Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Google callback scam
4h ago
Oct 6th, 2026
Sublime Security
Service Abuse: American Express callback scam
5h ago
Oct 6th, 2026
Sublime Security
Service abuse: Microsoft Power Apps callback scam
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: QuickBooks
6d ago
Sep 30th, 2026
Sublime Security
Service abuse: Apple callback scam
7d ago
Sep 29th, 2026
Sublime Security
Callback phishing via e-signature service
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing via Adobe Sign comment
8d ago
Sep 28th, 2026
Sublime Security
PayPal invoice abuse
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing via Xodo Sign comment
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing: SumUp infrastructure abuse
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via image file
8d ago
Sep 28th, 2026
@vector_sec
Attachment: Image-only docx/pptx callback phishing
8d ago
Sep 28th, 2026
Sublime Security
Service abuse: Payoneer callback scam
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing solicitation in message body
8d ago
Sep 28th, 2026
Sublime Security
Service abuse: Dropbox share with suspicious sender or document name
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing via SignFree e-signature request
8d ago
Sep 28th, 2026
Sublime Security
Callback Phishing via Signable E-Signature Request
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Personalized fake order/invoice file naming pattern
8d ago
Sep 28th, 2026
Sublime Security