Fraudsters are sending emails in the name of 1177, Sweden’s national healthcare service, offering discounts on services and planting invitations in recipients’ calendars. The warning sits on the front page of 1177.se and 1177 states that it never offers services, discounts or invitations in the way these emails describe.
A second variant tells the recipient to click a link to log in and read a message waiting on 1177.se. That one is always false. 1177 sends no clickable login links. The single exception is a patient with an ongoing care contact who may receive a link to a video appointment or a survey.
SSF Stöldskyddsföreningen pushed the warning to its subscribers on 5 October, according to Oskarshamns-Nytt and Nyheter24 reported it on 6 October citing the organisation’s Säkerhetskollen service. 1177 is run by Inera, the company owned by Sweden’s regions and municipalities and Inera’s 2024 annual report puts traffic to 1177.se at 16 million visits a month. The campaign abuses the 1177 name. No flaw in 1177 itself is involved.
The calendar entry survives the deleted email
Researchers at Barracuda described the method on 6 August 2026: links, QR codes and fake requests are embedded in an .ics calendar file, the entry is added to the recipient’s calendar with little or no interaction and it persists after the original email has been deleted or quarantined. Email filters that inspect the message body and conventional attachments have historically paid less attention to calendar content.
Barracuda sells email security products. The behaviour it describes matches 1177’s own notice. Sent to a work address, the same email can put an entry in a corporate calendar next to ordinary meetings.
1177 has given no numbers
1177 has not said how many messages are circulating, has not published a sample and has not named a sender domain. The advisory page carries a last-updated date of 4 March 2026 while describing the campaign as current, so readers cannot tell from 1177 alone whether this is a new wave or a rolling notice. In late July 1177 displayed a warning at login about SMS and emails carrying login links and regional press repeated it in August.
Region Halland has published its own warning about a related phone scam: callers claim to be from a health centre and ask the patient to identify with BankID during the call in order to rebook an appointment. Health care does not call and ask you to log in while you are on the line.
Four signs of a genuine 1177 message
1177 lists four characteristics of its real notifications:
- It says you have received a message in your inbox on 1177.se.
- It asks you to log in on the website to read it.
- It contains no clickable link.
- It cannot be replied to.
If an email claiming to come from 1177 contains a link, an offer or a calendar invitation, delete it and remove the calendar entry as well. Then open a browser, type 1177.se and log in. Never use BankID or another e-legitimation because an unknown sender asked you to.
Quarantine does not clear the calendar
For IT teams, the calendar entry is the part to act on. If it stays put after the email is deleted or quarantined, as Barracuda describes, a clean-up that stops at the mailbox leaves the lure in place. We would check whether your email tooling removes calendar items along with quarantined messages and tell staff to delete both.
References
- Så vet du att meddelandet är från 1177
- Skarp varning från 1177: Akta dig för det här just nu
- Varning för falska meddelanden som påstår sig komma från 1177
- JUST NU: 1177 varnar för falska mejl
- Understanding calendar invite phishing: how attackers abuse .ics files
- Var vaksam på bedrägeriförsök i Region Hallands namn
- Ineras års- och hållbarhetsredovisning 2024
This post is also available in:

