
Most phishing training teaches your team to hover over links and never open a strange attachment. Callback phishing works because it has neither. The email is a few lines of plain text and a phone number, so your email filter finds nothing to block. The trap only springs when someone picks up the phone and calls the number.
That single change of channel, from inbox to phone line, is why this scam keeps landing on businesses that thought they were covered. Here is how it works and what actually stops it.
What is callback phishing?
Callback phishing, also called telephone-oriented attack delivery or TOAD, is a scam that starts with a plain email, usually a fake invoice or subscription renewal, and urges you to call a number to dispute the charge. There are no malicious links or files, so the message slips past email security. The real attack happens on the call.
Why does it slip past email security?
Email filters are built to catch known-bad links, malware attachments, and spoofed sender domains. A callback phishing email carries none of those. It is often sent from a freshly created account at a real provider like Gmail or Outlook, with a PDF that contains nothing but text and a phone number. There is simply nothing technical for the filter to flag.
The message also leans on money and urgency. A note claiming your card was charged $499 for antivirus you never bought is designed to make a busy owner or bookkeeper reach for the phone before they think it through. Attackers know a worried person moves faster than a careful one.
What happens when you call the number?
A person answers, calm and professional, playing the part of billing support. They confirm a few details, then offer to "cancel" the charge or "process the refund." To do that, they say, they need to connect to your computer, and they walk you to a website that installs a remote-access tool.
Once they control the machine, the friendly tone has done its job. They can plant malware, steal saved passwords and session tokens, drain a bank account through a fake refund form, or set the stage for ransomware. Because the victim invited them in, endpoint alerts that would have caught a drive-by download often stay quiet.
How common is callback phishing?
Common enough that it shows up in the millions. At its peak, security firm Proofpoint tracked more than 600,000 of these attacks per day, and the technique has climbed steadily since it first appeared in late 2021. Small businesses are a favorite target because they rarely have a dedicated help desk, so an unexpected "billing" call feels plausible, and because a single compromised bookkeeper can open the door to payroll and banking.
How small businesses stop callback phishing
You cannot filter your way out of this one, so the defense is a mix of habits and controls:
- Teach the pattern, not just the logo. Staff should treat any email that pushes them to call a number about a charge as suspect, especially for software they do not recognize.
- Verify through a channel you already trust. If a charge looks real, log into the vendor account directly or call the number on your actual statement, never the one in the email.
- Lock down remote-access tools. Block consumer remote-support apps on company machines so a panicked employee cannot install one mid-call.
- Give people a fast way to report. A one-click report button beats "email IT," because speed matters when the scam runs on urgency.
- Back your endpoints with real monitoring. Managed detection and response can catch the remote session and the follow-on malware even when the user let the attacker in.
None of this requires new software your team has to babysit. It requires a clear rule ("we verify charges before we call anyone") and the technical guardrails to back it up. If you are not sure which remote-access tools are already installed across your fleet, that is the first gap worth closing.
By The NetSys Group Team. The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Frequently asked questions
Is callback phishing the same as vishing?
They overlap. Vishing is any voice-based phishing. Callback phishing is a specific style where an email lures you into placing the call yourself, which makes the incoming request feel legitimate because you dialed the number. The end goal, stealing access or money over the phone, is the same.
Why didn't our spam filter catch it?
Because there was nothing to catch. The email has no malicious link or attachment and often comes from a real, newly made mailbox at a mainstream provider. Filters score it as ordinary text, so it lands in the inbox like any other message.
What should an employee do if they already called?
Disconnect, and do not install anything the caller asked for. If a remote-access tool was installed or credentials were shared, disconnect that device from the network and tell IT immediately. Fast reporting is what limits the damage, so no one should fear getting in trouble for speaking up.
Can security awareness training really help?
Yes, when it teaches the behavior rather than a checklist. Staff who know that "call this number about a charge" is a red flag will pause before dialing. Pair that with technical controls so a single mistake does not become a breach.
Want a second set of eyes on how your team handles suspicious billing calls and emails? Book a complimentary risk assessment and we will walk your defenses with you.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



