Online Threat Alerts (OTA) - Alerting you to scams and frauds.

Calendly Scams - How to Protect Yourself
Calendly Scams - How to Protect Yourself

Calendly itself is a completely legitimate online scheduling tool, but scammers actively abuse the platform to launch highly sophisticated phishing and job scams. Because people naturally trust a Calendly link, bad actors exploit this trust to steal login credentials, distribute malware, or run fake recruitment schemes.

How the Scams Work

  • Fake Job Offers & Recruiter Phishing: Scammers masquerade as recruiters from major corporations (like Disney, Uber, or Mastercard). They email you an invitation to schedule an interview via a Calendly link.
  • Credential Harvesting via "OAuth" Logins: When you click the scheduling link, you are directed to a page that forces you to log in via "Google" or "Facebook" to secure your time slot. These are fake login windows designed to steal your account credentials.
  • The "View Document" Injected Link: Scammers use free Calendly accounts to build a real event, but use the "Add Custom Link" function to insert a button labeled "View Documents" or "Preview Contract". Clicking this takes you to a fake Microsoft 365 or Google Workspace login page.
  • Malicious Calendar Spam: Attackers push unsolicited calendar invites containing urgent, panic-inducing text (like "Legal Violation Notice" or "Fax Received") to force you into clicking external, malicious links.

Key Red Flags to Watch For

  • Every Single Time Slot is Open: If you open a busy recruiter's or executive's Calendly page and literally every 30-minute block across nights, weekends, and past dates is fully open, the page is likely a fraudulent copy.
  • Mandatory Social Login to Book: Legitimate Calendly links only require your name, email, and basic text answers. If a page forces you to sign in with your corporate or social media password just to pick a time, close the tab immediately.
  • The URL Looks Slightly Off: Check the browser address bar. Scammers often use lookalike domains or complex routing to hide the fact that you aren't on the official Calendly Website.
  • Unsolicited Urgency: The email or invitation creates massive panic or a sense of unearned opportunity, demanding you book "immediately".

Direct Steps to Protect Yourself

  1. Verify via External Channels: If a recruiter hits you up, do not use their provided link. Go directly to the company's official corporate website careers page or look up the employee on LinkedIn to verify their identity.
  2. Never Enter Passwords to Schedule: Guard your corporate and email credentials. Treat any calendar invite asking for a login as a critical threat.
  3. Tweak Your Calendar Settings: Set your personal and corporate email settings so that invitations from unknown, external senders are not automatically accepted or added to your visible schedule.
  4. Report Abuse: If you find a scammer actively utilizing a live Calendly page, report it directly to the platform via the Calendly Help Center Report Abuse Page so they can take the account down.
0

Comment sectionComments / Answers (0)

Remove sensitive information from your post. Your IP address will be used to display your estimated location.

Comment count 0


waiting