
Callback phishing is one of the fastest-growing cyberattack techniques targeting businesses today. Unlike traditional phishing, it weaponizes your instinct to pick up the phone, and once an employee dials that number, your organization's data, finances, and reputation are all at risk. Here's exactly how callback phishing works, how to recognize it, and what your team can do right now to stop it.
What Is Callback Phishing?
Callback phishing, sometimes called telephone-oriented attack delivery (TOAD), is a two-stage cyberattack that starts with a deceptive email and ends with a phone call to a fraudulent "support agent." What makes it especially dangerous is what it deliberately leaves out: no malicious links, no suspicious attachments, nothing for your email security filters to catch.
The attack succeeds by exploiting human psychology rather than software vulnerabilities. It bypasses your technical defenses and targets the one thing no security tool can fully patch: human judgment under pressure.
Expert Insight: Callback phishing campaigns have surged in recent years because they sidestep traditional email security tools. By moving the attack off email and onto a voice call, threat actors avoid detection by spam filters and sandboxes that scan for links and attachments.
How Does Callback Phishing Work, Step-By-Step?
Understanding the mechanics of a callback phishing attack is the first step in defending against it. Here's how the attack unfolds from the first email to a full network compromise:
- The bait email arrives. An employee receives an email claiming they've been charged for a subscription service such as antivirus software, IT support, or a cloud tool are common examples. The email includes a dollar amount large enough to trigger concern and a phone number to "dispute the charge." No links. No attachments.
- The employee calls the number. Confused or alarmed, the target employee calls to cancel. They reach a convincing "support agent" who seems eager to help resolve the problem.
- Remote access is established. The attacker guides the employee through steps to "reverse the charge", which actually install remote access software (RAT) or malware on the device.
- The attacker takes control. Once inside, threat actors can steal credentials, exfiltrate sensitive data, deploy ransomware, and move laterally across your network, all while the employee believes they were just canceling a subscription.
⚠️ Key Risk: The employee never knows they were attacked. They believe they resolved a billing issue. The breach may not be discovered for days, weeks, or longer.
How to Recognize a Callback Phishing Email
Callback phishing emails are designed to look credible. But they consistently share a set of identifying characteristics your team can learn to spot. Here are 5 red flags to look for in suspicious billing emails:
- No business email address. Legitimate companies send billing communications from branded domains (e.g., billing@company.com). Callback phishing emails often come from generic addresses like Gmail or Yahoo.
- Spelling and grammatical errors. Professional organizations proofread customer communications. Errors in language or formatting are a reliable signal something is wrong.
- Artificial urgency. Phrases like "You have 2 hours to dispute this charge" are designed to pressure recipients into acting before they think critically.
- A phone number and nothing else. If the only actionable item in a billing email is a "customer service" number with no account portal link, no detailed invoice, no company address, treat it as highly suspicious.
- Unexpected charges for services you don't use. Threat actors often reference software or services the recipient has never heard of, counting on confusion to prompt a call.
5 Ways to Protect Your Organization From Callback Phishing
Defending against callback phishing requires a layered approach that combines technical controls, employee training, and clear internal procedures. Here are the 5 most effective measures your organization can implement today:
1. Deploy advanced email security
Email security platforms with AI-powered anomaly detection can flag suspicious billing emails even without malicious links or attachments, catching TOAD attacks at the perimeter before they reach employee inboxes.
Look for solutions that:
- Flag emails from non-business domains claiming to be from known vendors
- Identify urgency language and pressure tactics
- Detect domain spoofing (Micr0soft, Microsoift, etc.)
- Scan email metadata for spoofing attempts
2. Train employees regularly
Security awareness training that includes callback phishing scenarios, not just link-based phishing, closes the human vulnerability these attacks rely on. Simulate TOAD attacks to test retention and measure improvement over time.
Learn more: Cybersecurity Training for Employees
3. Establish a clear vendor verification process
Create a written policy: any billing discrepancy must be verified by looking up the vendor's official contact information independently, never by calling a number provided in the email itself. Post and share this policy visibly (desk posters, company intranet, email signature reminders).
4. Restrict remote access software
Use endpoint management and application control tools to prevent unauthorized installation of remote desktop applications, which are the attacker's primary tool after the phone call is complete. This doesn't prevent the initial compromise, but it dramatically increases detection likelihood and limits attacker capabilities.
5. Monitor for suspicious activity
Managed detection and response (MDR) and security operations center (SOC) monitoring can identify unusual remote access sessions, lateral movement, and data exfiltration in real time, even when the initial entry was via a phone call rather than a network exploit.
