Cybersecurity

New CalPhishing Campaign Turns Internal Email Forwards Into Credential-Stealing Lures

mm
Add Unite.AI to your preferred sources on Google
Illustration of a malicious email moving through a trusted internal forwarding chain toward a fake login page.
A new CalPhishing variant uses helpful employees and internal email forwards to make malicious booking links appear trustworthy.

Fortra Intelligence and Research Experts (FIRE) has identified a new CalPhishing campaign that turns one of the most ordinary workplace behaviors—forwarding a sales inquiry to the right colleague—into a credential-theft delivery mechanism.

Rather than directly targeting a salesperson with a suspicious cold email, the attacker first approaches an employee outside the sales team while posing as a prospective customer. The request appears routine: connect the sender with someone who can discuss a product or service. Once the employee responds, the attacker supplies a meeting-booking link and asks that it be forwarded internally.

The forwarded message then reaches the intended target carrying something the attacker could not easily manufacture: the credibility of a known colleague.

How the trust chain is built

Fortra describes the technique as a form of “tiered trust abuse.” The attacker is not relying on a compromised mailbox or a convincing imitation of an executive. Instead, the campaign recruits an unwitting employee to become a trust bridge.

The sequence begins with a prospect-style inquiry sent to someone who is not responsible for sales. That employee tries to help and confirms that the request can be routed to the appropriate person. The attacker then provides a booking link, which the employee forwards to a salesperson or another business-development target.

At that point, the message no longer looks like an unsolicited external approach. It appears to be a warm internal handoff. The sender’s original identity may still be visible in the thread, but the forwarding employee has effectively supplied social proof that lowers the recipient’s defenses.

This is the central innovation in the campaign. Traditional phishing often depends on impersonating someone the target trusts. Here, the attacker persuades a real trusted person to deliver the lure without realizing it.

The booking page becomes the phishing site

The forwarded link opens what appears to be a conventional scheduling page. The visitor selects an available date and time, reinforcing the impression that the workflow is legitimate and nearly complete.

Only after the time selection does the page introduce the critical step: a Microsoft 365 work-or-school sign-in prompt, presented as necessary to confirm or synchronize the meeting. Fortra says the observed flow is consistent with an attempt to harvest Microsoft 365 credentials.

The delayed credential request is important. A login prompt delivered immediately after an unsolicited email might trigger suspicion. The same prompt can feel less unusual after a user has followed a colleague’s referral, visited a polished booking page and chosen a meeting time.

Every individual action resembles normal business activity. It is the complete chain—from external inquiry to internal forward, calendar page and authentication request—that reveals the attack.

Why email-only defenses may miss the attack

The technique exploits the difference between message trust and destination trust. Employees are often trained to check the sender, watch for impersonation and treat unexpected external mail cautiously. Those habits become less effective when the malicious link arrives inside a thread forwarded by a legitimate coworker.

It can also complicate automated detection. The original external message may contain no attachment, overt malware or urgent financial request. The employee forwarding it is not compromised, and the internal message itself is genuinely sent from the organization’s mail system.

Fortra recommends that investigations correlate the entire path: the original external inquiry, the internal forward, the booking-domain visit and any authentication activity that follows. Looking at only one stage can make the campaign appear benign.

The findings also reinforce a broader shift in email security. Attackers increasingly exploit business context and legitimate workflows rather than relying only on obvious malicious payloads. In a recent Unite.AI interview, StrongestLayer CEO Alan LeFort discussed why modern phishing detection increasingly needs to reason about business context, not simply match known signatures.

What organizations should watch for

The clearest warning sign is a booking page on an unfamiliar or unrelated domain that asks the visitor to sign in with a corporate Microsoft 365 account after selecting a time. Employees should stop at that point and verify the meeting request through a known communication channel.

Security teams should also treat internally forwarded links as external destinations unless the underlying domain has been independently validated. The fact that a coworker forwarded a message does not establish that the linked site is safe.

If credentials are successfully captured, attackers may gain access to business email, sensitive data and customer communications. A compromised account could then support fraud, further phishing, impersonation or lateral movement inside the organization.

The operational lesson is straightforward: an internal forward can add credibility, but it cannot make an external destination trustworthy. In this CalPhishing variant, the first employee is not the final target. That person is part of the delivery chain—and the small act of being helpful is what makes the eventual lure more convincing.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.