Callback Phishing
A phishing attack that avoids malicious links entirely, instead pressuring the victim to call a phone number where a live scammer completes the attack.
Definition
Callback phishing, sometimes called telephone-oriented attack delivery, is a phishing technique in which an email contains no malicious link or attachment, only a phone number and an urgent reason to call it, such as a fake subscription invoice or account alert. When the victim calls, a live scammer on the other end talks them through installing remote access software or revealing sensitive information.
A typical callback phishing email looks like a receipt for an expensive purchase or subscription renewal the victim never made, along with a customer service number to call to dispute or cancel it. Because the email contains no link and no attachment, it easily passes through spam filters and security tools designed to detect malicious URLs or files. Once the victim calls out of concern about the unexpected charge, they reach a scammer posing as a support agent, who guides them step by step into installing remote access software, sharing a one-time code, or providing payment details.
This technique matters because it deliberately sidesteps the technical controls organizations rely on most, since there is nothing malicious in the email itself for automated tools to flag, and it exploits the trust people place in a live human voice over a written message. The approach has proven effective against corporate employees, not just consumers, because a plausible IT support or vendor invoice scenario can convince even security-aware staff to make the call. Because the entire attack happens over a live phone conversation, it can be adapted in real time to overcome a victim's hesitation in a way a static phishing email cannot.
Employees should be trained to verify any invoice or account alert through the official website or a known customer service number, never the number listed in the email itself, before calling anyone back. Organizations should establish policies against installing remote access software at the direction of an unsolicited phone caller, regardless of how legitimate the caller sounds. Reporting suspicious callback phishing emails, even without a malicious link to point to, helps security teams track this technique as it evolves.
At a glance
- Severity
- Medium-High
- Prevalence
- Growing
- Primary targets
- Employees and consumers who respond to fake invoice or subscription alerts
- Also known as
- TOAD, telephone-oriented attack delivery
How it works
- 1
Bait email: the victim receives an email with no link or attachment, only a phone number and an urgent reason to call, such as a fake invoice.
- 2
Filter evasion: because the email contains nothing malicious to scan, it easily passes spam filters and link-detection tools.
- 3
The call: the victim, concerned about the unexpected charge, calls the number provided.
- 4
Live manipulation: a scammer posing as a support agent talks the victim through installing remote access software or sharing sensitive information.
- 5
Compromise: the attacker gains remote control, payment details, or credentials directly from the live conversation.
Warning signs
- An email invoice or subscription alert for something you never purchased
- A request to call a phone number rather than click a link
- No malicious link or attachment, just urgency to call
- A support agent asking you to install remote access software
- Pressure to act quickly to dispute or cancel an unexpected charge
How to defend
- Verify any invoice or account alert through the official website or a known customer service number
- Never call the number listed in an unsolicited email; look it up independently
- Never install remote access software at the direction of an unsolicited caller
- Report suspicious callback phishing emails even without a malicious link to point to
- Train employees to treat urgent phone-based instructions with the same scrutiny as suspicious links
Real-world example
An employee receives an email that looks like a receipt for an expensive antivirus subscription renewal they never made, with a number to call to dispute it. Concerned, they call the number and reach a scammer posing as support, who talks them into installing remote access software that gives the attacker control of their computer.
How Claro helps
Claro's phishing simulation library includes callback phishing scenarios, since link-based awareness alone leaves employees unprepared for attacks that move the deception to a phone call.
Frequently asked questions
Why does callback phishing avoid using links or attachments?
Removing any malicious link or attachment lets the email pass through spam filters and security tools built to detect malicious URLs or files, since there is nothing technical for them to flag.
How is callback phishing different from vishing?
Vishing starts with an unsolicited phone call. Callback phishing starts with an email or text that convinces the victim to initiate the call themselves, which makes the victim feel more in control and less suspicious.
What should I do if I receive a suspicious invoice email with a phone number?
Do not call the number in the email. Look up the company's official customer service number independently and verify the charge through that channel instead.
What should I do if I already called and installed software?
Disconnect the device from the network, uninstall the remote access software, change any passwords you may have shared, and report the incident to your security team immediately.
Related terms
Vishing
Vishing is a voice-based social engineering attack where a caller impersonates a trusted party over the phone to trick victims into revealing sensitive information or authorizing fraudulent actions.
Pretexting
A social engineering tactic where an attacker invents a false scenario to trick a target into revealing information or granting access.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo