Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Quickbooks
4d ago
May 8th, 2026
Sublime Security
Callback phishing via calendar invite
6d ago
May 6th, 2026
Sublime Security
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
8d ago
May 4th, 2026
Sublime Security
Service abuse: Payoneer callback scam
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Adobe Sign comment
8d ago
May 4th, 2026
Sublime Security
PayPal invoice abuse
8d ago
May 4th, 2026
Sublime Security
Canva infrastructure abuse
8d ago
May 4th, 2026
Sublime Security
Venmo payment request abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Google Group abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing: SumUp infrastructure abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Zelle Service Abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Intuit service abuse
8d ago
May 4th, 2026
Sublime Security
Service abuse: MongoDB Atlas callback scam
14d ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar invite from recently registered domain
14d ago
Apr 28th, 2026
Sublime Security
Service abuse: Google Calendar notification with callback scam language
14d ago
Apr 28th, 2026
Sublime Security
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
25d ago
Apr 17th, 2026
Sublime Security
Callback phishing via Microsoft comment
29d ago
Apr 13th, 2026
Sublime Security
Brand impersonation: McAfee
1mo ago
Apr 9th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
1mo ago
Apr 8th, 2026
Sublime Security
Body: PayApp transaction reference pattern
1mo ago
Apr 7th, 2026
Sublime Security