Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF generated with wkhtmltopdf tool and default title
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-generated-with-wkhtmltopdf-tool-and-default-title-64e6c8a8
Callback phishing via Microsoft comment
17d ago
Dec 16th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-microsoft-comment-8346c7b9
Service abuse: Callback phishing via Microsoft Teams invite
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-callback-phishing-via-microsoft-teams-invite-13e35e5f
Callback phishing via Google Meet
30d ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-google-meet-70e01845
Reconnaissance: Short generic greeting message
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
PayPal invoice abuse
1mo ago
Nov 20th, 2025
Sublime Security
/feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4
Callback phishing in body or attachment (untrusted sender)
1mo ago
Nov 19th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Brand impersonation: Quickbooks
1mo ago
Nov 14th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Service abuse: Google Drive share from new reply-to domain
1mo ago
Nov 13th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-drive-share-from-new-reply-to-domain-c1a2d367
Callback phishing via extensionless rfc822 attachment
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-extensionless-rfc822-attachment-197722c4
Callback phishing via SignFree e-signature request
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signfree-e-signature-request-21381c37
Callback phishing via Adobe Sign comment
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d
Callback phishing via Xodo Sign comment
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-xodo-sign-comment-6f722c5d
Callback phishing solicitation in message body
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-solicitation-in-message-body-10a3a446
Service abuse: Google classroom solicitation
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92
Callback Phishing via Signable E-Signature Request
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signable-e-signature-request-4599575d
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-branded-invoice-from-senderreply-to-domain-less-than-30-days-old-e6f4af53
Callback phishing via e-signature service
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Potential prompt injection attack in body HTML
3mo ago
Sep 29th, 2025
Sublime Security
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Attachment: Callback phishing solicitation via image file
3mo ago
Sep 25th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36