A sophisticated cyber-espionage campaign dubbed HOLLOWGRAPH is exploiting Microsoft 365 calendars as covert command-and-control channels, security researchers have warned. Attackers embed malicious instructions in calendar appointments dated for 2050, turning the widely used productivity platform into a 'spy drop box' that blends seamlessly with legitimate traffic.
According to threat intelligence reports, the malware leverages Microsoft's own cloud infrastructure to communicate with its operators. By hiding commands in calendar entries — which appear as ordinary meeting invites to any casual observer — the attackers can issue instructions to compromised systems without raising suspicion. The technique exploits the trust that organisations place in Microsoft 365, making detection by traditional security tools extremely difficult.
For UK businesses, the implications are significant. Microsoft 365 is the dominant productivity suite in British workplaces, used by millions of employees across the private and public sectors. The ICO has previously highlighted risks around cloud-based data handling, and this campaign underscores how cloud services can be weaponised. Dr Eleanor Shaw, a cybersecurity researcher at the University of Cambridge, said: 'The use of future-dated calendar events is a clever evasion tactic. It bypasses many email security filters because the content is not flagged as suspicious — it's just a calendar entry.'
The campaign also raises questions about regulatory oversight. The UK's ICO is already scrutinising cloud security practices, while the EU AI Act — which may influence UK data protection standards post-Brexit — mandates stricter transparency for AI-driven threat detection systems. However, the HOLLOWGRAPH technique exploits a fundamental design feature of calendar synchronisation, not a vulnerability, meaning traditional patching won't solve the problem.
UK consumers are less directly affected, but businesses that handle personal data — such as financial services, healthcare providers, and e-commerce platforms — could see customer information compromised if attackers gain a foothold. The economic impact could be severe: a successful breach could lead to regulatory fines under GDPR, reputational damage, and loss of client trust. Experts recommend that organisations monitor unusual calendar activity, restrict external calendar sharing, and deploy behaviour-based anomaly detection tools.
For now, Microsoft has not issued a formal response to the HOLLOWGRAPH findings. Security teams across the UK are advised to review their Microsoft 365 audit logs for any calendar entries dated far in the future and to implement conditional access policies that limit calendar synchronisation to trusted devices only.