Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Quickbooks
15h ago
Jun 1st, 2026
Sublime Security
Reconnaissance: Short generic greeting message
4d ago
May 29th, 2026
Sublime Security
Service Abuse: HelloSign share with suspicious sender or document name
5d ago
May 28th, 2026
Sublime Security
Service abuse: Amazon invitation with suspected callback phishing
11d ago
May 22nd, 2026
Sublime Security
Service abuse: Calendly callback scam detection
12d ago
May 21st, 2026
Sublime Security
Callback phishing via calendar invite
21d ago
May 12th, 2026
Sublime Security
Venmo payment request abuse
29d ago
May 4th, 2026
Sublime Security
Callback phishing via Zelle Service Abuse
29d ago
May 4th, 2026
Sublime Security
Service abuse: Payoneer callback scam
29d ago
May 4th, 2026
Sublime Security
Callback phishing via Adobe Sign comment
29d ago
May 4th, 2026
Sublime Security
PayPal invoice abuse
29d ago
May 4th, 2026
Sublime Security
Canva infrastructure abuse
29d ago
May 4th, 2026
Sublime Security
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
29d ago
May 4th, 2026
Sublime Security
Callback phishing via Google Group abuse
29d ago
May 4th, 2026
Sublime Security
Callback phishing: SumUp infrastructure abuse
29d ago
May 4th, 2026
Sublime Security
Callback phishing via Intuit service abuse
29d ago
May 4th, 2026
Sublime Security
Service abuse: MongoDB Atlas callback scam
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar invite from recently registered domain
1mo ago
Apr 28th, 2026
Sublime Security
Service abuse: Google Calendar notification with callback scam language
1mo ago
Apr 28th, 2026
Sublime Security
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
1mo ago
Apr 17th, 2026
Sublime Security