Attack Type: Callback Phishing

Callback phishing is a straightforward but dangerous scam that usually begins with a fake invoice or receipt. These attacks often appear to be a charge from a well-known company, such as Norton, McAfee, Geek Squad, or Apple. The email includes a phone number to call if the charge wasn't authorized. The goal is to get you to call that number, not to click a link.
Once you're on the phone, the attacker often poses as a customer service representative. They might ask for personal information, offer to help you “cancel the charge,” or convince you to install remote support software. From there, they can access your device, steal sensitive data, or walk you through a fake refund process that results in real financial loss.
Because there’s often no link or attachment in the email, these messages can bypass traditional security filters. Once the conversation moves to a phone call, it’s out of sight from most security tools. That’s what makes this type of attack so effective and why it’s important to verify unexpected emails or charges through official channels, not the contact info provided in the message.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback phishing: Zero-width character obfuscation from freemail sender
2d ago
Aug 5th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
2d ago
Aug 5th, 2026
Sublime Security
Brand impersonation: SiriusXM
3d ago
Aug 4th, 2026
Sublime Security
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Quickbooks
11d ago
Jul 27th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
11d ago
Jul 27th, 2026
Sublime Security
Callback phishing via Microsoft comment
11d ago
Jul 27th, 2026
Sublime Security
Service abuse: FileMail callback scam
14d ago
Jul 24th, 2026
Sublime Security
Service abuse: Coursera callback scam
17d ago
Jul 21st, 2026
Sublime Security
Stripe invoice abuse
24d ago
Jul 14th, 2026
Sublime Security
Service abuse: Calendly callback scam detection
24d ago
Jul 14th, 2026
Sublime Security
Service abuse: Oracle Cloud Workflow callback scam
28d ago
Jul 10th, 2026
Sublime Security
Service abuse: Facebook mail notification callback scam
29d ago
Jul 9th, 2026
Sublime Security
Callback phishing via Google Meet
30d ago
Jul 8th, 2026
Sublime Security
Brand impersonation: McAfee
1mo ago
Jun 26th, 2026
Sublime Security
Service abuse: Settime.io sender with callback scam intent
1mo ago
Jun 24th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
1mo ago
Jun 17th, 2026
Sublime Security
Service abuse: IBM IAM account notification with callback scam indicators
1mo ago
Jun 16th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
1mo ago
Jun 11th, 2026
Sublime Security