All resources

7 September 2026 · Threat Spotlight · CyberSec360 Australia

Threat Spotlight: Callback Phishing — the Scam That Makes You Dial the Attacker

Security filters hunt for malicious links and attachments — so one of the most effective phishing styles of recent years carries neither. Callback phishing (researchers call it telephone-oriented attack delivery, or TOAD) sends a clean, boring email: a subscription renewal, an invoice for something you never ordered, “your free trial converts to $499/year today — call this number to cancel.” The malicious payload is a phone number, and the victim delivers themselves to it.

How the call goes

  • A calm, professional “support agent” answers — this is a staffed operation, pioneered at scale by the BazarCall campaigns from 2021 onward and adopted by ransomware crews since.
  • To “process your refund” or “cancel the subscription”, they walk you through installing legitimate remote-access software — the same tools real IT support uses.
  • With that access, they “help” while quietly stealing credentials, planting persistence, or staging data theft — several documented ransomware intrusions began exactly this way.
  • Variants skip the malware entirely and simply guide victims through “refund” screens that drain accounts.

Why it works so well

Every trust signal is inverted. The email contains nothing scannable, so it lands in the inbox with a straight face. The victim initiates the call, which feels safe — we’re trained to fear incoming contact, not outgoing. And the fake charge creates urgency without threatening language: people call fast to stop a $499 bill. Small businesses are prime targets because a surprise software invoice is entirely plausible.

Defences that map to the con

  • The rule to teach: never call numbers from unexpected invoices. Look up the company independently and check your actual card or bank statement first — the “charge” usually doesn’t exist.
  • Treat remote-access software as radioactive: nobody installs it at the request of an inbound OR outbound support call that you didn’t arrange through known channels.
  • Application control (an Essential Eight strategy) stops unauthorised remote-access tools from running at all.
  • Tell staff to report the email even though “nothing happened” — a callback lure in one inbox means colleagues got it too.

Callback phishing is a reminder that the phish is the ask, not the medium. Filters can’t block a phone number — but a team that treats surprise invoices with independent verification beats the whole operation.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check