Skip to main content

Op-Ed: Calphishing is challenging how we think about phishing

Article preview on calphishing in healthcare featuring Errol Weiss, Chief Security Officer at Health-ISAC.

Hackers are now taking advantage of employee calendars, making a dangerous threat even greater – particularly for the overworked healthcare sector.

Errol Weiss, Chief Security Officer at Health ISAC | Tue, 28 Jul 2026

While phishing remains the most common and damaging cyber threat, with 3.4 billion phishing emails sent daily, the methods are evolving.

Now, phishing attacks are taking advantage of people’s busy work lives via their calendars.

Called calendar phishing (calphishing), this new kind of social hacking involves delivering malicious content directly into an employee’s calendar, aiming to trick victims into visiting fake login pages, approving authentication requests, or phoning the hackers directly – only to fall for a social engineering scam.

The end goal, as with most kinds of phishing, is to capture login credentials, obtain authenticated access, or steal money directly from the victim. Some clever campaigns of this sort also target session tokens – the credentials that maintain a user’s logged-in state – to bypass multifactor authentication and access internal systems without triggering additional verification protocols.

For overburdened healthcare employees who don’t have time to vet every calendar event, this new evolution of phishing could prove catastrophic.

Read the article in Cyber Daily AU. Read More