A bench whose envelope tray holds only a number plate with the link clamp empty, a light disc keeping the alarm needle below its trip line, and an outbound horn line returning a tool cradle.

Callback Phishing (TOAD)

Callback phishing, also called TOAD, is a phishing email that carries a phone number instead of a link, so the victim places the call. MITRE ATT&CK has no technique of that name, and the FBI has documented one group escalating from the call to sending a person into the building.

Every page in a full capture of both major search engines describes the same thing: an email about an urgent problem, a number to ring, a scammer waiting on the line. The word that appears in nearly all of them is urgent.

The most detailed government description of this attack says the opposite. It says the sums involved are kept small precisely because small sums are "less likely to generate immediate suspicion". That advisory is a US federal notification that uses the term "callback phishing" by name, and nothing on either search engine's first page links to it.

So this page reports what the framework actually holds on this term (very little, and it was checked rather than assumed), what that advisory says, and why the least alarming email in your inbox is the one designed to make you dial.

A filter collar clamped shut on an envelope carrying a link plate, while an identical envelope carrying only a number plate passes through the open collar to an outbound horn.

Explain it like I'm 10

Most scam emails want you to click something, and a lot of software is checking those links before they reach you.

This one has no link. It has a phone number and a small bill you do not remember agreeing to. You ring up to sort it out, and the person who answers the phone is the scammer, waiting for your call.

The clever part is that you called them. People are far more trusting of a conversation they started themselves, and nothing about the email set off any alarms, because there was nothing in it to catch.

Callback Phishing Quiz

Test your knowledge about Callback Phishing - maybe you already know everything about it.

EasyQuestion 1 of 3

What does a callback phishing email carry instead of a link?

A searched catalogue drum where one index tab carries a very small clipped slip underneath it and another tab position stands entirely empty.

What the framework has on callback phishing

Start with the framework. It settles a question quickly and then gets out of the way.

The MITRE ATT&CK Enterprise data bundle is a single large JSON file listing every technique the framework defines. It was downloaded and searched in full for this article. The phrase "callback phishing" appears in exactly one technique description, in parentheses, inside a technique about voice-based phishing: victims "may also receive phishing messages that direct them to call a phone number ('callback phishing') where the adversary attempts to collect confidential information."

That is the whole of it. The parent technique describes the same behaviour without using the term at all, and the name of the origin campaign discussed further down this page appears zero times in the bundle.

So there is no ATT&CK technique for callback phishing, and none for TOAD.

That is a fact about how frameworks index things rather than a verdict on the attack. Frameworks catalogue techniques; this is a delivery pattern that borrows a couple of them and joins them with a phone call. The nearest neighbour, where the attacker dials the victim, has its own entry in this glossary and its own technique identifiers; here the victim dials, which is the whole distinction.

The method matters more than the result. This was checked against the framework's own data rather than against an article describing the framework, because those are different things and only one of them is authoritative.

A heavy stamped notification plate tubed to a funnel-shaped rack that narrows from many mixed shelves to one deep shelf packed with document cases.

The FBI advisory behind all of this

On 23 May 2025 the FBI published a Private Industry Notification, numbered 20250523-001 and marked TLP:CLEAR, which it describes as coordinated with DHS and CISA. Its title is "Silent Ransom Group Targeting Law Firms".

Its opening sentence names the group and its aliases: Silent Ransom Group, "also known as Luna Moth, Chatty Spider, and UNC3753". And the notification is explicit about what the group is known for: "SRG has been operating since 2022 and has primarily been known for their callback phishing emails, masquerading as well-known businesses who offer subscription plans."

A federal agency, using this exact term, naming a group that has been running the technique for four years. It appears nowhere in the captured results for this term on either engine. The closest thing to a government source on either first page is a vendor blog post from 2023 summarising a different, earlier FBI warning.

Who they target, and why

The notification is specific about the shift. Silent Ransom Group has "historically victimized companies in many sectors", but "starting Spring 2023, the group has consistently targeted US-based law firms, likely due to the highly sensitive nature of legal industry data."

That is a sentence about the value of the data rather than the softness of the target, and it is a useful corrective to the assumption that this technique goes after people who are easy to fool. A law firm's document store is worth the labour of running a call centre.

An alarm balance holding one very light disc with the needle below the marked trip line and the bell silent, beside a much heavier unused disc.

Why the bill is small on purpose

Here is the correction, and it comes from putting two sources side by side.

