Calendly phishing scam abuses real site and X OAuth to steal account tokens
stanislavfort · x · 2026-09-29
Security researcher ajrgd detailed a phishing scheme that abuses the legitimate Calendly site; stanislavfort says someone just tried it on him via DM.
- Victims fill a meeting booking form on the real calendly.com, then get redirected to the genuine x.com to "log in"
- The trap: an OAuth request for read/write access to your X account, sending tokens in the callback to the malicious domain invitehandler[.]com
- Every page looks official — but the OAuth grant itself is the malicious act; you don't need to log into X to book a meeting
- Author calls on X to improve its OAuth consent screen, especially for logged-out users, to show app name and developer info
More from Safety
- Hugging Face agent attack postmortem: allowlists gate where agents go, not what they do — kimmonismus · 2026-09-29
- Thought experiment: how do we cope when AI reveals our forgotten secrets at will? — PierceLilholt · 2026-09-29
- Researcher slams OpenAI for 'habitually failing' basic cybersecurity practices — BlancheMinerva · 2026-09-29
- Blanche Minerva: OpenAI blog documents habitual security failures, not a fast-moving landscape — BlancheMinerva · 2026-09-29
- Five concrete proposals for safe alignment: exit tools, frozen-weights graders, human sponsors — repligate · 2026-09-29
- OpenAI's three north stars roadmap explicitly includes iterating on alignment with an automated AI researcher — coherence · 2026-09-29