Cybersecurity
New CalPhishing Campaign Turns Internal Email Forwards Into Credential-Stealing Lures

Fortra Intelligence and Research Experts (FIRE) has identified a new CalPhishing campaign that turns one of the most ordinary workplace behaviors—forwarding a sales inquiry to the right colleague—into a credential-theft delivery mechanism.
Rather than directly targeting a salesperson with a suspicious cold email, the attacker first approaches an employee outside the sales team while posing as a prospective customer. The request appears routine: connect the sender with someone who can discuss a product or service. Once the employee responds, the attacker supplies a meeting-booking link and asks that it be forwarded internally.
The forwarded message then reaches the intended target carrying something the attacker could not easily manufacture: the credibility of a known colleague.
How the trust chain is built
Fortra describes the technique as a form of “tiered trust abuse.” The attacker is not relying on a compromised mailbox or a convincing imitation of an executive. Instead, the campaign recruits an unwitting employee to become a trust bridge.
The sequence begins with a prospect-style inquiry sent to someone who is not responsible for sales. That employee tries to help and confirms that the request can be routed to the appropriate person. The attacker then provides a booking link, which the employee forwards to a salesperson or another business-development target.
At that point, the message no longer looks like an unsolicited external approach. It appears to be a warm internal handoff. The sender’s original identity may still be visible in the thread, but the forwarding employee has effectively supplied social proof that lowers the recipient’s defenses.
This is the central innovation in the campaign. Traditional phishing often depends on impersonating someone the target trusts. Here, the attacker persuades a real trusted person to deliver the lure without realizing it.
The booking page becomes the phishing site
The forwarded link opens what appears to be a conventional scheduling page. The visitor selects an available date and time, reinforcing the impression that the workflow is legitimate and nearly complete.
Only after the time selection does the page introduce the critical step: a Microsoft 365 work-or-school sign-in prompt, presented as necessary to confirm or synchronize the meeting. Fortra says the observed flow is consistent with an attempt to harvest Microsoft 365 credentials.
The delayed credential request is important. A login prompt delivered immediately after an unsolicited email might trigger suspicion. The same prompt can feel less unusual after a user has followed a colleague’s referral, visited a polished booking page and chosen a meeting time.
Every individual action resembles normal business activity. It is the complete chain—from external inquiry to internal forward, calendar page and authentication request—that reveals the attack.
Why email-only defenses may miss the attack
The technique exploits the difference between message trust and destination trust. Employees are often trained to check the sender, watch for impersonation and treat unexpected external mail cautiously. Those habits become less effective when the malicious link arrives inside a thread forwarded by a legitimate coworker.
It can also complicate automated detection. The original external message may contain no attachment, overt malware or urgent financial request. The employee forwarding it is not compromised, and the internal message itself is genuinely sent from the organization’s mail system.
Fortra recommends that investigations correlate the entire path: the original external inquiry, the internal forward, the booking-domain visit and any authentication activity that follows. Looking at only one stage can make the campaign appear benign.
The findings also reinforce a broader shift in email security. Attackers increasingly exploit business context and legitimate workflows rather than relying only on obvious malicious payloads. In a recent Unite.AI interview, StrongestLayer CEO Alan LeFort discussed why modern phishing detection increasingly needs to reason about business context, not simply match known signatures.
What organizations should watch for
The clearest warning sign is a booking page on an unfamiliar or unrelated domain that asks the visitor to sign in with a corporate Microsoft 365 account after selecting a time. Employees should stop at that point and verify the meeting request through a known communication channel.
Security teams should also treat internally forwarded links as external destinations unless the underlying domain has been independently validated. The fact that a coworker forwarded a message does not establish that the linked site is safe.
If credentials are successfully captured, attackers may gain access to business email, sensitive data and customer communications. A compromised account could then support fraud, further phishing, impersonation or lateral movement inside the organization.
The operational lesson is straightforward: an internal forward can add credibility, but it cannot make an external destination trustworthy. In this CalPhishing variant, the first employee is not the final target. That person is part of the delivery chain—and the small act of being helpful is what makes the eventual lure more convincing.












