Cyberoo logo
Home
|
About
|
Products
|
Solutions
|
Insights
|
Contact
Cyberoo logo
Leading the fight against scammers, supporting organisations globally in detecting and disrupting scams, including those preparing for regulatory frameworks such as Australia's Scams Prevention Framework
Menu
HomeAboutInsightsContact
Products
NothingPhishyScams.ReportMuleHunt
Solutions
SPF Compliance for Scam PreventionScam Detection & Threat IntelligenceDigital Risk & Infrastructure DisruptionWebsite Takedown & Digital Risk ProtectionPayment Scam & Mule Account IntelligenceScam Awareness & Behavioural Defence
Contact
Level 1/63 Ann Street,
Surry Hills
NSW 2010
info@cyberoo.ai
© All rights reserved | Cyberoo Pty LtdPrivacy PolicyTerms of Use
← ALL POSTS

Inside a Callback Scam: What Happens After You Call the Number?

Fake transaction alerts, invoice emails and account-security messages are often only the bait. The active attack begins when the recipient calls the number.

July 11, 2026 | Cyberoo Research & Analysis Team

Examples of callback scam messages impersonating a bank, PayPal and a cryptocurrency exchange, each directing the recipient to call a telephone number.
Click to view full size

Across recent cases reviewed by Cyberoo, the same pattern appears repeatedly. A message claims that a payment has been processed, a new cryptocurrency wallet has been linked, an app PIN has changed, a transfer has been scheduled, or an unwanted subscription has been renewed.

The message then offers an apparently simple solution:

Call this number immediately if the activity was not authorised.

A previous Cyberoo analysis explains why callback numbers matter as scam infrastructure. This article focuses on the next stage of the attack: what happens after a person calls.

What Is a Callback Scam?

A callback scam is a social-engineering attack in which a person is induced to call a telephone number controlled by a scam operation.

The initial SMS, email, invoice, attachment or notification is primarily a routing mechanism. Its purpose is to move the recipient away from a static message and into a live conversation where the operator can adjust the story according to the response of the caller.

Callback scams overlap with voice phishing, commonly called vishing, but the operating model is different. In conventional vishing, the scammer normally calls the target. In a callback scam, the target initiates the call after receiving a manufactured warning.

In enterprise security, this technique is often described as telephone-oriented attack delivery, or TOAD. Proofpoint notes that TOAD messages may avoid malicious links and attachments and instead direct the recipient to call a telephone number.

The Message Is Not the Main Attack

Many phishing messages rely on a malicious link, login page or attachment. Callback messages can avoid all three.

A fake invoice may contain only branding, a transaction amount and a telephone number. An SMS may contain no URL. The message can therefore appear less technically suspicious to the recipient and may also pass controls that focus heavily on links, attachments and known payloads.

Microsoft documented BazaCall campaigns that replaced the usual malicious link with a customer-service number and a live operator. When the recipient called, the operator supplied step-by-step instructions that led to malware installation and hands-on access to the device.

Key point: The absence of a link does not make the message safe. It can mean that the next stage has been moved to a telephone call.

The Most Common Callback Lures

LureTypical claimIntended reaction
Suspicious transactionA payment or transfer has been processed or scheduled.Call immediately to stop the payment.
Account security changeA PIN, password, device or wallet has been added.Call to secure the account.
Fake invoiceAn unfamiliar PayPal, retail or software purchase has been completed.Call to dispute the invoice.
Subscription renewalAntivirus, cloud storage or support services will renew automatically.Call to cancel and request a refund.
Cryptocurrency activityA new withdrawal address or wallet has been linked.Call before digital assets are transferred.
Technical alertA computer, account or service requires urgent support.Call the support desk.
Enterprise billing noticeA business service or licence is about to incur a charge.Call to prevent the charge.

PayPal warns that invoice and money-request scams may include alarmist notes that ask the recipient to call a fake customer-service number. The United States Federal Trade Commission has documented similar renewal messages that direct a recipient to call within a short period, after which the operator may seek remote access or stage a false refund.

A Related Variant: Reply Yes or No and Wait for the Call

Not every transaction-alert scam asks the recipient to call a number.

