Most phishing training still centers on the same instruction: don't click the link, don't open the attachment. Callback phishing was built around that exact gap. The email that starts it has neither. It's a plain notice, often styled to look like an invoice, a software renewal, or a subscription charge, with a total, a case number, and a phone number to call about it. There's nothing for a spam filter to scan and nothing for an employee's training to catch, because the entire attack hasn't happened yet. It happens on the call.
1. The format is the evasion
Email security tools are built to catch what's embedded in a message: malicious links, infected attachments, spoofed sender domains carrying a payload. A callback phishing email carries none of that. It's frequently sent from a real, unflagged mailbox or a legitimate mass-mail service, with a subject line built to create mild urgency about a real-sounding charge. Because the message itself does nothing harmful, it routinely lands in the inbox instead of the spam folder, and it doesn't trip the "hover before you click" habit most security awareness training spends its time building.
2. The call is where the work happens
The number connects to a live person, often running a script polished enough to sound like a real support line, sometimes for a period holding, a case lookup, or a brief transfer that adds to the illusion. The goal of that call is to get the person on the other end to do one of two things: open a website and run a piece of remote access software like AnyDesk, TeamViewer, or ScreenConnect so the "agent" can "process the cancellation," or read off payment or account details to "verify" the charge. Once a remote tool is running with the caller watching, everything on that screen, saved passwords, open accounting software, a banking portal, is reachable.
3. A professional call is not the tell
The instinct to distrust a message full of typos and urgency doesn't apply here, because the email is deliberately bland and the call is deliberately smooth. The tell isn't tone, it's verification. A real vendor's invoice can be checked against last month's actual charge or a prior receipt without touching anything in the new email. A real renewal can be looked up by going to the software directly, not through a link or number the message supplies. Anyone calling back should be calling a number found independently, not the one printed in the email itself, which is the same logic already applied to a suspicious link and just as easy to build into a habit.
This is close cousin to the impersonation calls covered in how a fake help desk call talks an employee into installing remote access software, and it sits in the same family as other voice-based social engineering a small business runs into. What makes callback phishing worth calling out on its own is that it doesn't rely on impersonating anyone internal. It just needs one invoice-shaped email and a phone number nobody thinks to question, because nothing about the email itself looks wrong.
Frequently asked questions
What makes callback phishing different from a normal phishing email?
A normal phishing email asks the reader to click a link or open an attachment, which is exactly what spam filters and security awareness training are built to catch. Callback phishing has neither. The email is a bare notice with a phone number, so it slips past link-scanning and attachment-scanning entirely, and the actual attack happens later on a live phone call.
Is it risky just to dial the number in one of these emails?
The call itself doesn't install anything. The risk starts if the person on the line asks you to open a website, type in a code, or run a piece of software to fix or cancel whatever the email claimed. Hanging up and calling back a number found independently, not the one in the email, is what keeps the call safe to make.
If the email looks professional with no typos, how do you spot it?
Polish isn't the tell anymore. The reliable check is whether the email can be verified independently of itself: look up the vendor or biller through a bookmark or a prior invoice, not through any number or link the email supplies, and confirm the charge or renewal exists before calling anyone back.
Not sure your team would catch a callback phishing call before remote access software gets installed?
30 minutes with an engineer with DoD infrastructure experience. We'll walk through what your team would actually do with a call like this, and where security awareness training needs to cover phone-based social engineering, not just email.
Book your free assessmentPrefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.