ADVERTISEMENT

A fake journalist used a real Calendly link to phish a tech founder

One genuine link, one fake app, one hijacked account.

phishing attack

Image by Cybernews

Mayank Sharma
Mayank Sharma Contributor
September 29, 2026 2 min read
Key takeaways:
ADVERTISEMENT
After authorization, my research browser reached a real Calendly event. Calendly appeared at both ends of the attack: the genuine routing form in Peter’s original message and the configured event after consent. The attacker placed the authorization request between those familiar scheduling steps.
Casco security engineer Anthony Gibbs explained.

Abusing trust

Mayank Sharma
Journalist
ADVERTISEMENT