The standard description, in the search engine's own summary, is that callback phishing "urges you to call a phone number to fix a fake urgent problem." Urgency is the organising idea of nearly every explanation in that capture.

Now the advisory: "Typically, SRG phishing emails purport to charge small amounts of 'subscription fees' as they are less likely to generate immediate suspicion."

The attack does not want panic. It wants a phone call.

Consider what each emotion actually produces.

A frightened person forwards the email to IT, or deletes it, or sits on it. Fear makes people freeze or escalate, and both of those outcomes are useless to an attacker whose entire plan depends on the victim performing one specific voluntary action.

Mild irritation produces a phone call. Someone who has apparently been charged a modest amount for a service they never signed up for does not panic. They ring the number to sort it out, calmly, on their own initiative, and they arrive on the line in a reasonable mood towards whoever is about to help them cancel it. That is a far better starting position than fear, and the design reflects it.

The origin campaign, documented four years before that advisory, used the same register. Its waves ran on themes of photo editing services, cooking and recipe sites, fitness programmes and software licences, all claiming that a trial was ending or a card was about to be charged. Mundane by design, consistently, across two independent sources and four years.

Which means the awareness lesson is upside down. The email to be suspicious of is not the frightening one. It is the boring one with a phone number and no link.

Four stations on one tube: an outbound horn, a newly seated tool cradle, an arm lifting sealed cartridges onto a carrier, and a press stamping a demand slip, with a second horn line curving back.

What happens after the call

The captured coverage stops when the victim dials. The advisory does not, and the rest of it is the useful half.

The immediate step is described plainly: to cancel the fake subscription, "the victim was instructed to call the threat actor who emails a link which downloads remote access software giving the actor access to their device or system." The call is not where the data is stolen. The call is where the victim is talked into installing the thing that steals it.

From there: "Once the actor has established persistent access, the threat actors will seek to identify valuable information to exfiltrate, before sending a ransom notice." Then extortion, with a threat to "sell or post the data online".

And then the phone rings again. The advisory notes that Silent Ransom Group "will also call employees at a victim company to pressure them into engaging in ransom negotiations." The telephone is used twice in this attack: once to get in, and once to collect.

The escalation in the advisory's first sentence

The notification's opening sentence contains something no page in the captured results mentions. The group is now "sending an individual posing as an IT support employee to the firm in-person, after which they insert a storage device into a computer to steal sensitive data."

A person. Walking into the building. A phishing technique that grew a physical delivery step, which is not a sentence one expects to write about email fraud.

One scope note, because the advisory is careful and this page should be too. It describes this as recently observed, says it "has been highly effective and resulted in multiple compromises", and gives no count. Documented and effective is what the evidence supports. Common is not, and nothing here should be read that way.

Where the technique came from

The lineage runs back further than the captured coverage suggests. In July 2021, Microsoft documented a campaign built on exactly this pattern, in which the emails "include phone numbers that recipients are misled into calling" instead of malicious links, and where callers "are connected with actual humans on the other end of the line" who talk them through installing malware.

The emphasis on actual is Microsoft's own, and it is the point. This technique requires the attacker to staff something.

#### Which makes this the one variant that has to be staffed

Sit with that, because it is what separates this technique from every other member of the phishing family.

An email campaign scales by sending more email. A text campaign scales by sending more texts. This one scales by hiring. Someone has to be on the line when the victim rings, able to hold a plausible support conversation, at the hour the victim chooses to call.

That imposes constraints nothing else in the family has: a working day, a headcount, a training problem of the attacker's own, and a cost that rises with volume instead of falling. It also explains the targeting. If each conversation costs real labour, the target list has to justify the labour, which is what a federal advisory means when it says a group settled on law firms because of the sensitivity of the data.

#### What it bought them

That campaign's documented outcome was fast. Attacks arising from it "could move quickly within a network, conduct extensive data exfiltration and credential theft, and distribute ransomware within 48 hours of the initial compromise", with Ryuk or Conti payloads deployed through compromised high-privilege accounts. That is one campaign's recorded behaviour rather than a general rate, but it establishes what the phone call was worth to the people making it.

Five indicator collars over lanes carrying properly stamped parts, with one joining bracket bolted across the outbound horn lane and the tool cradle lane, wired to a single alarm.

What the FBI says to watch for

Before the list, the qualifier, because the agency puts it there itself: defenders are advised to treat the following as "potential, but not definitive, indications" of this group's activity.

