Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback Phishing via Zoom comment
1d ago
Feb 11th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoom-comment-8ec30881
PayPal invoice abuse
1d ago
Feb 11th, 2026
Sublime Security
/feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4
Canva infrastructure abuse
6d ago
Feb 6th, 2026
Sublime Security
/feeds/core/detection-rules/canva-infrastructure-abuse-b69fdb5c
Service abuse: WeTransfer callback scam
13d ago
Jan 30th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-wetransfer-callback-scam-c60c8650
Reconnaissance: Short generic greeting message
16d ago
Jan 27th, 2026
Sublime Security
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
Service abuse: Monday.com callback scam
17d ago
Jan 26th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-mondaycom-callback-scam-82cf4502
Service abuse: Microsoft Power BI callback scam
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e
Callback phishing in body or attachment (untrusted sender)
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Callback phishing via calendar invite
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-calendar-invite-95c84360
Service abuse: GetAccept callback scam content
27d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b
Brand impersonation: Quickbooks
28d ago
Jan 15th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Callback phishing: Social Security Administration fraud
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-social-security-administration-fraud-a9049d52
Callback phishing via Yammer comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-yammer-comment-66650e2b
Callback phishing via Zelle Service Abuse
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zelle-service-abuse-08727484
Callback phishing via DocuSign comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-docusign-comment-48aec918
Message traversed multiple onmicrosoft.com tenants
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Potential prompt injection attack in body HTML
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Link: Invoice or receipt from freemail sender with customer service number
1mo ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/link-invoice-or-receipt-from-freemail-sender-with-customer-service-number-3825232d
Link: Jensi file preview link from unsolicited sender
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Microsoft infrastructure abuse with suspicious patterns
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/microsoft-infrastructure-abuse-with-suspicious-patterns-cfe8e804