Phishing Is Targeting Small Business Booking Links
If you have a booking link on your website - through Calendly, Cal.com, or any other scheduling tool - there is a phishing attack circulating right now that you need to know about.
We flagged it on our Threads account in June after seeing it firsthand. Since then, we have heard from other business owners who received the same type of booking. This post covers what the attack looks like, why it is effective, and exactly what to do to protect yourself.
What the Attack Looks Like
The booking appears legitimate at first glance. Someone with a real-sounding name books a time through your public calendar link. The email address looks slightly unusual but not immediately suspicious. In the booking notes, they include a link to a document, usually from a domain like driveshare or papershare, framed as background context for an "exploratory conversation."
The document link is the attack. Clicking it may expose your device to malware, credential theft, or further phishing attempts.
What makes this attack effective is that it arrives through a channel you trust. Your booking software feels like a controlled environment. You are expecting inquiries from new contacts. The setup lowers your guard in a way that a cold email would not.
Why Booking Software Is Being Targeted
Public booking links are an efficient attack surface for a few reasons.
They are easy to find. If your booking link is on your website, in your email signature, or on your LinkedIn profile, it is accessible to anyone, including automated systems scanning for targets.
They bypass email filters. A phishing attempt sent directly to your inbox would likely be caught by spam filters. A booking submitted through Calendly or Cal.com arrives in your inbox looking like a legitimate notification from a tool you use and trust.
They are integrated with your most sensitive business software. Your booking software may also be connected to your Google or Microsoft calendar, CRM, payment systems, and other business tools. That makes securing the booking account and its integrations important.. A compromised account does not just affect your schedule, it can cascade through your entire business systems.
Three Things to Do Right Now
1. Turn on booking confirmation
If your scheduling tool allows you to manually approve or confirm bookings, consider enabling that feature for public-facing discovery calls. It gives you an opportunity to review the requester's email address and booking notes before the meeting is added to your calendar.
2. Review your event types and make them private where possible
Check which of your event types are publicly visible versus invitation-only. For any booking type that is not meant for cold inbound inquiries (internal team meetings, client-only links, paid consultations) set them to private or hidden so they cannot be found and abused by automated scanning tools.
3. Enable multi-factor authentication on your booking software account
Because your calendar booking tool is integrated with other important business software, a compromised account has wider consequences than most people realize. Enable multi-factor authentication (MFA), preferably using an authenticator app or passkey where supported. Do this on your booking software account and on the Google or Microsoft account it is connected to if you have not already.
How to Spot a Suspicious Booking
A few signals worth watching for:
The email address looks slightly off: a real name paired with a string of random characters, or a domain you do not recognize.
The booking notes include a link, especially to a document on an unfamiliar domain. An unexpected document link in an initial discovery call request should be treated as suspicious, particularly when you weren't expecting the document. The request is for a vague "exploratory conversation" with no specific context about their business or what they need help with.
If something feels off, do not click any links in the booking notes. Decline the booking and mark the contact as blocked in your booking software.
This attack works because it exploits trust in your tools, in your process, and in the assumption that your booking link is a controlled environment. It is not. Any public link is a potential entry point, and attackers are increasingly targeting the tools small business owners use every day.
Turning on booking confirmation, reviewing your event visibility, and enabling MFA are small steps that take less than fifteen minutes and significantly reduce your exposure.
Your booking link is only one part of your technology environment. The bigger question is what that booking system can access, what it is connected to, and who has permission to use it.”
If you want to review the security of your full tech stack - including your booking software, your integrations, and your access controls - that is exactly what we cover in a Technology Audit.
And if you want to start with a self-assessment, the CONTROL Audit covers who and what has access to your business systems across seven critical areas.