What to watch for

Which half of the attack it belongs to

Unauthorised downloads of system management or remote access tools, with five products named

The endpoint, after the call

Unidentified individuals attempting to access computers while claiming to be IT support

The in-person escalation

File transfer tools connecting to an external address

The theft

Emails or voicemails from an unnamed group claiming data was stolen

The extortion

Employees receiving unsolicited calls from people claiming to work in their IT department

The second call, or a fresh attempt

The advisory names five specific products in that first row and two in the third. This site covers the abuse of remote management software in its own entry.

So is file transfer to external services, which is what the third row describes.

The extortion step that follows the theft has an entry of its own as well. The point here is not what any of those tools do. It is that every one of them is legitimate software.

Both halves are quiet for the same reason

The advisory explains the endpoint problem in one sentence: "SRG campaigns leave few artifacts on compromised machines. They are also unlikely to be flagged by traditional antivirus products because SRG generally uses legitimate system management or remote access tools to carry out the attacks."

Microsoft's 2021 write-up explains the email problem in one sentence: "the lack of obvious malicious elements in the delivery methods could render typical ways of detecting spam and phishing emails ineffective."

Together those two sentences describe one consistent property. Nothing in either half of this attack is illegitimate on its face. The email contains no malicious content, and the software installed afterwards is software a support desk might genuinely use. What is wrong is the context, and context is not something a scanner evaluates.

That is what makes the one useful question a joining question rather than a filtering one: would anyone notice a remote-access tool being installed shortly after a user made an outbound phone call? Neither event is remarkable. Together they are.

A large rehearsal bench turning out rows of identical practice envelopes beside a test-card rack, with a small record cabinet holding only a few plates off to one side.

A term that is taught more than it is searched

One observation that only the search record itself can support, offered as a derived reading rather than a measurement.

The result count reported for this phrase is the smallest this glossary has recorded for any security term. The question cluster attached to it runs to four questions. And four of the eight related searches are phrased as test items rather than as questions a person would ask, including one that ends "select all that apply".

The composition of the results follows from that. A substantial share of the first page is about simulating this attack rather than about the attack - a training platform's product documentation for building callback phishing campaigns ranks organically on both engines and is cited first in one engine's own answer.

What it does and does not tell you

None of that says anything about whether the attack is real. The federal advisory settles that question. What it explains is why the coverage is so uniform, and why almost all of it stops at the phone call: material written to support a training module has no reason to go further than the moment the trainee is supposed to recognise.

A counting drum with its ribbon come loose, two sealed cylinders bolted shut, and a rack of indicator plates each notched only half way so none seats fully.

What this page cannot tell you

No verifiable volume figure exists for this technique. Two figures circulate widely: a count of TOAD attempts in a single year, and a percentage of businesses said to have been affected in that year. Both are attributed to one vendor's research, and two attempts to reach a primary source carrying either figure with its method failed. The percentage in particular has the shape of a self-reported survey rather than telemetry, and no page in the captured results says which it is. Neither figure appears above.

The advisory's indicators are not detection. The FBI grades them itself, as quoted above, and no evaluation of how reliably they catch this activity exists.

The in-person escalation has no published count. It is described as recently observed and highly effective. That is all the evidence supports.

And the advisory is not a prevalence statement. It describes one actor group, targeting one sector, in one country, from a particular date. It is the best public documentation of this technique that exists, and it is not a measurement of how often the technique is used by anyone else.

A summary block: a number plate with the link clamp empty, a light disc under the alarm trip line, an outbound horn line returning a tool cradle, and a joining bracket wired to one bell.

The short version

Callback phishing, or TOAD, replaces the malicious link with a phone number so that the victim initiates contact. There is no ATT&CK technique of that name, which was verified against the framework's own data rather than assumed, and that absence describes how frameworks index things rather than how serious the attack is.

The FBI has documented a group running it since 2022, and the advisory contradicts the standard description in one important way: the fake charge is kept small deliberately, because small charges do not generate suspicion. The email is not trying to frighten you into calling. It is trying to mildly annoy you into calling, which works better.

After the call comes remote-access software, then theft, then extortion, then a second phone call to push the negotiation along. And in recent cases, a person arriving at the office claiming to be IT support.

The one thing to check after reading this: would anyone notice a remote-access tool being installed shortly after a user made an outbound phone call? Neither of those events looks like an incident. The pair of them is the whole attack.