Getting an unsolicited lead for a major website redesign, SEO, and “the works” is usually cause for celebration. Lately, though, it might be a trap. A booking scam is making the rounds, specifically designed to compromise web agencies and freelancers during standard discovery calls.
There’s no software exploit here. No malware attachment. Just deceptive workflow manipulation. By looking at how this fake client inquiry phishing pattern (a booking link phishing attack) works, we can see how it manages to slip past standard email filters and how to keep your agency’s infrastructure safe.
The Bait: A High-Value, Vague Inquiry
The initial outreach relies on the psychological appeal of a major contract to drop your professional guard. Here is the exact text of the Calendly scam email template currently hitting agency inboxes:
Subject: Re: Thank you for contacting us
Hello Team,
We want to do a massive revamp of [example-brand].co.uk. Design, SEO, the works. To be honest, we don’t have a technical scope written up yet – we need an expert team to help us figure that part out.
My boss is awesome and very down-to-earth, so the call will be super relaxed and productive. Go ahead and schedule a time here: calendar
Once it’s locked in, please send a screenshot of the confirmation and the email you used right here so I don’t lose track of it.
Best regards, [An image attachment showing a professional email signature for an employee at the impersonated company, using a free public outlook.com address]
It looks like a normal, lucrative inquiry until you slow down and read it a second time. On the surface, it’s a standard discovery call request, but checking the mechanics behind the outreach reveals major red flags.
4 Major Red Flags to Watch Out For
1. Senders Using Public Domains for Enterprise Brands
The message references a legitimate corporate domain ending in .co.uk, signaling a UK-based company. However, the actual email headers show it was sent from a free, public account like @outlook.com or @gmail.com. While prospects occasionally reach out via personal accounts, it is highly suspicious for a corporate manager coordinating a massive corporate website redesign to rely on a generic consumer email address.
2. Strategic Disconnects in Lead Metadata
In variations of this booking link phishing attack, there are frequently glaring inconsistencies between the text and the submission metadata. For example, the message may claim to represent a UK corporation, but the phone number, IP routing, or area code provided in your intake form matches a completely different geographic region.
3. Deliberate Vagueness to Fast-Track a Call
Legitimate companies planning an extensive site overhaul typically come to the table with some defined constraints – rough budgets, target launch windows, or specific technical pain points. Scammers intentionally stay vague because their only goal is to push you into the scheduling workflow before you can ask qualifying technical questions.
4. Flattery and Artificial Comfort
Promising a “super relaxed” call with an “awesome boss” is a calculated social engineering tactic. It is explicitly designed to trigger an automated sales reflex, making you more likely to click the embedded link quickly without executing standard security vetting.
Why the Screenshot Request Matters (Bypassing the Security Sandbox)
The most unusual element of this campaign is the strict demand that you reply with a manual screenshot of the confirmation page and the exact email address used to book the slot. This pattern has been increasingly reported across agency intake workflows, and it serves two critical tactical purposes for the attacker:
Evading Automated Security Sandboxes
Modern enterprise mail filters use automated secure email gateways (SEGs) and sandbox environments to follow links inside incoming messages, checking if they lead to known credential-harvesting setups. By forcing a manual verification step and requiring the victim to interact with the external page to generate a screenshot, attackers introduce human-dependent logic that can bypass these automated link-following security systems.
Filtering and Refining the Target List
These agency lead phishing scams are frequently blasted across thousands of general business aliases simultaneously (info@, sales@, contact@). Because savvy web professionals often input fake data into suspicious landing pages to test them, demanding a matching screenshot and email confirmation allows the attacker to isolate live, monitored business accounts from dead data, significantly improving the overall quality of their target list.
Why Agencies Are Being Targeted
Web design agencies, SEO firms, and freelancers are common targets for these campaigns because their intake process is naturally optimized for lead capture and low-friction conversion.
Attackers exploit this by masquerading as lucrative leads, knowing that sales teams are highly incentivized to click calendar booking links quickly to secure an active discovery call. These campaigns often impersonate Calendly, Google Calendar invites, or similar trusted scheduling tools to blend seamlessly into an agency’s daily workflow.
Technical Deep-Dive: How It Bypasses Spam Filters
Many business owners assume that if an inbound message successfully reaches their main inbox, it has been thoroughly cleared by their mail provider’s security systems. This scam shows how easily that safety net can fail when facing entirely clean transport infrastructure.
