It shows up on a Tuesday morning. An invoice from PayPal, or Norton, or Geek Squad, for something you don't remember buying. A recurring charge you never agreed to. And a phone number to call if you want to dispute it.
That little spike of annoyance you feel is the trap. The email is not trying to steal your password on the spot. It is trying to get you to dial a number a stranger controls.
Security people call this callback phishing, or telephone-oriented attack delivery. Barracuda's researchers documented five examples in August 2026, and every one followed the same shape: a familiar brand, a believable charge, a short deadline, and a phone number offered as the solution.
Why it slips past your email filter
Your spam filter is built to catch bad links and bad attachments. Most of these emails have neither. One of the examples Barracuda published was almost entirely a single image, a fake Geek Squad renewal notice with the phone number baked into the picture and almost no text for a scanner to read. It came from an ordinary Gmail address.
Another arrived as a Google Calendar invitation from what looked like a compromised account, warning that a recurring charge would begin within 12 hours.
There is no file to block. There is no website to flag. The payload is a ten-digit phone number.
The problem is who answers
A phishing website is a scripted conversation. A live person is not. Whoever answers that number can hear you hesitate, answer your questions, and change the story until it fits. They can talk you through installing remote access software while calling it a diagnostic tool. They can ask you to read them the code that just landed on your phone.
The FBI issued a flash alert in May 2026 about exactly this pattern. The group it describes began with fake subscription fee emails that included a cancellation number. By spring 2026 the approach had changed. The callers now claim to be from your IT department, or they send an email telling an employee to call IT support. Once they are on the phone, they ask the employee to grant access to a remote desktop session.
If you are wondering why an FBI alert about law firms matters to a twelve-person shop in the Upper Peninsula, here is the honest answer. The targets changed. The technique did not.
Google's threat intelligence team described a related campaign in August 2026. Those callers posed as IT helpdesk staff walking employees through an urgent, mandatory security migration, then pushed them to a fake login page. In some cases the callers spoofed the company's real helpdesk number, so the caller ID looked right. Several of the fake web addresses contained the word passkey.
Turn that trust into a rule
You cannot train your way out of every scam, and you should not try. What works is a rule that does not depend on anyone's judgment in the moment.
Nobody from IT, and nobody from a software company, asks you to install a program over the phone. If someone does, the call ends. Not "let me check first." It ends.
If you get a bill you do not recognize, do not call the number in the message. Look up the company's number yourself, or log into your own account and check the billing history. If the charge is not there, the email was fake.
If someone claims to be from a company you actually work with, hang up and call back on a number you already had. That is the whole defense.
Write it down. Say it out loud at a staff meeting. Put it where the person who pays the bills can see it, because that person is the one who gets these emails.
The FTC's guidance to small businesses says the same thing in fewer words: scammers fake their phone numbers, so do not trust caller ID.
Tell people it is safe to say so
The part nobody plans for is the silence afterward. Most people who fall for one of these calls are too embarrassed to mention it for a day or two. Two days is the difference between a nuisance and a mess.
If someone on your team makes the call, you want to hear about it in ten minutes. Say that out loud, more than once, and mean it.
Where the numbers stand
The FBI's Internet Crime Complaint Center logged 191,561 phishing and spoofing complaints in 2025. That made it the most reported crime type it tracks. Business email compromise drew 24,768 complaints on its own, and the FBI rates it the second costliest category of cyber-enabled fraud it follows. In 2025 the FBI also began tagging complaints with an artificial intelligence descriptor for the first time and applied it to 22,364 of them.
Those are national numbers, and they are the reported ones. The FBI has said for years that most fraud goes unreported.
One more place to look
Fake invoices also turn up somewhere you would not expect. In June 2026, researchers found fabricated receipts inserted into the Shop order tracking app alongside real purchases, impersonating brands like Norton, McAfee, and Apple, each one with a support number attached. The app's owner said it added controls to reduce the activity.
So the rule is not "read your email more carefully." It is simpler than that. Any phone number that arrives in a message you did not ask for belongs to a stranger, no matter what the message looks like.