Phishing Campaign Exploits Calendly to Evade Email Security in Hotels

Phishing Campaign Exploits Calendly to Evade Email Security in Hotels

First seen 27 Jun 2026, 14:43 UTC TechtimesTravelerstodaywww.bleepingcomputer.comwww.microsoft.com 91% similarity 68.0
Share:

Article Content

Browse articles
ThreatCluster

A phishing campaign targeting hotels in Europe and Asia since April 2026 has utilized a method called 'authentication laundering' to bypass enterprise email security filters. Microsoft Threat Intelligence disclosed this operation on June 25, 2026, revealing that attackers registered a legitimate Calendly account to send phishing emails. These emails, appearing as legitimate notifications, passed all standard authentication checks (SPF, DKIM, DMARC) due to their origin from Calendly's authorized servers. The messages, written in Japanese, Danish, and Dutch, contained urgent lures related to guest complaints and operational threats. The campaign has significant implications for any organization relying on SaaS platforms for email notifications, as it exposes a critical design flaw in email security. The phishing emails embedded a redirect URL leading to a malicious payload disguised as a Windows shortcut file. Currently, the campaign remains active, posing risks to hotel operations across multiple regions.

Key Points: • Phishing campaign uses legitimate Calendly accounts to bypass email filters. • Attackers exploit a design flaw in email authentication standards (SPF, DKIM, DMARC). • Urgent lures target hotel staff with threats of operational consequences.

ThreatCluster AI

Timeline

2026-04-01
Phishing campaign begins targeting hotels
The campaign exploits email security flaws, starting its operations in Europe and Asia.
Techtimes
2026-06-25
Microsoft discloses phishing campaign details
Microsoft Threat Intelligence formally names the attack method 'authentication laundering' and warns of its implications.
Techtimes
2026-06-26
Articles published detailing the attack
Both Techtimes and Travelerstoday report on the phishing campaign and its methods, highlighting its operational scale.
Travelerstoday
2026-06-27
Campaign remains active
The phishing campaign continues to target hotel staff, posing ongoing risks to operations across Europe and Asia.
Travelerstoday

Community

Browse all →