson scans the thread, the familiar internal sender is more salient than the external origin buried below. That is the trust-chain mistake.<\/p>\n<div id=\"mwtad3915162465\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>This is not the same as a compromised employee account. Fortra&#8217;s observed route used an ordinary forward as part of the social engineering.<\/p>\n<p>The distinction matters. You cannot solve it only by checking whether the internal coworker&#8217;s account is real. You must inspect the request they passed along.<\/p>\n<p>A legitimate prospect might also use a third-party scheduler. The warning arises when an unverified booking flow suddenly demands corporate credentials.<\/p>\n<div id=\"mwtad3752571434\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Calendar Booking Phishing Scam Works<\/h2>\n<h3>Step 1: The attacker chooses an employee likely to redirect the request<\/h3>\n<div id=\"mwtad817704347\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Instead of emailing the target salesperson directly, the supposed prospect contacts another employee and asks for an introduction or internal forward.<\/p>\n<p>That recipient may have no reason to inspect the booking link closely. They are not the person who will attend the meeting.<\/p>\n<p>The attacker gains a clean-looking handoff. The forwarding employee supplies a legitimate internal address and may supply their own helpful context.<\/p>\n<p>Nothing about the coworker&#8217;s good intentions makes the original meeting request genuine. The attacker controls the content that is forwarded.<\/p>\n<h3>Step 2: The salesperson receives an ordinary work request<\/h3>\n<p>Sales teams deal with meetings constantly. A possible new customer can be important enough that declining or delaying feels costly.<\/p>\n<p>The forwarded message appears in the same inbox as normal introductions. That familiarity can lower the attention given to the original sender and URL.<\/p>\n<p>The lure does not need an outrageous promise. It only needs the salesperson to do what they already do, book a conversation.<\/p>\n<p>A calendar invitation and a booking-page link are different. In the observed case, the user was invited into a page-controlled booking sequence.<\/p>\n<h3>Step 3: The booking page asks for a time slot<\/h3>\n<p>Selecting a date and time is plausible. It encourages the visitor to invest a little effort before any suspicious demand appears.<\/p>\n<p>The page&#8217;s schedule layout helps establish a normal rhythm: choose a slot, review availability, then confirm. The visitor may already feel committed.<\/p>\n<p>This design can postpone skepticism. A sign-in request that would look strange at the start may seem like a final administrative step afterward.<\/p>\n<p>A calendar design is easy to imitate. Its presence does not authenticate the organizer, the domain, or the next page.<\/p>\n<h3>Step 4: A work or school login appears<\/h3>\n<p>Fortra reported that the flow led to a Microsoft 365-style sign-in after a slot was chosen. That is the moment to stop.<\/p>\n<p>A business email address is often needed to receive a meeting confirmation. A full corporate password is a very different request.<\/p>\n<p>Single sign-on can be legitimate, but only when the organization has approved the service and the sign-in occurs at the authentic identity provider.<\/p>\n<p>If the link is unfamiliar, contact IT or the prospect independently. Do not test the form with your real password to see whether it works.<\/p>\n<h3>Step 5: A submitted password can expose the wider workplace<\/h3>\n<p>If the page captures credentials, the potential impact reaches beyond one calendar appointment. A work account may connect to mail, documents, chats, and customer records.<\/p>\n<p>Multi-factor authentication helps but is not a reason to ignore a submitted password. Attackers may try repeated prompts or other follow-up tricks.<\/p>\n<p>Fortra&#8217;s description supports a credential-harvesting assessment. It does not establish that any specific target completed the sign-in or that an account was compromised.<\/p>\n<p>Incident response should be based on what the employee actually entered and what the organization&#8217;s sign-in logs show.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-422712 lazyload\" alt=\"Illustrative booking page followed by a work-account sign-in prompt, not a screenshot of the observed site\" title=\"\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-detail.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-detail.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-detail-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/calphish-detail-1024x683.png 1024w\"><\/figure>\n<div id=\"mwtad1987586167\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check the Meeting Request Without Losing the Lead<\/h2>\n<p>Security and customer service are not competing goals. A real prospect will generally accept a brief verification or an alternative scheduling method.<\/p>\n<p>Start by reading the original external message, not only the coworker&#8217;s forwarding note. Look at the sender&#8217;s organization, context, and exact ask.<\/p>\n<p>Search for the prospect&#8217;s company through a known channel. If there is a public business number, call and ask whether the meeting request came from them.<\/p>\n<p>Use contact details you find independently. A signature inside the suspicious email is part of the unverified material.<\/p>\n<p>Offer your company&#8217;s normal meeting link instead. A real interested buyer can choose a time there without requiring you to sign into their unfamiliar page.<\/p>\n<p>If your organization approves a particular scheduling service, open that service from your own bookmark or app. Do not assume a cloned login is genuine.<\/p>\n<p>Tell the forwarding coworker what you found, without criticizing them. They may help identify other recipients who received the same request.<\/p>\n<div id=\"mwtad159014177\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Signs That the Login Is Out of Place<\/h2>\n<p>The strongest clue is the context. You are scheduling a meeting with an outside party, yet a page asks for your employer&#8217;s sign-in credentials.<\/p>\n<ul>\n<li>The login appears only after you choose a time, rather than through your organization&#8217;s normal sign-in route.<\/li>\n<li>The domain is unfamiliar or slightly different from the service it imitates.<\/li>\n<li>The page claims Microsoft branding but is not hosted on an authentic Microsoft sign-in destination.<\/li>\n<li>The meeting prospect cannot be confirmed through independent business contact.<\/li>\n<li>The coworker forwarded the request without personally verifying the external link.<\/li>\n<\/ul>\n<p>None of these observations proves that every external scheduler is fraudulent. Together, they justify stopping before entering a password.<\/p>\n<p>If you are unsure how to judge a Microsoft sign-in page, ask IT. They can inspect the link without requiring you to take the risk.<\/p>\n<div id=\"mwtad576932832\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>If you clicked but entered no credentials, report the link.<\/strong> Give IT the complete forwarded thread and page address. Do not revisit the site just to capture another screenshot.<\/li>\n<li><strong>If you typed a password, change it immediately through your organization&#8217;s normal sign-in route.<\/strong> Tell the security team you may have entered it into a fake page.<\/li>\n<li><strong>If you approved a sign-in prompt or shared a code, say so explicitly.<\/strong> Security staff need that detail to investigate sessions and revoke access quickly.<\/li>\n<li><strong>Ask IT to review sign-in logs and active sessions.<\/strong> They can look for unusual locations, devices, mailbox rules, app grants, or messages sent from the account.<\/li>\n<li><strong>Check related work and personal accounts carefully.<\/strong> Change reused passwords anywhere else, but do so from a clean, trusted device and a known service address.<\/li>\n<li><strong>Report any download or unexpected extension.<\/strong> A credential lure does not automatically mean malware, yet extra files change the response. Use an approved scanner or Malwarebytes when relevant.<\/li>\n<li><strong>Preserve the original chain.<\/strong> Keep the prospect&#8217;s message, coworker&#8217;s forward, booking URL, screenshots, and the time you submitted any data.<\/li>\n<li><strong>Warn others through your security team.<\/strong> They can identify similar forwards and block destinations. AdGuard may reduce exposure to some malicious links, but account recovery remains essential.<\/li>\n<\/ol>\n<div id=\"mwtad2624402280\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Managers and Teams Can Learn From This Attempt<\/h2>\n<p>A rule saying \u201ctrust internal mail\u201d is too broad. Internal employees can honestly pass along unverified outside material.<\/p>\n<p>Give staff a simple way to forward prospective leads without endorsing links. A short note such as \u201cexternal request, not verified\u201d can preserve context.<\/p>\n<p>Sales teams should know which scheduling tools the company approves. That lets an employee offer a safe alternative without losing a potential customer.<\/p>\n<p>Training should include the moment after a time slot is chosen. That is when a person may be least inclined to abandon the task.<\/p>\n<p>Security teams can also provide a quick link-check channel. A delayed meeting is easier to recover than a compromised work account.<\/p>\n<h2>Three Different Things a Meeting Page Might Ask For<\/h2>\n<p>A booking page may need a name and email address to send an invitation. That is ordinary contact information, although it should still go to a verified prospect.<\/p>\n<p>It may also ask permission to read a calendar. That is a broader request because it can reveal availability or other details, depending on the authorization.<\/p>\n<p>A third possibility is a full work-account sign-in. This gives the visitor a much more consequential decision than simply selecting a meeting time.<\/p>\n<p>The observed phishing attempt blurred those categories. Choosing a slot made the later Microsoft-style prompt appear like routine completion of the booking.