Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Phishing

Callback Phishing: How Scams Get You to Call Them

Callback phishing flips the script on traditional scams. Instead of clicking a link, victims are baited into calling a fake support number, leading to fraud.

By · Published · 12 min read

A concerned person holding a smartphone to their ear, with a worried expression, sitting at a desk with a laptop open in a home office setting.

Callback phishing, also known as voice phishing or "vishing," is a social engineering attack where adversaries trick you into calling them. Unlike traditional phishing that relies on malicious links, these scams use urgent emails or text messages—often containing nothing more than a phone number—to bypass security filters and create a direct line of communication where a live scammer can manipulate their target.

How Callback Phishing Works

The attack preys on fear and a sense of urgency, moving the interaction from the inbox to a live phone call. This human-to-human element makes it uniquely effective. The scam typically unfolds in four distinct stages: the bait, the hook, the conversation, and the exploit.

1. The Bait: The attack begins with an email or message designed to cause alarm. It often impersonates a well-known company like McAfee, Norton, Microsoft, or Amazon, warning you about a large, imminent charge for a product or service renewal you never authorized. The email itself is intentionally simple, containing no links or attachments that would trigger email security scanners. Its only payload is text and a phone number to call to "cancel" or "dispute" the charge.

2. The Hook: The message creates a powerful sense of urgency. Seeing a notice that your account will be debited for $499.99 for a "Geek Squad Premium" subscription you don't have triggers an immediate fight-or-flight response. The path of least resistance appears to be calling the provided toll-free number to quickly resolve the issue.

3. The Conversation: When you call, you're connected to a scammer posing as a legitimate customer support agent. They are often well-trained, following a script designed to build rapport and establish credibility. They will sound professional, ask for an invoice or customer ID from the email, and confirm the fake charge. This is the core of the social engineering, where the attacker's goal is to gain your trust.

4. The Exploit: Once trust is established, the scammer initiates the final phase. Their objective varies, but it almost always involves getting you to perform an action that compromises your security. They might claim they need to connect to your computer to process the "refund" or remove the "malicious software" that triggered the alert. They will guide you to download and install a legitimate remote monitoring and management (RMM) tool like AnyDesk, TeamViewer, or ConnectWise ScreenConnect. With remote access, they can steal files, install malware like infostealers or ransomware, or trick you into logging into your bank account, which they can then drain.

FeatureTraditional Email PhishingCallback Phishing
Primary GoalSteal credentials via a fake login page.Gain remote access or extract information over the phone.
BaitMalicious link or attachment.Phone number in a plain-text email.
Security EvasionObfuscates links, uses lookalike domains.Bypasses link/attachment scanners entirely.
InteractionAsynchronous (victim vs. webpage).Synchronous (victim vs. live scammer).
Attacker FlexibilityLow (static webpage).High (scammer adapts their script in real-time).

The Psychology of the Callback Scam

Callback phishing is so successful because it exploits human psychology more effectively than many automated attacks. It bypasses technical defenses by targeting the person sitting at the keyboard.

First, it weaponizes fear and urgency. The prospect of losing a significant amount of money triggers panic, short-circuiting rational decision-making. The victim's focus shifts from questioning the email's legitimacy to stopping the impending financial loss. The most direct route offered is the phone number.

Second, it evades security software. Corporate and personal email gateways are sophisticated at detecting and blocking emails with suspicious links, known malicious attachments, and other technical red flags. But an email containing only text and a phone number often appears benign. This allows the initial bait to land in the target's inbox, something that is becoming harder for traditional phishing campaigns. You can learn more about classic email threats in our guide on how to spot a phishing email or text.

Finally, the human element is a powerful convincer. A static phishing page can be poorly designed or have tell-tale errors. A live, trained scammer, however, can build rapport, answer questions, and calmly address skepticism. They sound helpful and empathetic while guiding their victim toward a disastrous outcome. This personal touch disarms people who might otherwise be wary of a suspicious email.

Common Lures and Themes

Attackers use a variety of pretexts to make their bait convincing. While the tactics evolve, several common themes have proven highly effective.

Fake Antivirus and Tech Support Renewals This is the classic callback phishing lure. Scammers send fake renewal notices for popular antivirus products from Norton, McAfee, and Microsoft or services like Best Buy's Geek Squad. The renewal prices are intentionally inflated—often between $300 and $600—to guarantee a reaction from the recipient. The scammer, posing as support, will then offer to "help" remove the subscription, which is their entry point to take over the victim's computer.

