ADVERTISEMENT

Phishing Alert: LVMH, Disney, Uber, Mastercard used in fake Calendly recruitment scam

Attackers impersonating 75 major brands, such as LVMH, Unilever, Lego, and dozens more, are using fake Calendly invites to steal Google Workspace and Facebook Business ad credentials – all part of a recently discovered phishing campaign, researchers said on Tuesday.

Google Calendar used as command and control

Image by Cybernews.

Stefanie Schappert
Stefanie Schappert Senior Journalist
December 3, 2025 Updated: December 3, 2025 3 min read
Key takeaways:
Push Security Google Facebook credential harvesting
Image by Push Security

How it works

Push Security - LVMH (Louis Vuitton Moët Hennessy fake recruiter page
Image by Push Security
ADVERTISEMENT
Push Security - Calendly invites
Image by Push Security

3 distinct variants, 75 brands

Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.
  • Be suspicious of job offers that come with a Calendly invite
  • Check the URL carefully – even after clicking through Calendly
  • Confirm the sender
  • Hover over links before clicking
  • Resist entering credentials from links inside such invites.
  • Always enable multi-factor authentication (MFA)

ADVERTISEMENT