Calphishing uses calendar invites as the primary attack vector rather than email messages. Calendar invites land in a less scrutinized environment, can persist even after emails are deleted, and bypass many email-focused security controls that organizations rely on to detect phishing attempts.