Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Microsoft Power BI callback scam
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e
Callback phishing in body or attachment (untrusted sender)
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Callback phishing via calendar invite
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-calendar-invite-95c84360
Service abuse: GetAccept callback scam content
7d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b
Brand impersonation: Quickbooks
8d ago
Jan 15th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Service abuse: QuickBooks notification from new domain
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-quickbooks-notification-from-new-domain-c4f46473
Service abuse: QuickBooks notification with suspicious comments
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-quickbooks-notification-with-suspicious-comments-a23d0950
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/becfraud-urgent-language-and-suspicious-sendinginfrastructure-patterns-ba8a79e0
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-aol-senders-with-suspicious-html-template-or-pdf-attachment-f6044eed
Callback phishing via e-signature service
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Callback Phishing via Signable E-Signature Request
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signable-e-signature-request-4599575d
Callback phishing via SignFree e-signature request
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signfree-e-signature-request-21381c37
Callback phishing: Social Security Administration fraud
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-social-security-administration-fraud-a9049d52
Callback phishing via Yammer comment
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-yammer-comment-66650e2b
Callback phishing via Zelle Service Abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zelle-service-abuse-08727484
Callback phishing via Zoho service abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoho-service-abuse-61e351ec
Message traversed multiple onmicrosoft.com tenants
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Potential prompt injection attack in body HTML
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Link: Invoice or receipt from freemail sender with customer service number
11d ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/link-invoice-or-receipt-from-freemail-sender-with-customer-service-number-3825232d
Link: Jensi file preview link from unsolicited sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3