Cyberoo has also observed a related banking impersonation pattern in which the message asks whether the recipient made a transaction and instructs the person to reply Y or N. If the recipient replies Y, the interaction may end. If the recipient replies N, the recipient later receives a telephone call from someone claiming to represent the bank fraud or security team.

Strictly speaking, this is not a callback scam because the recipient does not initiate the telephone call. It is better understood as reply-triggered vishing or an interactive SMS-to-voice scam. These labels are descriptive Cyberoo terms rather than formal industry classifications.

The reply acts as a simple screening mechanism. A response of N confirms that the mobile number is active, the message was read, the supposed transaction caused concern, and the recipient is likely to answer a follow-up call. The scam operation can distribute messages at scale while reserving human operators for recipients who have already demonstrated engagement.

Accuracy note: A Yes-or-No transaction verification message is not automatically genuine or fraudulent. The safest action is to verify the claimed transaction through the official banking application or an independently sourced bank contact channel.

Diagram comparing a callback scam with reply-triggered vishing, showing how both paths lead to a live scam operator and financial or technical compromise.
Click to view full size

Two delivery paths, one conversion point: a live social-engineering call.

What Happens When the Victim Calls?

The precise conversation varies, but the structure is often consistent.

Stage 1: The Caller Is Triaged

By making the call, the victim has already confirmed that the telephone number is active, the message was received, the lure created enough concern to prompt action, and the caller is prepared to engage with a supposed support representative.

Some operations use an automated menu, hold music or a call queue. Others connect directly to an operator posing as a fraud analyst, billing officer, cryptocurrency-security specialist or technical-support representative.

Stage 2: The Operator Establishes Authority

The operator normally begins with a calm and professional tone. The person may say that the transaction can be cancelled, the invoice can be located, or the security alert can be resolved after account verification.

The caller may be asked to read an invoice number, transaction amount or reference displayed in the original message. This creates the appearance that the operator has located a real case, even though the caller has supplied the information.

Stage 3: Verification Is Reversed

A genuine support process may ask limited identity-verification questions. Scam operators exploit this expectation and turn verification into data collection.

  • Full name, date of birth, email address and residential address
  • Customer identifier, card number or account number
  • Security answers, password or PIN
  • One-time security code or authentication approval
  • Details shown in the official banking application

The victim believes that identity is being verified. In reality, the operator may be collecting information for account takeover, identity fraud or a live payment attempt. Scamwatch warns that bank impersonators may request account details, security codes or a transfer to a so-called safe account.

Stage 4: Urgency and Isolation Are Introduced

Once the caller begins cooperating, the operator increases pressure and reduces the chance of independent verification.

  • Remain on the line and do not call the bank separately
  • Do not discuss the matter with another person
  • Act before the transaction is completed
  • Ignore alerts displayed in the banking application
  • Approve an authentication request
  • Disable security software temporarily
  • Move to a quieter room or use a second device

The conversation often alternates between reassurance and urgency. The operator sounds helpful while repeatedly suggesting that delay will cause permanent financial loss.

Stage 5: The Call Moves to an Operational Outcome

The operator then attempts to convert concern into a measurable result: information, account access, remote access, a payment, malware installation or a transition to another communication channel.

Five-stage callback scam call sequence from caller triage to credential theft, remote access, payment fraud or malware installation.
Click to view full size

The live call turns a static alert into an adaptive social-engineering process.

The Main Attack Paths After the Call

1. Credential and Identity Theft

The operator may collect enough personal and account information to access an online account, reset a password, impersonate the victim in a later call, conduct an account-recovery attempt, or reuse the information in another fraud. Even when no money is lost during the original call, the data can support later attacks.

2. Account Takeover and Authentication Interception

In bank and cryptocurrency impersonation cases, the operator may attempt to access the real account while speaking to the victim. The victim then receives a genuine one-time code, login notification or device-authorisation request. The operator describes that genuine security control as part of the cancellation process.

A genuine code does not make the caller genuine.

3. Remote Access and Fake Refunds

Fake invoice and subscription-renewal scams frequently move into remote access. The operator may claim that a support application is required to cancel the transaction or process a refund. The caller is directed to install a legitimate remote-support product or visit a remote-access website.

Once access is granted, the operator can view files and browser sessions, observe online banking activity, capture credentials, manipulate displayed content, conceal transactions or install additional software. The Federal Trade Commission also describes a false-refund variation in which the victim is made to believe that too much money was returned and is then pressured to repay the nonexistent excess.

4. Transfer to a Safe Account

The operator claims that the current account is compromised and that funds must be moved to a secure holding account, investigation account or temporary account. There is no safe account. The destination normally belongs to a scammer, mule, payment intermediary or cryptocurrency service. Scamwatch states that a bank will not ask a customer to transfer money to keep it safe.

5. Malware Installation and Enterprise Intrusion

Some callback attacks target employees and business systems rather than individual consumer payments. The operator may send a follow-up email or direct the caller to a website where software must supposedly be downloaded to cancel a charge.

Microsoft documented BazaCall campaigns in which live operators guided victims through malware installation. The FBI also reported Silent Ransom Group callback-phishing activity in which pending-charge messages led victims to call, after which operators directed them to legitimate system-management tools that were used for data theft and extortion.

CategoryPrimary objective
Consumer callback fraudSteal money, account access, identity data or payment credentials.
Enterprise callback intrusionObtain device or network access, steal data, install malware or conduct extortion.

Why Transaction Alerts and PayPal Are Used So Often

Payment alerts create an immediate and believable reason to call. A person may ignore a general security warning but react quickly to a specific charge of several hundred or several thousand dollars. The amount is large enough to cause concern while remaining plausible as a retail purchase, software renewal or account transfer.

PayPal offers attackers two delivery paths. One is a fully counterfeit email or invoice image. The other is misuse of genuine invoice or money-request functions to send an unexpected request containing a fraudulent telephone number. PayPal advises users not to call numbers contained in suspicious invoices or money requests and to verify activity through the official website or application.

A Shift from Geographic Numbers to Mobile Numbers

Earlier callback cases reviewed by Cyberoo commonly used geographic landline-style numbers, inbound service numbers or VoIP-backed customer-service numbers. More recent Cyberoo casework includes a growing number of Australian mobile-format callback numbers. This is a Cyberoo operational observation, not a market-wide statistical conclusion.

A mobile number can appear ordinary and familiar to an Australian recipient. Provider identification can also be harder because mobile numbers can be ported between telecommunications providers. The number range that was originally allocated may not identify the current service provider.

For investigators, a mobile callback number should not be dismissed as a disposable personal number. It may route into a larger call flow, forwarding service, VoIP environment or organised campaign.

Can a Callback Number Be Taken Down?

A callback number has one useful property for defenders: it must receive calls. This distinguishes it from a spoofed caller ID, where the displayed number may belong to an unrelated person or organisation. A working callback number is normally connected to an active telecommunications service.

A practical disruption process includes the following steps:

  1. Preserve the original SMS, email, invoice or attachment.
  2. Record the callback number in a standard international format.
  3. Capture timestamps, sender details, email headers, claimed brands and the stated reason for calling.
  4. Verify the relationship between the message and the number through controlled investigation.
  5. Identify the likely current telecommunications provider or service chain.
  6. Build a concise evidence package and notify the provider, impersonated organisation and relevant authorities.
  7. Monitor whether the number remains reachable and whether a replacement number appears.
  8. Correlate the number with related domains, email senders, payment destinations and other campaign assets.

ACMA states that Australian telecommunications rules require providers to identify, trace and block scam calls and SMS. That obligation does not mean that every reported number will be disabled immediately.

Cyberoo casework shows several sources of delay: incomplete evidence, difficulty confirming the scam during provider checks, number porting, separation between the retail provider and upstream carrier, differing abuse channels, international service chains, and escalation teams that may not operate continuously. Attackers may also replace the number before a provider completes the review.

These limits reflect the wider problem described in Why Scam Infrastructure Is Hard to Remove. Detection is not removal. A provider must receive enough evidence, identify the service correctly and accept that action is justified.

The broader evidence and escalation process is explained in How Phishing Takedown Actually Works.

Workflow for investigating and disrupting a scam callback number through evidence collection, provider identification, escalation and monitoring.
Click to view full size

Callback number disruption is a provider-led evidence process, not a single automated action.

What Should a Consumer Do?

Do not use the telephone number contained in an unexpected SMS, email, invoice, pop-up or attachment.

  • Open the official application.
  • Type the official website address manually.
  • Use the number printed on the back of the bank card.
  • Find the contact number independently.
  • Review the real account for the claimed transaction.
  • Contact the organisation through a verified channel.

If a call has already been made, end the conversation, contact the real organisation, notify the bank if any financial or security information was disclosed, change affected passwords from a trusted device, block exposed cards, report unauthorised transactions and remove any remote-access software that was installed.

A suspicious message, screenshot, email or telephone number can also be assessed through Scams.Report.

Received a suspicious message, invoice or callback number?

Check it with Scams.Report and receive an explainable assessment of the available evidence.

CHECK A SCAM

What Should Banks and Digital Brands Do?

Organisations should treat callback numbers as infrastructure indicators rather than as text contained in a customer complaint.

  • Extract telephone numbers from screenshots, PDFs, image-based invoices and email bodies.
  • Preserve the original source, timestamps and delivery channel.
  • Record the claimed transaction, impersonated brand and pretext.
  • Normalise numbers into a searchable international format.
  • Correlate the same number across different messages, brands and campaigns.
  • Link the number with domains, email senders, fake profiles and payment destinations.
  • Maintain provider-specific telecommunications escalation paths.
  • Monitor whether a number is disabled, reassigned or replaced.
  • Preserve provider responses and disruption evidence for governance and reporting.

NothingPhishy supports evidence-led monitoring and disruption of scam infrastructure, including scam phone numbers and the associated impersonation campaign.

Where a callback conversation exposes a beneficiary account, PayID, payment link or cryptocurrency wallet, MuleHunt can help connect the payment destination to the wider scam operation.

Need to identify, correlate and disrupt scam infrastructure?

NothingPhishy supports evidence-led monitoring and disruption across scam websites, impersonation assets, fake applications and scam callback numbers.

TALK TO CYBEROO

The Call Is the Conversion Point

A callback scam may begin as an SMS or email, but the message is not where the main manipulation occurs.

The message creates fear. The number creates a path. The operator converts concern into action.

Once the call begins, the scammer can adapt the story, answer objections, collect information and guide the victim through actions that a static phishing page could not easily achieve. The safest response is not to out-argue the operator. It is to avoid entering the conversation through a number supplied by the suspicious message.

Frequently Asked Questions

What is a callback scam?

A callback scam is an attack in which a message, invoice or alert directs the recipient to call a number controlled by a scam operation. The live operator then attempts to obtain information, money, remote access or account control.

What happens when a person calls a scam callback number?

The operator may impersonate a fraud team or customer-support service, request identity information, ask for security codes, direct the caller to install remote-access software or instruct the caller to transfer money.

Is a callback scam the same as vishing?

Callback scams are related to vishing, but the victim initiates the telephone call. In conventional vishing, the attacker normally calls the victim directly.

What is reply-triggered vishing?

Reply-triggered vishing is a related pattern in which a message asks the recipient to reply Yes or No. A negative response identifies an engaged recipient, after which the scammer initiates a follow-up call.

Can a scam callback number be taken down?

A confirmed scam number may be reported to the current telecommunications provider for suspension or blocking. Action depends on provider identification, evidence quality, jurisdiction and the reporting process.

What should a person do after calling the number?

End the call, contact the real organisation through a verified channel, notify the bank if information was disclosed, change affected passwords and remove any remote-access software that was installed.

References

  1. Cyberoo – Callback Scams: Why the Number You Are Told to Call Back Matters
  2. Proofpoint – Cybersecurity Stop of the Month: Attack Sequence of TOAD Threats
  3. Microsoft Security – BazaCall: Phony call centers lead to exfiltration and ransomware
  4. United States Federal Trade Commission – How to recognize a fake Geek Squad renewal scam
  5. PayPal Australia – What are invoice scams and money request scams on PayPal?
  6. Scamwatch – Scammers impersonating banks in text messages, phone calls and emails
  7. ACMA – Combating phone scams
  8. ACMA – Rules for porting a phone number
  9. FBI and IC3 – Ransomware Actors Continue to Gain Access through Third Parties and Legitimate System Tools