Fake invoices, real scammers: The callback phishing playbook
How callback phishing uses fake invoices, images and calendar invites to move victims from the inbox to a live scammer
Key takeaways
- The ultimate payload in these attacks is a phone number that connects victims to a live scammer.
- Attackers are increasingly hiding callback scams inside images, branded HTML emails and even calendar invitations to evade traditional email security controls.
- Despite using different brands and delivery methods, every attack relied on urgency, financial anxiety and trusted company impersonation to trigger a phone call.
Traditional phishing attacks try to get victims to click a malicious link or open a dangerous attachment. The five attacks examined here simply asked recipients to call a phone number.
Known as callback phishing or telephone-oriented attack delivery (TOAD), these attacks use fake invoices, receipts and billing notifications to create anxiety and doubt, encouraging the recipient to call a fraudulent support number where a live scammer takes over.
What makes these attacks particularly effective is that many traditional email defenses are built to detect malicious URLs and attachments. In these campaigns, the primary payload doesn’t raise any red flags.
Five cases detected and blocked by Barracuda
The examples seen by Barracuda researchers used different delivery methods and brands, but they all followed the same playbook: impersonate a trusted company, create urgency around an unexpected payment or subscription, and persuade the recipient to make a phone call.
1. Fake PayPal invoice sent to a mass mailing list
The message impersonated PayPal using the misspelled brand name “P@YP@L” and claimed the recipient had purchased a $299.99 Amazon e-gift card. The sender used an unrelated .org domain and distributed the email to multiple recipients.
The email included invoice details, a transaction ID and a deadline for payment, but its real purpose was to get the recipient to call a support number if they wanted to dispute the charge.
2. Minimal email with the scam hidden in an image
This message appeared to come from a personal Gmail account and contained very little meaningful text. Instead, the main lure was an embedded image posing as a Geek Squad subscription renewal notice.
The image contained a support number and a fake billing summary. By placing the key content inside an image rather than the email body, attackers attempted to avoid text-based email inspection.
3. Near-empty email carrying an image-only lure
This message reduced the visible content even further. The subject line contained only a person’s name, while the body consisted almost entirely of an embedded image.
The image itself contained the fake Geek Squad renewal notice and callback number. This approach minimizes detectable content and relies on recipients viewing the image to see the scam.
4. Fully branded PayPal payment notification
The fourth message was the most convincing visually. It used PayPal branding, colors and formatting to create a realistic-looking HTML receipt.
The email claimed a new recurring payment agreement for $518.93 had been established and displayed a prominent support number for canceling the charge. The recurring-payment narrative was designed to increase urgency by implying ongoing financial losses rather than a one-time purchase.
5. Fake billing alert delivered via calendar invite
The final message demonstrated how these attacks are expanding beyond traditional email.
Instead of arriving as an ordinary message, the lure was delivered as a Google Calendar invitation from what appeared to be a compromised account. The invitation warned that a $599.99 PayPal auto-debit would begin within 12 hours and repeatedly displayed a cancellation phone number.
Using a calendar invite helps attackers exploit the trust users place in collaboration platforms while potentially bypassing email-focused security controls.
The unifying technique
Despite their different appearances, all five attacks relied on the same psychological triggers:
- A trusted brand such as PayPal or Geek Squad
- A believable financial charge
- A short deadline or cancellation window
- A support phone number presented as the solution
Once the victim makes the call, the attackers can adapt their approach in real time. They may ask victims to verify personal information, install remote access software, log into financial accounts, or approve fraudulent transactions.
This human interaction is what makes callback phishing particularly dangerous. Unlike a phishing website, a live scammer can answer questions, overcome objections and continuously adjust their story to maintain credibility.
How Barracuda detected and blocked the threats
Although these messages were designed to evade traditional phishing detection, they shared characteristics that security technologies can identify.
For image-based attacks such as the Geek Squad examples, Barracuda uses optical character recognition (OCR) to extract and analyze text hidden inside embedded images and attachments. This allows phone numbers, brand names and invoice details to be inspected even when they are not present in the email body.
Phone-number intelligence helps identify callback numbers associated with known scam activity, while sender and domain analysis highlights inconsistencies such as PayPal-themed messages arriving from personal Gmail accounts, unrelated domains or compromised educational addresses.
For highly branded campaigns, Barracuda analyzes email structure, branding elements and impersonation indicators to identify messages designed to mimic legitimate companies. Natural language analysis also helps detect common TOAD patterns, including combinations of payment notifications, urgent deadlines and instructions to call a support number.
Barracuda’s machine learning models continuously learn from newly observed campaigns, helping detect evolving variations that use different brands, invoice themes, phone numbers and delivery formats.
Importantly, this protection extends beyond traditional email messages to emerging delivery methods such as calendar invitations and other collaboration-based channels.
Conclusion
These five examples show how callback phishing is evolving from simple fake invoices into a broader social-engineering strategy that spans images, HTML emails and even calendar invites.
The attackers’ objective remains the same: move the conversation away from security controls and into a phone call where a live scammer can manipulate the victim directly.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit