Callback Phishing
Callback phishing (TOAD) is an attack where an email lures the victim into phoning a fake support line, moving the scam to a live phone call.
Callback phishing — also called TOAD (telephone-oriented attack delivery) — is a hybrid attack that starts with an email but does its real damage over the phone. Instead of a malicious link or attachment, the email contains only a phone number and a reason to call it: a fake invoice for a subscription renewal, a fraud alert, or a pending charge of a few hundred dollars.
How it works
The initial email is deliberately clean. With no link to scan and no attachment to detonate, it sails past secure email gateways — there is nothing for a filter to flag. The pressure comes from the content: "You have been charged $349.99 for your annual antivirus renewal. To dispute this charge, call our billing team."
When the victim calls, a live operator takes over. From there the attack typically goes one of two ways:
- Remote access. The "support agent" walks the victim through installing a legitimate remote-desktop tool (AnyDesk, TeamViewer, Quick Assist) to "process the refund," then uses that access to steal data, drain accounts, or deploy ransomware. Several major ransomware groups have used exactly this playbook.
- Payment or credentials. The operator "verifies identity" by collecting card numbers, banking logins, or one-time passcodes in real time.
Callback phishing works because a phone call feels more legitimate than an email, and because the victim initiates it — calling a number you chose to dial defuses suspicion in a way an inbound call never could. A related setup inverts the sequence: the attacker floods the victim's inbox with email bombing first, then calls posing as IT support offering to fix the mess.
How to defend against it
- Treat unexpected invoice-plus-phone-number emails as phishing, even with no link present. Verify charges through the provider's official website or app, never the number in the message.
- Restrict remote access software. Block or allowlist remote-desktop tools so a persuaded employee cannot install one on demand.
- Simulate the full chain. NOUSEC simulations can combine email lures with voice-channel follow-ups, building the reflex our guide to vishing and smishing attacks covers in depth.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo