logo

Surge in callback phishing attacks abusing auto notifications, verifications, alerts, receipts, and more · Blog · Sublime Security

ID: ed359244-9fa9-5bcb-91c7-8b5f6a12cdaa

STIX ID: report--ed359244-9fa9-5bcb-91c7-8b5f6a12cdaa

Feed Name: Sublime Security Blog

Threat Score
60/100

Date Published: 2026-06-17

Date Updated: 2026-07-22

...
...

This Attack Spotlight details active callback-phishing campaigns that leverage legitimate cloud services and notification templates (Apple, Amazon SNS/Budgets, Grammarly, e-commerce receipts) to insert phone numbers and social-engineering text into messages delivered to distribution lists, increasing reach and evading traditional security; the report includes example payloads, detection signals (e.g., callback phishing in address fields, distribution list delivery, financial urgency), and mitigation recommendations such as input validation, template hardening, limiting free-trial features, and red-team testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.