A calendar grid with one cell containing an entry that does not belong, representing spam calendar events.

Google Calendar Spam: How to Stop the Fake Events

There’s a meeting on your calendar Thursday at 2pm. You don’t remember agreeing to it. The title says something about an invoice, or a crypto purchase, or a payment that’s about to go through, and there’s a phone number underneath. A reminder already went off.

Start here, because it’s the question everyone actually has. Nobody hacked your account. There’s no virus on your phone. Somebody sent an invitation to an address they got off a list, and your calendar did the thing calendars are built to do, which is put invitations on your calendar.

That’s genuinely the whole mechanism. The fix takes about a minute, and I’ll get to it. But the reason this keeps happening to people who are otherwise careful is worth understanding first, because it isn’t carelessness.

The “Calendar Virus” Isn’t a Virus

Search the phrase and you’ll get a wall of antivirus products. That’s an advertising market, not a diagnosis. Apple’s own support staff say it plainly on their community forums when people show up panicking: no hack, no exploit, nothing wrong with the device.

An invitation is a small text file that tells a calendar app to draw a box on a certain day. It can’t install anything. It can’t read your messages. The only thing it can do is sit there looking official and hope you tap the link inside it.

Which means running a virus scan won’t help, and buying security software to fix it is money spent on the wrong problem. What you actually need is a settings change.

The follow-up question is usually how they got the address. Almost always a breach. Your email turns up in a dump from some company you barely remember signing up with, gets bundled into a list, and gets resold. It has nothing to do with anything you did last week, which is why it can feel so random. If you want the longer version of that pipeline, I’ve written about what actually happens after a data breach.

Why a Box on Your Calendar Slips Past You

You’ve been trained to eye an email. You check the sender, you notice the odd greeting, you hover the link.

A calendar entry gives you none of that. There’s no sender line, no subject, no signature block, nothing to inspect. It also skips your inbox entirely, which means it skips your spam filter, because the calendar service processes invitations separately from mail.

Then the reminder fires. Hours later, out of context, your phone tells you something is happening soon. By then the entry has been sitting next to your dentist appointment and your kid’s game, borrowing their credibility. That’s the part attackers are actually buying.

What the Fake Events Usually Say

Three shapes, and they’ve been consistent through the 2025 and 2026 campaigns that university IT departments have been posting alerts about.

A charge you didn’t authorize. A crypto purchase, a PayPal payment, a subscription renewal, an overdue balance. The number is always large enough to make you look.

A phone number instead of a link. This is the one I’d watch hardest. There’s no site to inspect and nothing to hover, so the usual advice doesn’t apply. Calling puts you in a live conversation with somebody reading from a script, which is the same setup as a tech support scam and it works for the same reasons.

A meeting that looks like work. A payroll acknowledgment, an HR notice, a review session, with a join link that goes to a lookalike sign-in page.

The money framing does most of the work in the first two. An unexplained charge creates a small spike of urgency and a reason to act right now, and the amount is chosen to be worth a phone call but not so large that you’d assume it was a mistake. The same crews run an invitation-shaped version by email, impersonating Evite and Paperless Post, which I’ve covered in the fake invitation guide.

Don’t Hit Decline

This is the mistake nearly everyone makes, and it makes things worse.

Declining sends a response. It tells whoever sent the invitation that a real person is reading a real address on a real device, which is exactly what they were testing for. People who decline typically see the volume go up, not down.

Delete it, or better, report it. Both Google and Apple have a report option that removes the event without notifying the sender, and reporting also flags the sender in a way that helps everyone else. It’s the same amount of tapping.

The short version.

Declining talks back. Deleting doesn’t. Reporting doesn’t either, and it flags the sender on the way out. Pick one of the quiet two.

One thing before you do either. Don’t open the link in the event to see what it is. Google’s own guidance is to report without clicking anything inside it, and that’s the right instinct.

Stop It at the Source

The permanent fix is a setting. Each platform buries it somewhere different.

Google Calendar

Open Calendar on a computer. Click the gear icon, then Settings. Under General on the left, click Event settings, and find the dropdown called Add invitations to my calendar. Change it to Only if the sender is known.

That single change ends this. Invitations from your contacts, your coworkers, and anyone you’ve corresponded with keep landing normally. Everyone else has to go through your email first, and nothing touches your calendar until you say yes.