Exploiting Outbound Infrastructure Trust
The attackers didn’t use a compromised web server or a sketchy domain to route the mail. Instead, they registered real consumer accounts directly through Microsoft Outlook or Google Workspace. Because the email came through Microsoft’s or Google’s legitimate infrastructure, it can still pass standard SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) checks. To the receiving email server, the transport layer identity appears completely pristine.
Brand New, Unrated Lookalike Domains
While the anchor text in the body of the email simply displays a benign word like “calendar,” the underlying hyperlink points to a newly registered lookalike domain. These domains frequently stack recognizable scheduling keywords alongside impersonated corporate names, creating URLs that look fine at a quick glance.
Because these domains are usually registered only hours before a campaign goes live, traditional threat intelligence feeds and blocklists haven’t had time to classify them as malicious yet. An authenticated email coming from a trusted network like Microsoft that links out to a brand-new, unrated domain represents a notable blind spot for automated filters.
Once clicked, these fake booking links typically deploy one of two payloads:
- Credential Harvesting: A highly accurate clone of a Microsoft 365 or Google Workspace login portal designed to capture administrative credentials.
- OAuth Consent Phishing: A malicious app invite that requests the user to grant extensive read/write permissions to their corporate profile, bypassing passwords and two-factor authentication (2FA) entirely.
Common Variations of the Intake Scam
As endpoint filters adapt, attackers alter their delivery templates to stay ahead of security awareness training:
- The “Shared Brief” Phishing Link: The attacker claims the detailed technical project scope or wireframes are hosted on a shared external platform like Notion, Figma, or Canva, requiring a corporate “login” to access the file.
- The RFP Malicious Attachment: The sender skips the discovery call workflow entirely and asks for an immediate project bid, attaching a malicious
.zip,.iso, or.icsfile disguised as an architectural brief or calendar invite. - Direct Calendar Injection: Attackers bypass the inbound email filter entirely by sending an unsolicited calendar event invite directly to your calendar software, using the description fields to house the malicious links.
Read more on related scams: The 30-Minute Job Interview That Steals Your Entire Hard Drive
Anatomy of a Domain Renewal Scam: How Phishing Emails Use Subdomain Tricks
Action Checklist: Protect Your Agency Workflow
To ensure your business remains secure against fake client inquiry phishing, implement these baseline operational rules across your sales and intake teams:
- Don’t click anchor text at face value. Hover over links before deciding to click on it or not, to check the destination domain. Look for hyphenated variants, reversed characters, or uncharacteristic extensions.
- Verify senders independently. If a prospect claims to represent an established enterprise but communicates via a public domain, do not interact with their links. Open a separate browser tab, navigate to the official corporate website, and use an independent contact channel to verify the inquiry.
- Enforce strict screenshot policies. Establish an absolute administrative rule stating that internal account states, confirmation setups, or internal authentication flows are never to be screenshotted and shared with external, unverified entities.
- Implement OAuth controls. Restrict your team’s ability to grant third-party application permissions to your primary corporate tenant without explicit IT or administrative approval.
What to Do If You Already Clicked
If a member of your intake or sales team has already interacted with one of these links, take immediate mitigation steps:
- Terminate Active Sessions: Force a global sign-out across all active sessions for the compromised user account via your administrative console.
- Reset Account Credentials: Change the user’s master account password immediately and verify that no unauthorized authentication methods or backup phones were added to their profile.
- Audit OAuth Applications: Check your Google Workspace or Microsoft 365 enterprise applications panel for any newly authorized, unverified third-party apps and immediately revoke their access tokens.
- Review Email Rules: Check the user’s account for newly created email forwarding rules or deleted item rules, which attackers frequently install to quietly snoop on corporate data without the user’s knowledge.
Have you noticed similar variations of this booking link phishing attack hitting your inbox? These campaigns evolve quickly – sharing real examples is often what helps agencies and web professionals spot the next variation early.
If you actually are interested in integrating an actual, valid Google Calendar or booking system on your website, read our guide, How to Embed a Google Calendar or Booking System on Your Website (Custom Code or UltimateWB)
Want to design & build your own website? Learn more about UltimateWB! We also offer web design packages if you would like your website designed and built for you.
Got a techy/website question? Whether it’s about UltimateWB or another website builder, web hosting, or other aspects of websites, just send in your question in the “Ask David!” form. We will email you when the answer is posted on the UltimateWB “Ask David!” section.
