Back to Examples
PHISHINGRisk Level: 9/10

Sophisticated phishing attack weaponizing Google Calendar infrastructure to deliver McAfee subscription scam.

HIGH ConfidenceCallback Phishing

Email Details

From
user@company.com (anonymized)
Subject
FW: Confirmation: Coverage Period Extended
Date
January 20, 2026

Key Findings

  • Calendar invitation being weaponized to deliver McAfee subscription renewal scam content disguised as a meeting

  • Classic callback phishing pattern - mentions contacting "support at {phone}" for cancellation/refund but no actual phone number provided

  • Sender authentication shows significant red flags with no SPF/DKIM/DMARC protection and domain mismatch between authentication header (pgsbe.ac.in) and actual sender domain

Detailed Analysis

This email represents a sophisticated phishing attack that weaponizes Google Calendar's legitimate infrastructure to deliver fraudulent content. The attacker has created a calendar invitation with the subject "Confirmation: Coverage Period Extended" but the body contains a fake McAfee subscription renewal notice claiming a $340.85 charge for a 5-year term. This is a classic callback phishing scam where the victim is encouraged to call a support number to cancel or request a refund.

The technical indicators strongly support this being malicious. The authentication results show "dmarc=none action=none header.from=pgsbe.ac.in" while the sender claims to be from macleodinc.com, indicating potential domain spoofing or forwarding abuse. The sender email (tejaswini.phy1910@pgsbe.ac.in) appears to be from an Indian academic institution (Post Graduate Studies Board of Education), which has no legitimate connection to McAfee services.

The attack combines several modern techniques: legitimate calendar infrastructure abuse to bypass email security, brand impersonation of McAfee, and callback phishing to avoid including suspicious links. The fake transaction details and realistic formatting are designed to create urgency and convince recipients they've been charged for an unwanted subscription. The use of stylized Unicode characters throughout the message body is likely an attempt to evade text-based security filters.

Recommended Actions

  • Delete the calendar invitation and do not respond to it or call any phone numbers provided

  • Report this as a phishing attempt to your IT security team and consider blocking the sender domain pgsbe.ac.in

  • If you have a legitimate McAfee subscription, verify its status directly through McAfee's official website or by calling their official support number from their website

Get this level of protection for every email

ForwardToSafety analyzes every suspicious email with AI-powered detection to keep you safe from phishing attacks.

View Pricing Plans