Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Body: PayApp transaction reference pattern
3d ago
Mar 27th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
3d ago
Mar 27th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
4d ago
Mar 26th, 2026
Sublime Security
Callback phishing via Microsoft comment
4d ago
Mar 26th, 2026
Sublime Security
Service abuse: Google Calendar notification with callback scam language
14d ago
Mar 16th, 2026
Sublime Security
Brand impersonation: McAfee
19d ago
Mar 11th, 2026
Sublime Security
Brand impersonation: GitHub with callback scam indicators
19d ago
Mar 11th, 2026
Sublime Security
Service abuse: Microsoft Power Automate callback scam impersonation
25d ago
Mar 5th, 2026
Sublime Security
Callback Phishing via Zoom comment
1mo ago
Feb 11th, 2026
Sublime Security
PayPal invoice abuse
1mo ago
Feb 11th, 2026
Sublime Security
Canva infrastructure abuse
1mo ago
Feb 6th, 2026
Sublime Security
Service abuse: WeTransfer callback scam
1mo ago
Jan 30th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
2mo ago
Jan 27th, 2026
Sublime Security
Service abuse: Monday.com callback scam
2mo ago
Jan 26th, 2026
Sublime Security
Service abuse: Microsoft Power BI callback scam
2mo ago
Jan 22nd, 2026
Sublime Security
Callback phishing via calendar invite
2mo ago
Jan 22nd, 2026
Sublime Security
Service abuse: GetAccept callback scam content
2mo ago
Jan 16th, 2026
Sublime Security
Brand impersonation: Quickbooks
2mo ago
Jan 15th, 2026
Sublime Security
Link: Jensi file preview link from unsolicited sender
2mo ago
Jan 12th, 2026
Sublime Security
Microsoft infrastructure abuse with suspicious patterns
2mo ago
Jan 12th, 2026
Sublime Security