Bonus: Implement zero-trust principles
Least-privilege access, multi-factor authentication (MFA), and network segmentation limit the blast radius if a callback phishing attack does succeed in gaining a foothold on one device.
FAQ: Callback Phishing Questions Answered
Q: What's the difference between callback phishing and vishing?
A: Vishing (voice phishing) is any social engineering attack conducted by phone. Callback phishing is a specific type of vishing where the attacker tricks the user into calling a malicious number. All callback phishing is vishing, but not all vishing is callback phishing.
Q: Can legitimate software be used in callback phishing attacks?
A: Yes. TeamViewer, AnyDesk, and Chrome Remote Desktop are legitimate tools often used in callback phishing after the attacker tricks an employee into installing them. This makes detection harder because the software itself isn't malicious—the attacker's use of it is.
Q: Should employees ever call vendor support numbers provided in emails?
A: No. Always call the vendor's official number found on their website, or through independently verified contact information. This simple rule stops most callback phishing attacks.
Q: What if an employee thinks they're being socially engineered during a phone call?
A: They should end the call immediately and report it to the security team. No legitimate vendor will be offended if you hang up to verify their identity independently.
Q: How do attackers make their phone numbers look legitimate?
A: Through caller ID spoofing. Technology allows attackers to make any number appear on caller ID. Never trust caller ID. Always verify by calling the company's official number directly.
Q: Can advanced email filtering catch all callback phishing emails?
A: No. Callback phishing emails are intentionally plain—no links, no attachments, no suspicious content. Email filters can reduce volume, but won't catch all. Employee training is essential.
Q: What if an employee already shared their password?
A: Reset the password immediately. Check if the account was accessed from unexpected locations. Review account activity for unauthorized access. Consider resetting related accounts too (email used for password recovery, etc.).
Q: How long can attackers lurk undetected after gaining access?
A: Weeks, months, or longer. Without active monitoring (EDR, MDR), attackers can establish persistence and maintain access for extended periods. This is why detection matters as much as prevention.
Q: Should we fire employees who fall for callback phishing?
A: No. These employees are victims of sophisticated social engineering, not security negligence. Create a supportive environment where employees report incidents. Blame creates cover-up behavior.
Q: How do we simulate callback phishing for training?
A: Have a trusted third party call employees and attempt callback phishing scenarios. Track who doesn't fall for it and recognize them. Track who does and provide additional training. Measure improvement over time.
Q: What's the difference between MDR and SIEM for detecting callback phishing?
A: SIEM (Security Information and Event Management) correlates logs. MDR (Managed Detection and Response) actively hunts threats and responds. For callback phishing detection, MDR is superior because it actively looks for suspicious access patterns, not just correlating logs.
Q: Can VoIP make callback phishing easier?
A: Yes. VoIP systems make caller ID spoofing easier. Emphasize that caller ID cannot be trusted. Rely entirely on independently verified phone numbers.
Q: What role does cyber insurance play in callback phishing incidents?
A: Cyber insurance can cover breach notification costs, forensics, and business interruption. But insurance doesn't prevent incidents. Prevention through training, email security, and incident response is primary.
Q: Are new employees at higher risk?
A: Yes. They're less familiar with company procedures and more likely to follow instructions from "authority figures." Prioritize callback phishing training for new hires.
Q: How does callback phishing relate to ransomware attacks?
A: Callback phishing is often the entry point for ransomware. Attacker gains access via callback phishing → establishes persistence → deploys ransomware. This is why detection and rapid response are critical.
Q: Can callback phishing attacks be conducted without email?
A: Yes. Cold calling employees directly is another variant. Attacker calls claiming to be from vendor support. Bypass the email entirely.
Q: What should a callback phishing incident response plan include?
A: Employee reporting procedures, escalation paths, forensics access, credential reset procedures, communication templates, and regular testing of the plan.
Q: How does callback phishing differ for remote vs in-office employees?
A: Remote employees may be more isolated and less likely to verify with colleagues. They also may have home networks less well-protected. Emphasize verification procedures for remote workers.
Callback Phishing Is Preventable
Callback phishing is sophisticated, growing, and designed to bypass technical defenses. But it has one critical weakness: it depends entirely on human decision-making under pressure.
Your best defense is a combination of:
- Email security
- Employee training
- Clear procedures
- Technical controls
- Detection and response
Organizations that implement these five strategies can reduce callback phishing success rates. The investment in training and procedures is modest compared to the cost of a successful attack.
Start by downloading our Cybersecurity for Employees Guide.
Turn your team into your first line of defense against cyber attacks.
95% of breaches involve human error. Our free guide gives your employees the knowledge to spot threats before they become incidents — no IT background required.

