logo

Callback phishing with online appointment abuse and distribution lists · Blog · Sublime Security

ID: 58afe049-31eb-5404-82e4-8e2c95c5375c

STIX ID: report--58afe049-31eb-5404-82e4-8e2c95c5375c

Feed Name: Sublime Security Blog

Threat Score
50/100

Date Published: 2025-11-13

Date Updated: 2026-05-01

...
...

Attack Spotlight: A callback-phishing campaign used a bank's online "Request a Meeting" form and distribution-list relays to send legitimate-looking autogenerated meeting confirmations containing urgent financial language and repeated attacker-controlled phone numbers, leveraging legitimate domains to evade authentication; Sublime detected and blocked these messages using signals like mismatched context, multiple phone numbers, urgent language, commonly abused brands, and suspicious return paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.