Surge in callback phishing attacks abusing auto notifications, verifications, alerts, receipts, and more · Blog · Sublime Security
ID: ed359244-9fa9-5bcb-91c7-8b5f6a12cdaa
STIX ID: report--ed359244-9fa9-5bcb-91c7-8b5f6a12cdaa
Feed Name: Sublime Security Blog
This Attack Spotlight details active callback-phishing campaigns that leverage legitimate cloud services and notification templates (Apple, Amazon SNS/Budgets, Grammarly, e-commerce receipts) to insert phone numbers and social-engineering text into messages delivered to distribution lists, increasing reach and evading traditional security; the report includes example payloads, detection signals (e.g., callback phishing in address fields, distribution list delivery, financial urgency), and mitigation recommendations such as input validation, template hardening, limiting free-trial features, and red-team testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
