Blog/Phishing

Callback Phishing: The Fake Invoice With a Phone Number

Callback phishing emails contain no links, just a fake invoice and a phone number to cancel. How the call leads to remote access, refunds scams or malware, and how to avoid it.

CyberWatch AI1 October 2026 · 2 min read
A man on a phone call at a desk with his laptop

Callback phishing turns the usual attack around. There is no link to click. Instead, an email says you have been charged for something expensive, such as an antivirus renewal or an online order, and gives a phone number to cancel. You call, and a friendly agent takes it from there.

How it unfolds

  1. The email: an invoice or receipt for a purchase you did not make, with a phone number.
  2. The call: you ring to cancel; an "agent" answers.
  3. The pivot: to process the refund, they ask you to visit a website, install remote access software, or log in to your bank.
  4. The theft: they take money, install malware, or stage a refund scam.
Illustrative example · Email
Order Confirmation #INV-0000 Premium Security Suite (3 years) - USD 499.00 Your account will be charged within 24 hours. If you did not authorise this purchase, call our billing helpline: +1 (8XX) XXX-XXXX
Red flags: an unexpected high charge, a short deadline and a phone number instead of a link to your account.

How to protect yourself

  • Never call a number from an unexpected invoice email.
  • Check statements and your real accounts through official websites or apps.
  • Never install remote access software for someone who contacted you. See remote access requests during a call.
  • Report the email as phishing.

At work

Callback phishing is used to get staff to install remote tools, leading to wider attacks. Report such emails to IT and never install software at a caller's request.

Got an unexpected invoice? Paste it into CyberWatch AI Scan for a free check.

Related: fake subscription renewals. For more, read the complete guide to phishing.

Frequently asked questions

Why no link in the email?

Emails without links are harder for filters to catch. The phone call is where the real attack happens.

What happens on the call?

The 'agent' offers to cancel or refund, then asks you to install remote access software, visit a site, or share payment details.

How do I check if I really have a subscription?

Check your bank statements and your accounts on the official websites or app stores. Never call the number in the email.

Sources

  1. How To Spot, Avoid, and Report Tech Support Scams, US Federal Trade Commission
  2. Refund and Recovery Scams, US Federal Trade Commission
  3. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.