If an event on your calendar says you were charged for Norton, McAfee, PayPal, Geek Squad or another company and gives you a phone number to cancel, it's a scam. Don't call, and don't tap Accept, Maybe or Decline. Check your real account yourself, then report the event. The charge isn't real. The calendar is just the delivery method, and it gets around spam filters in a way most people don't expect.
We saw this firsthand on September 25, 2026, when a $499.99 "Norton LifeLock" invoice landed on a family member's calendar. Microsoft had already filed the invitation email in Junk. The reminder popped up on their phone anyway. We took that invite apart; this guide explains the scam in general and points you to the right next step.
| Your situation | Where to go |
|---|---|
| You found one and haven't called | Do this now, then how to remove and stop spam calendar invites |
| You or a relative called the number | Called the number on a fake invoice? |
| You want to protect a parent or relative | How to protect older relatives from fake invoice scams |
| You manage email for a business | Admin controls for Microsoft 365 and Google Workspace |
What a scam calendar invite looks like
This is callback phishing, sometimes called TOAD (telephone-oriented attack delivery). Instead of a malicious link or attachment, the "payload" is a phone number. The scammer creates a calendar event whose title and description read like a receipt, then invites you to it. When you call to cancel the charge, the real scam starts.
The published examples follow a script:
- A security or identity-protection brand, most often Norton, LifeLock, McAfee, Malwarebytes or Webroot, plus PayPal, Geek Squad and crypto purchases.
- A few hundred dollars. Norton puts the typical amount at $400 to $700 (Norton). Our sample was $499.99.
- "Paid", "renewed" or "auto-debit", with an invoice or order number.
- A deadline, usually 24 hours.
- A phone number as the only way to cancel, often with a different number in every wave.
Nobody hacked your calendar to put it there. Anyone who knows your email address can send you an invitation, and many calendars add invitations automatically.
Is [email protected] real? Yes. If the scammer created the event in Google Calendar, Google genuinely sends the invitation and signs it. That's what makes it look trustworthy. Google delivered the message, but the organizer and everything written in the event belong to whoever created it. The same trick works through Apple: BleepingComputer documented a fake $599 PayPal "receipt" sent through iCloud Calendar from Apple's own servers (BleepingComputer).
Tells to look for
- A charge on your calendar at all. Norton says it "never sends calendar invites related to billing or payment" (Norton support). McAfee says, "We'll never require you to call a phone number in an email or text" (McAfee).
- An organizer who isn't the company. Open the event and look at who invited you. In our sample it was a student account at a school.
- A "toll-free" number that isn't. US toll-free numbers start with 800, 833, 844, 855, 866, 877 or 888 (FCC). Our sample labeled an 805 California number "toll-free".
- Sloppy formatting. Malwarebytes and others have documented duplicated "+1 +1" country codes, curly braces in phone numbers and stacks of fake transaction IDs (Malwarebytes).
- An event that starts a few minutes after it arrives. Ours was created to start 10 minutes later, so its reminder went off immediately. Here's how that works.
Why the Junk folder doesn't stop it
The invitation email and the calendar entry travel separately. A spam filter can catch the email and still leave the event on your calendar.
Outlook.com, Hotmail and Microsoft 365. When an invitation arrives, Exchange adds it to your calendar as a tentative event, whether the email lands in your inbox or in Junk. Microsoft puts it plainly: "Outlook automatically creates a calendar entry during delivery, which remains accessible to users" even after the email is removed (Microsoft). On personal mailboxes this processing is fixed: Microsoft's documentation says "you can't change the value on a user mailbox" (Microsoft Learn). Deleting the invitation email doesn't remove the tentative event either (Microsoft). Microsoft support staff have acknowledged the problem on its Q&A forum (Microsoft Q&A), and as of October 2026 there is no consumer setting that stops it.
Google Calendar. Google treats this as a Calendar setting, separate from Gmail's spam filter. Under Add invitations to my calendar, the "From everyone" option adds every invitation automatically, and Google's announcements have given it as the default (Google). Switching to Only if the sender is known is the fix Google recommended when calendar phishing made headlines in December 2024 (Check Point). Our removal guide has the steps.
The reminder. In our sample, the event was created to start 10 minutes later. A reminder set for 10 minutes before the start was already due when the invitation arrived, so the phone alerted right away. That reminder put the number on the lock screen before anyone had opened an email.
Found one? Do this now
- Don't call, reply, or tap Accept, Maybe or Decline. Responding notifies the organizer (Google), which tells the scammer your address is active.
- Check the real account yourself. Open your bank or card app, or sign in to the company's website by typing its address. As the FTC puts it, "If you don't see a transaction for a tech support subscription, that tells you the message was a scam" (FTC).
- Report and remove the event. In Google Calendar, open it and choose Report as spam rather than deleting it, because removing an invitation on the web tells the organizer you declined. For an iCloud invite, use Report Junk. In Outlook.com, report the invitation email as phishing, then delete the event, and don't send a response if you're offered the choice. Full steps for each platform.
- Change the setting that let it in. Settings for Google, Outlook and iPhone.
- Report the scam at ReportFraud.ftc.gov.
- Already called? Here's what to do next.
How common is this?
Reports of fake-invoice calendar invites with a callback number cluster from September 2025 onward, from security vendors, university IT departments, Better Business Bureau offices and local TV. In June 2026, Google's own fraud advisory noted: "We investigated 'Calendar Phishing' bypasses, where fake renewal notices were added directly to Google Calendar invites" (Google). Gen Digital, Norton's parent company, reported that "tens of thousands of these invites were blocked in a single month" (Gen).
Nobody publishes loss figures for the calendar version specifically. The call leads to an ordinary tech-support refund scam, and those losses are large. People reported $2.13 billion in tech and customer support scam losses to the FBI in 2025, and people 60 and older accounted for about $1.04 billion of it (FBI IC3).
This is different from calendar invites that carry a phishing link, such as the late-2024 campaign that sent people through Google Forms and Google Drawings to a fake login page (Check Point). Those try to steal a password. Callback invites have no link at all; they want you on the phone.
Where Blue Lantern fits
A link checker has nothing to check here. This scam carries no link, only a phone number, and we'd rather say that than pretend otherwise. If you want to look at the invitation email itself, our Email Analyzer shows the sender and authentication results, and how to read a suspicious email report explains why a passing signature doesn't make a message trustworthy. We're working on checks for the calendar-specific signals in this cluster. Today, the setting change and the "check the real account yourself" habit are what protect you.
Analyze an email with Blue Lantern Security
Frequently asked questions
Did someone hack my calendar? No. Anyone with your email address can send you an invitation, and many calendars add invitations automatically. The scammer never had access to your account.
Why is junk mail showing up on my calendar? Because the calendar handles invitations separately from the spam filter. In Outlook.com, invitations are added as tentative events during delivery, even when the email goes to Junk. In Google Calendar, whether invitations are added depends on your "Add invitations to my calendar" setting, not on Gmail's spam folder.
Can I just delete it? You can, but on Google Calendar's website deleting an invitation tells the organizer you declined, which confirms your address is active. Use Report as spam instead. Our removal guide covers each platform.
I tapped Accept by mistake. Is that a problem? Not a dangerous one. The reply only reached the scammer's account. Remove the event and report it. In Google Calendar, accepting an invitation can make the sender count as "known", so their future invitations may be added automatically; report and block them.
Why did the reminder go off right away? Because the event was scheduled to start minutes after it was sent. Any reminder longer than that gap is already due when the invitation arrives. See the timeline from our sample.