TL;DR:
- Callback phishing sends fake emails with phone numbers (not links) — victims call the criminals, who then talk them into handing over access, installing remote software, or making payments
- It bypasses email security because there are no malicious links or attachments — just text and a phone number, which automated scanners can’t flag as dangerous
- Staff training needs to cover this specifically: if an email asks you to call a number about an unexpected charge, software renewal, or account issue, call the company’s official number from their website instead
Most phishing training teaches people to hover over links before clicking and look for suspicious sender addresses. That’s still valid — but there’s a growing class of scam that doesn’t use links or attachments at all.
Callback phishing works like this. A criminal sends an email that looks like it’s from a well-known company — Microsoft, Amazon, PayPal, Norton, a bank, your accounting software provider. The email claims something has gone wrong: an unexpected charge has appeared on your account, your subscription is about to renew at a high price, your cloud storage is nearly full, or there’s been suspicious activity on your account.
Instead of a link to click, the email contains a phone number. “If this charge is incorrect, please call us urgently on 0800 XXX XXXX.” The victim, worried about the supposed problem, calls the number. A professional-sounding agent answers — often with fake hold music, a call queue, and company-specific patter. That agent is the criminal.
From there, the social engineering begins. The criminal typically asks the victim to install remote access software (AnyDesk, TeamViewer, QuickAssist) so they can “help resolve the issue” — and once inside, they access banking, email, or internal systems. Or they request card details, bank transfers, or gift card purchases to “process a refund.” Sometimes they’re after login credentials directly.
Why It Works
Email security tools — spam filters, URL scanners, sandboxes, DMARC checks — look for malicious links, known-bad domains, and suspicious attachments. A callback phishing email contains none of these. It’s just text and a phone number. Many email security systems pass these messages straight through.
The emails are often well-crafted. They use real company logos scraped from the web, professional formatting, and realistic invoice or subscription language. When your office manager receives what looks like an invoice from your software provider saying “Your annual renewal of £849 will be charged on Monday — call 0800 XXX XXXX to cancel or query this,” the natural response is concern, not suspicion.
And the phone interaction is where the criminals are genuinely skilled. They’re trained in social engineering, they create urgency, they have plausible-sounding answers to sceptical questions, and they guide victims through exactly what they need them to do.
Real Examples
Fake subscription renewals: Emails mimicking Microsoft 365, Norton, McAfee, PayPal, or Amazon Prime with inflated renewal amounts (often £300-900) designed to create panic about an unexpected large charge. When the victim calls to cancel, the agent either harvests banking details or installs remote access software.
Fake HMRC callback scams: Emails claiming HMRC has processed a tax refund or flagged your account, with a number to call to receive the refund or resolve the flag. HMRC communicates primarily by post for initial contact and never asks for card details over the phone.
Fake IT support calls: Emails to staff appearing to come from internal IT, asking them to call a support line about a system issue. These are particularly effective when scammers have done basic research on the company and reference realistic internal systems.
Fake bank callback fraud: Emails mimicking business banking providers about suspicious transactions. Banks do call customers about fraud, which makes this credible — but the real bank’s number is on the back of your card, not in an unsolicited email.
Protecting Your Business
The golden rule: never call a number from an email. If an email about an account problem, unexpected charge, or urgent issue includes a phone number, find the company’s contact number independently — from their official website (typed into the address bar, not searched), your existing contract documents, or the number on your bank card. Call that number, not the one in the email.
This sounds simple, but it needs to be explicitly taught. Many employees are accustomed to calling customer service numbers from emails — it’s a normal business practice. The distinction (“only if you initiated the contact or recognise it from a known document”) needs to be stated clearly.
Training should specifically name this attack type. Generic phishing training teaches link awareness. Callback phishing requires separate awareness: emails that ask you to call rather than click are not automatically safer. The phone call is the phishing mechanism.
Remote access software is a serious escalation. If anyone on a phone call — however professional they sound — asks your staff to install AnyDesk, TeamViewer, QuickAssist, or any remote access tool, staff should decline and escalate immediately. Legitimate tech support from vendors your business has contracted with would go through your IT team, not cold-contact individual employees asking for remote access.
Question unexpected charges. If an email claims an unexpected charge has occurred or is about to occur, check the actual account directly — log into your Microsoft 365 admin centre, PayPal, Amazon, or bank directly through bookmarked URLs, not through any email link or number. If there’s no corresponding charge in the actual account, the email is fake.
Set up a simple internal reporting process. Staff who receive suspicious callback phishing emails should be able to forward them somewhere for rapid review — a dedicated email address, a Slack channel, or just a text to their manager. A quick second opinion before calling that number can stop an incident.
If Someone Has Already Called
If a member of staff has already called the number and the interaction seemed suspicious, assume it may have been a fraud call and take these steps:
-
If remote access software was installed: disconnect the device from the network immediately and don’t turn it back on until IT has reviewed it. Remote access tools give criminals full control of the machine while the session is live — and often leave behind additional software.
-
If credentials were shared: change passwords immediately from a different device, enable MFA if it isn’t already active, and check account login history for unfamiliar sessions.
-
If payment was made: contact your bank immediately. Faster Payments can sometimes be recalled if actioned quickly. Report the fraud to Action Fraud (0300 123 2040) and your bank’s fraud team.
-
If card details were shared: request a new card immediately. Don’t wait to see if fraudulent charges appear — if the number was read out to a criminal, assume it’s compromised.
The NCSC’s Suspicious Email Reporting Service (report@phishing.gov.uk) accepts callback phishing emails — forwarding them helps the NCSC track patterns and take action against the numbers being used.