Threat Intelligence

The Calendar Invite Came From Australia. The Organizer Was Your Coworker.

Written by Audian Paxson | Mar 1, 2026 9:15:00 AM
TL;DR A calendar invite sent from onedot61[.]au, an Australian domain registered through CyberCircle, passed SPF, DKIM, and ARC authentication. The organizer field displayed an internal employee's name and corporate email address at a cybersecurity vendor, creating the appearance of a legitimate meeting request from a colleague. The invite included a Zoom meeting link with a specific meeting ID and passcode, alongside links to fillout[.]com and calendly[.]com. The SMTP sender and the calendar organizer were entirely different identities. Three mailboxes quarantined the message based on behavioral signals.
Severity: High Impersonation Calendar Phishing MITRE: {'id': 'T1566.002', 'name': 'Phishing: Spearphishing Link'} MITRE: {'id': 'T1656', 'name': 'Impersonation'}

The calendar invite looked like an internal meeting request. The organizer field displayed a colleague's name and corporate email address at a cybersecurity vendor. The Zoom link included a meeting ID and passcode. It looked routine.

The SMTP sender was kp@onedot61[.]au, an Australian domain with no prior relationship to the organization. SPF passed. DKIM passed. ARC passed. Every authentication check confirmed the email was legitimately sent from onedot61[.]au. None of them checked whether the organizer field was telling the truth.

The Gap Between SMTP Authentication and Calendar Identity

The iCalendar format allows the ORGANIZER property to be set independently of the SMTP envelope. This means an attacker can authenticate a message through their own domain while setting the calendar organizer to any name and email address they choose. The recipient's calendar application displays the organizer identity, not the SMTP sender, making the impersonation invisible in the calendar UI.

In this case, the SMTP sender authenticated through onedot61[.]au, a domain registered through CyberCircle in Australia. The domain had valid SPF and DKIM records. ARC headers confirmed the authentication chain survived relay processing. But the organizer field displayed a different identity entirely: a real employee at the target organization, complete with the correct corporate email address.

The invite included a Zoom meeting link (us06web[.]zoom[.]us, Meeting ID 85802428869, Passcode 777167), a fillout[.]com form link, and a calendly[.]com scheduling link. Each of these is a legitimate platform. The Zoom link could host a real meeting controlled by the attacker. The form and scheduling links could serve as data collection or social engineering touchpoints. None of the embedded URLs would trigger reputation-based blocking.

Why Calendar Invites Are a Preferred Impersonation Vehicle

Calendar invites auto-populate in most email clients. They create calendar entries, generate reminder notifications, and display the organizer's name every time the recipient checks their schedule. Unlike a standard email that sits in an inbox, a calendar invite persists across multiple touchpoints in the victim's workflow.

The display name spoofing technique here was more effective than a standard email impersonation because the calendar interface presents the organizer as the meeting creator, not as a message sender. Recipients are accustomed to accepting calendar invites from colleagues without scrutinizing the underlying SMTP metadata.

The mismatch between the SMTP sender (kp@onedot61[.]au) and the organizer (an internal employee address) was the discriminating signal. This divergence is not normal in legitimate meeting workflows. Behavioral analysis that correlates sender reputation, first-time sender status, and organizer-SMTP alignment flagged the anomaly. Three mailboxes were quarantined before any recipient interacted with the Zoom link or embedded forms.

See Your Risk: Calculate how many threats your SEG is missing

Indicators of Compromise

TypeIndicatorContext
SMTP Senderkp@onedot61[.]auAustralian domain, CyberCircle registrant
Sending Domainonedot61[.]auSPF/DKIM/ARC pass
Zoom Meetingus06web[.]zoom[.]us / ID 85802428869 / Passcode 777167Attacker-controlled meeting room
Form Linkfillout[.]comData collection endpoint
Scheduling Linkcalendly[.]comSocial engineering touchpoint
Auth ResultsSPF: pass, DKIM: pass, ARC: passFull authentication for onedot61[.]au
Organizer FieldInternal employee name and email (spoofed)SMTP-organizer identity mismatch

MITRE ATT&CK Mapping

TechniqueIDRelevance
Phishing: Spearphishing LinkT1566.002Calendar invite with Zoom, form, and scheduling links
ImpersonationT1656Internal employee identity set in calendar organizer field
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The U.S. Bank Email That Came From a Lawyer Directory and Passed Every Authentication CheckA fully authenticated email from lawyerlegion[.]com displayed pixel-perfect U.S.
Cloudflare Blocked the Page, But the Email Still Landed: A .vu TLD Phishing Domain That Slipped ThroughA phishing email impersonating an insurance adjuster used an obscure Vanuatu (.vu) TLD for its payload links.
How ARC Re-Signing and an IP Allow-List Turned Three Authentication Failures Into SCL -1A phishing email claiming to be a OneDrive share from an outlook.com address originated from a county government mail server.
The Phishing Link Lived on a Domain That Didn't Exist Nine Hours EarlierA compromised university student account sent a phishing email that passed SPF, DKIM, and DMARC.
The Zoho Sign Request That Passed Every Check Except the Reply-To: Government Impersonation via E-Sign InfrastructureA Zoho Sign document request passed SPF, DKIM, DMARC, and ARC.