ScamsPhishing

Telephone-Oriented Attack Delivery Scams Pressure Targets Into Calling

Telephone-oriented attack delivery (TOAD) is a form of social engineering that uses email to persuade the target to call a provided phone number. Unlike traditional phishing campaigns, TOAD emails contain no malicious links or attachments, which can help them bypass email security filters. They use phone conversations to build trust and familiarity with the threat actor.

These campaigns begin with urgent-sounding emails that use pretexting to create the bait. Pretexting relies on believable scenarios, such as payment processing issues, suspicious account activity, unexpected transactions, or subscription renewals, to prompt the target to call a provided phone number for further assistance. They may appear to come from trusted companies or even trusted individuals, such as helpdesk staff. These deceptive messages are deliberately designed to prompt the recipient to act quickly, often setting a short deadline to resolve the issue.

Fraudulent PayPal order confirmation email listing a support phone number
A TOAD email impersonating PayPal and urging the recipient to call a support number.

Once a call is placed, threat actors use social engineering tactics to pressure their target into following their instructions, claiming they will help cancel a payment or subscription or fix the purported issue. These instructions may include providing payment or personal information, clicking a link, downloading or installing software, sharing credentials, or opening an attachment in a follow-up email. They may also request remote access or trick an unsuspecting user into granting it.

As with other popular forms of cybercrime, TOAD-as-a-service business models can provide threat actors with rentable call centers, spoofed phone numbers, AI capabilities such as voice cloning, and email templates and tools to further escalate attacks, leading to a massive surge in these scams.

Recommendations

  • Facilitate user awareness training to include these types of phishing-based techniques.
  • Confirm requests from senders via contact information obtained from verified and official sources.
  • Review the Don’t Take the Bait! Phishing and Other Social Engineering Attacks NJCCIC product for more information on common phishing and social engineering attacks.
  • Ensure MFA is enabled for all online accounts.
  • If you suspect an account has been compromised, change the account’s password immediately and add a secondary authentication method.
  • Users who shared credit card information are advised to contact their banking institutions to cancel their credit cards and identify fraudulent purchases.