Blog.Talosintelligence Scammers Utilize VoIP Numbers in Email Phishing Campaigns
Article Content
- •VoIP numbers are increasingly used in phishing campaigns due to their ease of acquisition.
- •Six out of ten major scam campaigns detected recently relied on VoIP infrastructure.
- •Scammers exploit disposable VoIP numbers to bypass detection and reputation blocking.
Scammers are increasingly embedding phone numbers in scam emails, utilizing VoIP infrastructure to evade detection. This tactic, known as Telephone-oriented attack delivery (TOAD), manipulates victims into calling attacker-controlled numbers. Cisco Talos reported that six of the ten largest detected campaigns between February 26 and March 31, 2026, relied on VoIP numbers, which are favored for their ease of acquisition and difficulty in tracing. The analysis indicates that VoIP numbers, particularly from CPaaS providers, are exploited for rapid provisioning in fraud operations. The current landscape shows a growing trend in the reuse of these numbers across various campaigns, raising concerns about the effectiveness of existing detection methods. The use of disposable VoIP numbers complicates reputation blocking efforts, allowing scammers to scale their operations significantly. As the threat evolves, organizations are urged to enhance their defenses against these sophisticated phishing tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…