Google is upfront about the one tradeoff, and I’ll pass it along rather than pretend it doesn’t exist. Choosing this option can reveal to a sender that they’re not in your contacts. For most people that’s a fine trade. If you take cold meeting requests from strangers for a living, it’s worth knowing.

To clear the spam that’s already there, open the event, click the three-dot menu at the top right of the details popup, and choose Report as spam. The event goes away and the sender gets flagged.

iPhone and iCloud

Open the event in the Calendar app and tap Report Junk, then Delete and Report Junk. This one is worth calling out because most guides still tell you to sign in to iCloud.com on a computer to do it. You can do it from the phone now.

Outlook

Outlook.com and Outlook on the web: click the gear, go to Calendar, then Events from email, and turn off automatic adding. Under Events and invitations you can also set Add invitations to my calendar to only add events when you respond.

Classic Outlook on Windows: File, Options, Mail, scroll to Tracking, and uncheck Automatically process meeting requests and responses to meeting requests and polls.

New Outlook for Windows: that checkbox is gone. It hasn’t been rebuilt. Microsoft’s support forums have people asking about this through 2026, with moderators confirming the issue is known and under investigation and no complete fix for personal accounts. If you’re on new Outlook and this is driving you up a wall, the web settings above are your best available lever, and switching back to classic Outlook restores the checkbox. I’d rather tell you that than pretend there’s a tidy answer.

When the Events Keep Coming Back

You delete one and it returns in seconds. This is the most frustrating version and it has two causes, neither of which is the one people assume.

You’re subscribed to a calendar. Somewhere along the line a webpage popup offered to add a calendar and got a tap. That subscription now pushes events at you on a schedule, so deleting individual entries accomplishes nothing. Delete the subscription instead. On iPhone: Calendar app, tap the Calendars button, tap the info button next to any calendar you don’t recognize, then Delete Calendar or Unsubscribe. If it isn’t listed there, go to Settings, Calendar, Accounts, Subscribed Calendars, and delete the account.

It’s living in an email account your phone syncs. If the invitation sits in a junk folder on an account connected to your phone, the phone reads the invitation and draws the event, over and over. Nothing on the calendar side will fix that. Sign in to that email account on a computer and clear the junk folder, and the events go with it.

A useful tell: if the event shows on your iPhone but doesn’t show when you log into that same account in a browser, it’s coming from the phone’s subscription or sync, not from the mail account itself.

The Rule That Handles All of It

A calendar entry is never a reason to do anything.

Not to tap a link, not to call a number, not to sign in anywhere. Real meetings get confirmed the way real meetings always did, by asking the person or opening the app you already use. Everything else about these events is designed to look convincing, and it will keep getting better at it. That rule doesn’t degrade.

If You Already Tapped or Called

If you opened the link and closed the page, you’re almost certainly fine. Visiting a page is not the same as being compromised, and my guide on what to do after clicking a phishing link walks through how to tell the difference.

If you entered a password, treat it as an account takeover and move fast. Change that password first, from a different device if you have one, then check the account for forwarding rules and recovery addresses you didn’t set up. The full sequence for a compromised email account covers the order, and the order matters more than people expect.

If you called the number and gave out information or let someone connect to your computer, that’s the tech support playbook, and the recovery steps are in that guide.

Where to Report It

Report as spam inside Google Calendar, or Report Junk on Apple, does the most good with the least effort, since it removes the event and flags the sender at the same time.

For anything beyond that, file with the FTC at ReportFraud.ftc.gov. If the same crew is also texting you, and they usually are, forward the texts to SPAM, which is 7726 on the keypad.

The Honest Bottom Line

This is a nuisance dressed up as an emergency, and the marketing around it wants you to feel the second thing. You don’t have a virus. Your accounts are fine. Somebody bought a list with your address on it and pointed a calendar invitation at it.

Change the one setting, delete or report what’s already there, and check your calendar subscriptions if the events keep returning. Then stop thinking about it.

If you want to shore up the account these campaigns are really aiming at, start with how to recognize a hacked email account and get it back. And since the same lures run over text and QR codes, my breakdowns of text message scams and QR code scams cover the other two channels.


Tom Reardon spent over 20 years in product and operations at major identity protection providers. He writes at MyScamGuide.com to give consumers the honest picture the industry’s marketing never did.


Recommended resources: