March 10, 2026
Scamming via Google Calendar increasing
Denison Security
Denison’s cybersecurity intelligence has observed a threat actor that we now track as TANGERINECRAB attempting to steal money and financial information from victims.
This scamming technique sends a Google Calendar invitation directly to your calendar, which bypasses email spam filters. By default, Google automatically adds calendar invites directly to your calendar. The attackers’ invitations appear genuine alongside your real events, classes, and meetings.
The invitation sent in an email message as a part of the calendar event creation is automatically remediated using advanced email security tools. However, these tools are unable to remove the calendar invites themselves.
What should I do if I get a malicious Google Calendar invite?
- Select “Report as spam” in Google Calendar to report the event.
- Do not click “Accept” or “Decline.” This encourages the attacker to try again.
- Do not click links, call phone numbers, or reply to a suspicious event.
What is the attack mechanism itself?
In short, attackers disguise their lure as a harmless calendar event to increase the likelihood you will interact with it. The attacker’s goal is to get you to contact them, where the real attack occurs. They are known to carry out so-called “refund scams.”
A refund scam is a fraudulent scheme where someone deceives you into sending money to them, often under false pretenses of a refund. The scammer will create a situation where they appear to be a legitimate business or entity, and then manipulate you into sending them money with the promise of a refund. The goal is for the scammer to steal your money, and they often use sophisticated tactics to make their scheme seem credible.