Most of us have trained ourselves to be careful with email. We squint at sender addresses, hover over links before clicking, and think twice about unexpected attachments. Scammers know this, which is why their newest trick skips your inbox entirely and lands somewhere your guard is down: your calendar.
If you or your team use Microsoft Outlook, and most offices do, this one is worth two minutes of your time.
How the scam works
You open Outlook and spot a new meeting invitation. The title reads something like “Final Notice: Payroll Acknowledgement Required.” It feels urgent, and it involves your pay, so of course you open it.
Inside, you find a PDF attachment with a QR code and instructions to scan it for more details.
Here’s the problem: that meeting was never sent by anyone in your organization. It came from cybercriminals.
Scan the QR code and you’re taken to a page that looks exactly like a Microsoft 365 login screen. You enter your username and password, and just like that, your credentials are in someone else’s hands.
Why calendar invites slip past our defenses
This attack works because of a simple blind spot. Years of security awareness have taught us to be suspicious of email. We look for red flags, odd senders, and strange links. But a calendar invite doesn’t trigger that same instinct. It feels routine, administrative, even internal. Our guard drops, and that’s exactly what the attackers are counting on.
Calendar invites need to be on your radar the same way emails are.
How to protect yourself
The good news is that once you know this scam exists, it’s easy to sidestep. Here’s what we recommend:
- Don’t open attachments or scan QR codes in meeting invitations you weren’t expecting, no matter how official they look.
- Treat suspicious calendar invites like suspicious emails. Same skepticism, same caution.
- Slow down when you see urgent language. Words like “Final Notice” are designed to make you act before you think. No legitimate payroll issue gets resolved through a QR code.
- Report the invitation to whoever manages your IT before doing anything else.
- Don’t decline or interact with the invite in any way until you’ve reported it. Even clicking “Decline” counts as interacting.
And if you’ve already scanned a code like this and entered your login? Change your password right away, turn on multi-factor authentication, and let your IT provider know what happened. Acting fast makes all the difference.
Worth a conversation with your team
If you run a business, this scam deserves a mention at your next staff meeting. The payroll language is deliberately chosen because it triggers an immediate reaction in almost anyone, from the front desk to the corner office. Make sure your team knows this is circulating, and that meeting invites deserve the same scrutiny as email.
Scams like this succeed because they show up where you least expect them. Staying alert means staying one step ahead.
Keeping our clients a step ahead of threats like this is at the heart of how we approach cybersecurity-driven IT. If you’d like to know how your own defenses stack up, take our free 60-second Security Score, or talk to our team. We’ll help you make sure a fake meeting invite never turns into a real problem.