Bogus E-commerce Orders Impersonating major online retailers is another popular method. An email might claim to be an invoice from Amazon for a new TV or a high-end laptop you didn't order. Similar to renewal scams, the goal is to shock the victim with a large, unexpected purchase and drive them to the phone. These campaigns can be highly convincing, often mimicking the look and feel of real order confirmations, much like the [Amazon Prime phishing schemes](/posts/amazon-prime-phishing-fake-billing-alert) that use fake billing issues as a hook.

Financial and Crypto Service Alerts Some callback campaigns impersonate banks, payment processors like PayPal, or cryptocurrency exchanges. These messages may warn of a large, unauthorized transaction or a security issue that requires immediate attention. Given the sensitivity of financial accounts, victims are highly motivated to call and secure their funds, only to be manipulated by the scammer on the other end of the line.

A Gateway to Corporate Ransomware

While many callback phishing attacks target individuals for immediate financial fraud, the tactic is increasingly used by sophisticated threat actors as an initial access vector into corporate networks. Groups like Scattered Spider and the operators behind BazarLoader have used callback phishing to gain a foothold in target organizations, leading to widespread data theft and ransomware deployment.

In a corporate setting, the attack targets an employee. The scammer convinces the employee to install an RMM tool on their work computer. Once they have that initial access, the attackers move silently through the network, escalating privileges, stealing credentials, and mapping out critical systems. This reconnaissance phase can last for days or weeks. Ultimately, they use their deep access to exfiltrate sensitive corporate data before deploying ransomware, crippling the organization's operations and demanding a multimillion-dollar ransom.

These attackers rely on the fact that phishing campaigns install remote admin tools for access, leveraging legitimate software to fly under the radar of security solutions. For businesses, a single employee falling for a callback scam can be the starting point of a catastrophic security incident.

How to Protect Yourself and Your Organization

Defense against callback phishing requires a combination of skepticism, verification, and technical controls. Whether at home or in the office, the core principles are the same.

Red Flags to Watch For

  • Urgency: The email demands you act immediately to avoid a negative consequence.
  • A Phone Number as the Main Call to Action: Legitimate companies typically direct you to their website to manage your account.
  • Unexpected Subscription/Order: The email is for a product or service you never bought.
  • Generic Greetings: The message uses a vague salutation like "Dear Customer" or "Hi user@example.com."
  • High Price: The charge is for an unusually high amount for the service mentioned.

If You Receive a Suspicious Email

  1. Do not call the number. This is the most critical step. Do not engage the attacker.
  2. Do not reply to the email or click any links if present.
  3. Verify independently. Log in to your official account with the company in question through a saved bookmark or by typing the official URL into your browser. Check your purchase history or subscription status there.
  4. Report the email. Use the "Mark as Spam" or "Report Phishing" feature in your email client. In a corporate environment, report it to your IT or security team immediately.

If You Have Already Called and Acted

If you called a number and suspect you were scammed, take these steps right away:

  • Disconnect your computer from the internet to sever any remote connection.
  • Revoke any shared access. If you allowed remote control, shut down the computer. Run a full scan with a reputable antivirus program. For total peace of mind, consider backing up your data and performing a full system restore or factory reset.
  • Change your passwords. If you entered any passwords while the attacker was connected or shared them, change them immediately on all affected accounts. Using a password manager can make this process much easier and help you maintain unique passwords for every site. Consider reading our guide on if you need a password manager.
  • Contact your financial institutions. If you provided any banking or credit card details, call your bank's official fraud department number immediately. They can freeze your cards and monitor your account for suspicious activity.

Building a Resilient Defense

For individuals, the best defense is a healthy dose of skepticism. Always verify unsolicited communications through an independent channel. Never install software at the behest of someone who contacted you unexpectedly, and never share passwords or authentication codes over the phone.

For organizations, a multi-layered defense is key. This starts with security awareness training that specifically educates employees on callback phishing tactics. Simulations can be particularly effective. On the technical side, organizations should implement application controls to prevent users from installing unauthorized RMM software. Endpoint detection and response (EDR) solutions can also help detect the malicious activity that follows a successful breach. Finally, enforcing phishing-resistant multi-factor authentication (MFA), such as FIDO2 security keys, can prevent attackers from using stolen credentials to move deeper into the network.

By understanding the mechanics and psychology of callback phishing, both individuals and organizations can better spot the bait and avoid taking the hook.

Read next