<\/p>\n<p>Before entering credentials, check whether your organization actually uses that scheduling provider. A genuine provider may still be the wrong place to enter work credentials.<\/p>\n<p>Read the complete browser address. The phrase \u201cMicrosoft 365\u201d in a heading cannot establish that the login is hosted by Microsoft.<\/p>\n<p>If your organization uses single sign-on, the sign-in should follow its approved identity flow. Security staff can tell you what its normal prompts look like.<\/p>\n<p>Do not rely on the forwarding coworker to make that judgment. They may have seen only the original request and never reached the login screen.<\/p>\n<p>A polite reply to the alleged prospect can preserve the sales opportunity: offer to book through your own company&#8217;s calendar link.<\/p>\n<p>If the prospect refuses any alternative and insists on their particular login page, the pressure itself deserves scrutiny.<\/p>\n<p>Keep the sequence clear when reporting: original external message, internal forward, booking choice, and login prompt. Each stage explains the next.<\/p>\n<p>This specificity helps prevent an overreaction. The lesson is not to reject all meeting invitations; it is to keep external links from inheriting internal trust.<\/p>\n<p>Teams can reinforce that distinction in training with a simple question: \u201cWho selected this page, and who actually controls it?\u201d<\/p>\n<p>That question remains useful even when the person who handed you the link is a genuine colleague.<\/p>\n<p>It also tells the employee what to verify next. The prospect&#8217;s existence, the booking provider, and the sign-in host are three separate facts.<\/p>\n<p>One confirmed fact does not authenticate the others. A real prospect can have a compromised account, and a real coworker can forward a malicious URL.<\/p>\n<p>If the meeting is valuable, a short phone call or a reply offering your own booking link is usually a reasonable business step.<\/p>\n<p>When IT reviews the case, it can check whether anyone submitted credentials and whether similar prospect messages reached other teams.<\/p>\n<p>The goal is to keep normal business moving while denying the attacker a shortcut into the company&#8217;s identity system.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is a meeting request from a coworker automatically safe?<\/h3>\n<p>No. The coworker may simply be forwarding an unverified external request. Inspect the original sender and booking destination.<\/p>\n<h3>Does this mean our coworker&#8217;s account was hacked?<\/h3>\n<p>Not necessarily. Fortra&#8217;s described path involved a genuine internal forward that the attacker deliberately encouraged.<\/p>\n<h3>Why would booking a meeting require Microsoft 365 login?<\/h3>\n<p>Some approved scheduling tools use organizational sign-in. In this case, the unfamiliar sequence and imitated work login were consistent with credential harvesting.<\/p>\n<h3>Can I safely keep the appointment without using the link?<\/h3>\n<p>Yes. Verify the prospect independently and offer your company&#8217;s approved calendar link or another normal contact method.<\/p>\n<h3>What if I entered my email address but not my password?<\/h3>\n<p>Report what you entered. The address may invite more targeted phishing, but it does not by itself prove your account was accessed.<\/p>\n<h3>Should I delete the forwarded email?<\/h3>\n<p>Report or preserve it first. Your security team may need headers, links, and timestamps to find related messages.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The trick was not merely a fake calendar. It was an outside request laundered through a genuine coworker&#8217;s forward before a work-account sign-in appeared.<\/p>\n<p>Keep the lead if it is real, but verify the person and use an approved scheduling route. If you entered credentials, involve your security team immediately.<\/p>\n<div id=\"mwtad2208795855\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A potential customer wants to book a meeting. Their message reaches sales through a coworker who simply forwarded it to the right person. That sounds like an ordinary workday handoff. The trouble begins when the &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Calendar Booking Phishing Scam: How a Coworker&#8217;s Forward Builds False Trust\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/calendar-booking-phishing-scam-coworker-forward\/#more-422710\" aria-label=\"Read more about Calendar Booking Phishing Scam: How a Coworker&#8217;s Forward Builds False Trust\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":422711,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-422710","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/422710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=422710"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/422710\/revisions"}],"predecessor-version":[{"id":422713,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/422710\/revisions\/422713"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/422711"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=422710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=422710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=422710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}