Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback phishing in body or attachment (untrusted sender)
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Callback phishing via extensionless rfc822 attachment
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-extensionless-rfc822-attachment-197722c4
Callback phishing via SignFree e-signature request
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signfree-e-signature-request-21381c37
Callback phishing via Xodo Sign comment
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-xodo-sign-comment-6f722c5d
Callback phishing via e-signature service
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Callback Phishing via Signable E-Signature Request
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signable-e-signature-request-4599575d
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-branded-invoice-from-senderreply-to-domain-less-than-30-days-old-e6f4af53
Service abuse: Google classroom solicitation
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92
Callback phishing via Adobe Sign comment
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d
Callback phishing solicitation in message body
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-solicitation-in-message-body-10a3a446
Brand impersonation: Quickbooks
1mo ago
Sep 29th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Potential prompt injection attack in body HTML
1mo ago
Sep 29th, 2025
Sublime Security
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Attachment: Callback phishing solicitation via image file
1mo ago
Sep 25th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Callback phishing via calendar invite
1mo ago
Sep 25th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-calendar-invite-95c84360
Attachment: Calendar invite from recently registered domain
1mo ago
Sep 25th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-calendar-invite-from-recently-registered-domain-d801521c
Callback Phishing via Zoom comment
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoom-comment-8ec30881
Callback phishing via DocuSign comment
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-docusign-comment-48aec918
Attachment: Callback phishing solicitation via text-based file
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-text-based-file-ca39c83a
Brand impersonation: Vanguard
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-vanguard-3bd048fe
Service Abuse: HelloSign share with suspicious sender or document name
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-hellosign-share-with-suspicious-sender-or-document-name-464d98f3