logo

Attackers Impersonate Top Brands in Callback Phishing

ID: 84cd7254-37fc-5181-9783-029d097d54c9

STIX ID: report--84cd7254-37fc-5181-9783-029d097d54c9

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2025-07-03

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Cisco Talos observed a surge in telephone-oriented attack delivery (TOAD) campaigns that impersonate brands such as Microsoft, PayPal, DocuSign, Norton and Best Buy to trick recipients into calling attacker-controlled VoIP numbers. Attackers use PDFs, fake transaction receipts, QR codes and other brand-impersonation lures to prompt callbacks; live voice interaction enables advanced social engineering to harvest credentials or enable malware installation. The report notes VoIP number reuse across days and global distribution of these campaigns, and recommends adding impersonation-detection engines to email security stacks and prioritizing technical controls alongside targeted user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.