Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Microsoft 365 calendars used as spy drop boxes in HOLLOWGRAPH campaign

Cybercriminals are hiding malicious commands in calendar appointments set for 2050, using Microsoft's own cloud infrastructure to evade detection. The campaign, dubbed HOLLOWGRAPH, poses fresh risks for UK businesses reliant on Microsoft 365.

  • Malware hides commands in future-dated calendar entries set for 2050
  • Microsoft 365 cloud used to 'phone home' and receive instructions
  • UK businesses using Microsoft 365 could be prime targets for data theft

A sophisticated cyber-espionage campaign dubbed HOLLOWGRAPH is exploiting Microsoft 365 calendars as covert command-and-control channels, security researchers have warned. Attackers embed malicious instructions in calendar appointments dated for 2050, turning the widely used productivity platform into a 'spy drop box' that blends seamlessly with legitimate traffic.

According to threat intelligence reports, the malware leverages Microsoft's own cloud infrastructure to communicate with its operators. By hiding commands in calendar entries — which appear as ordinary meeting invites to any casual observer — the attackers can issue instructions to compromised systems without raising suspicion. The technique exploits the trust that organisations place in Microsoft 365, making detection by traditional security tools extremely difficult.

For UK businesses, the implications are significant. Microsoft 365 is the dominant productivity suite in British workplaces, used by millions of employees across the private and public sectors. The ICO has previously highlighted risks around cloud-based data handling, and this campaign underscores how cloud services can be weaponised. Dr Eleanor Shaw, a cybersecurity researcher at the University of Cambridge, said: 'The use of future-dated calendar events is a clever evasion tactic. It bypasses many email security filters because the content is not flagged as suspicious — it's just a calendar entry.'

The campaign also raises questions about regulatory oversight. The UK's ICO is already scrutinising cloud security practices, while the EU AI Act — which may influence UK data protection standards post-Brexit — mandates stricter transparency for AI-driven threat detection systems. However, the HOLLOWGRAPH technique exploits a fundamental design feature of calendar synchronisation, not a vulnerability, meaning traditional patching won't solve the problem.

UK consumers are less directly affected, but businesses that handle personal data — such as financial services, healthcare providers, and e-commerce platforms — could see customer information compromised if attackers gain a foothold. The economic impact could be severe: a successful breach could lead to regulatory fines under GDPR, reputational damage, and loss of client trust. Experts recommend that organisations monitor unusual calendar activity, restrict external calendar sharing, and deploy behaviour-based anomaly detection tools.

For now, Microsoft has not issued a formal response to the HOLLOWGRAPH findings. Security teams across the UK are advised to review their Microsoft 365 audit logs for any calendar entries dated far in the future and to implement conditional access policies that limit calendar synchronisation to trusted devices only.

Why this matters: Microsoft 365 is the backbone of countless UK organisations. This campaign shows how trusted cloud tools can be turned against users, potentially exposing sensitive business and customer data.

What this means for you: What this means for you: If your workplace uses Microsoft 365, your employer may need to tighten calendar-sharing policies and monitor for unusual appointment activity to prevent data leaks.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.