logo

Insights into the clustering and reuse of phone numbers in scam emails

ID: 492d7e86-c3d6-5e8d-898c-e6b32b871a62

STIX ID: report--492d7e86-c3d6-5e8d-898c-e6b32b871a62

Feed Name: Cisco Talos

Threat Score
55/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Omid Mirzaei

...
...

Cisco Talos analyzed scam email campaigns (Feb 26–Mar 31, 2026) and found phone numbers—predominantly VoIP—as durable, high-value IOCs: 1,652 unique numbers were observed with a median lifespan of ~14 days, frequent reuse and cool-down tactics, sequential DID block provisioning, and cross-brand recycling. Talos recommends shifting detection from ephemeral sender addresses to phone-number clustering and real-time reputation sharing between security and telecom providers to expose organized call-center infrastructure and mitigate these large-scale social-engineering campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.