Calendar phishing works because it exploits a design choice, not a software vulnerability. Google Calendar and similar apps auto-add meeting invitations without requiring user acceptance. That means a scammer's email — even one caught by your spam filter — can plant an entry in the same interface where your dentist appointment and your boss's weekly check-in live. The borrowed credibility is the weapon. The attack surface is broad and getting broader. Sublime Security threat detection engineer Luke Wescott reports "exponential growth" in calendar phishing. The scam takes multiple forms: fake meetings, voicemail notifications, payment confirmations ($298.99 receipts, PayPal warnings), auto-payment alerts, and contract bid invitations. Titles are engineered to create urgency without raising suspicion. What makes this particularly difficult to defend against is that scammers are routing invitations through legitimate platforms like Zoom. Max Gannon of Cofense notes that this makes the invitations nearly indistinguishable from real ones — both to recipients and to AI-backed security filters. Blocking invitations from these platforms would simultaneously block every legitimate meeting request, creating an impossible filtering problem. The sophistication extends to impersonation. Gannon confirms that attackers can customize calendar entries to look like internal company invitations, complete with corporate logos. The event description typically contains either a phishing link to a fake login page (Microsoft, Google, PayPal) or a phone number for a bogus support line. Until a user clicks the link or calls the number, no credentials are compromised — the calendar entry itself is just bait. The defensive advice is telling in its modesty. Turn off auto-accept in Google Calendar settings. Don't click "decline" on suspicious invites because it confirms your address is live — delete or report as spam instead. Gannon's top recommendation is blunt: "People just need to be paranoid." When the best institutional defense is individual paranoia, the system is failing. This is fundamentally a platform design problem masquerading as a user awareness problem. Google's default of auto-accepting calendar invitations prioritizes convenience over security, externalizing the cost of that choice onto every user. The platforms that serve as delivery mechanisms — Zoom, Google, Microsoft — capture the benefits of frictionless scheduling while users bear the fraud risk. The pattern is familiar in tech: build for convenience, ship the default that maximizes engagement, then tell users to be more careful when the design inevitably gets exploited. Calendar phishing will keep growing until platform defaults change, and platforms have little incentive to add friction to a feature that works exactly as designed — for them.