Attackers Impersonate Top Brands in Callback Phishing
ID: 84cd7254-37fc-5181-9783-029d097d54c9
STIX ID: report--84cd7254-37fc-5181-9783-029d097d54c9
Feed Name: Dark Reading
Date Published: 2025-07-03
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Cisco Talos observed a surge in telephone-oriented attack delivery (TOAD) campaigns that impersonate brands such as Microsoft, PayPal, DocuSign, Norton and Best Buy to trick recipients into calling attacker-controlled VoIP numbers. Attackers use PDFs, fake transaction receipts, QR codes and other brand-impersonation lures to prompt callbacks; live voice interaction enables advanced social engineering to harvest credentials or enable malware installation. The report notes VoIP number reuse across days and global distribution of these campaigns, and recommends adding impersonation-detection engines to email security stacks and prioritizing technical controls alongside targeted user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
