Scammers are using short-lived VoIP numbers to bypass email security filters
Scammers are using short-lived VoIP phone numbers to keep callback phishing campaigns active before reputation-based security tools can block them. Cisco Talos found that many large scam campaigns now treat phone numbers as disposable infrastructure, much like attackers already rotate domains and email accounts.
The tactic appears in telephone-oriented attack delivery, also known as TOAD. In these attacks, emails do not always include a malicious link or attachment. Instead, they push victims to call a phone number and speak with a scammer.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
That live call gives attackers more control. They can impersonate support agents, create urgency, ask for payment details, request remote access, or walk victims through steps that would look suspicious in a normal phishing email.
Why VoIP numbers help scammers scale attacks
VoIP numbers are attractive because attackers can obtain them quickly, use them in bulk, and discard them when they start getting blocked. API-driven provisioning makes this easier for organized scam groups.
Cisco Talos says six of the 10 largest scam campaigns it detected between February 26 and March 31, 2026 relied on VoIP infrastructure. These campaigns impersonated major brands such as PayPal, Geek Squad, McAfee, and Norton LifeLock.
VoIP also lets scammers operate at scale without relying on physical SIM cards. Cellular numbers are harder to provision in large numbers, while landlines often help attackers create a local or business-like appearance.
At a glance
| Finding | Details |
|---|---|
| Main tactic | Telephone-oriented attack delivery, also known as TOAD |
| Main infrastructure | VoIP numbers used in scam emails |
| Study window | February 26 to March 31, 2026 |
| Unique phone numbers found | 1,652 |
| Numbers reused on consecutive days | 57, or about 3.4% |
| Numbers active for more than one day | 108, or about 6.5% |
| Median phone number lifespan | About 14 days |
| Common impersonated brands | PayPal, Geek Squad, McAfee, and Norton LifeLock |
How scammers bypass reputation systems
Reputation systems can block known malicious URLs, domains, file hashes, and phone numbers. The problem is timing. Phone number intelligence can move more slowly than web or file indicators.
Scammers use that delay to their advantage. They rotate through phone numbers, pause them for several days, and reuse them after a cool-down period. That helps them avoid filters that rely on recently reported abuse.
Some numbers stay active for only a few days, while others last for nearly a month. Talos found that most active numbers lasted between two and six days, but the median lifespan across the studied set was about 14 days.
Sequential number blocks make blocking harder
Attackers also use sequential number grouping. They obtain blocks of numbers that differ only in the last few digits, then rotate through the block when one number gets flagged.
This helps scam call centers maintain operations without rebuilding the entire campaign. If one number gets blocked, the same lure can continue with the next number in the sequence.

Talos found one PayPal-themed example where a single number appeared in 117 scam emails in one day. The larger pattern showed scammers using related number ranges across campaigns and brand lures.
How scammers reuse the same number
| Reuse tactic | How it works | Why it matters |
|---|---|---|
| Same number across different subjects | The phone number appears in emails with different subject lines and business contexts. | Filters may struggle to connect the messages as one campaign. |
| Same number across different brands | A number can appear in PayPal and Norton LifeLock lures. | Different lures can still lead to the same call center. |
| Same number across attachments | The number can appear in PDF, HEIC, JPEG, or other file formats. | Attackers avoid relying on one content format. |
| Cool-down reuse | A number disappears for several days, then returns in a new campaign. | This can bypass delayed reputation updates. |
Why email-only filtering is not enough
Many email security tools focus on sender reputation, links, attachments, and message content. TOAD campaigns reduce those signals by replacing links with phone numbers.
The email may look like an invoice, subscription renewal, refund notice, order confirmation, or security alert. The call-to-action stays simple: call the listed number to cancel, verify, dispute, or resolve the issue.
Once the victim calls, the attack moves outside the email channel. That gives scammers a chance to use social engineering in real time, adapt their story, and pressure the victim into making a bad decision.
Common scam themes
- Fake PayPal purchase confirmations.
- Geek Squad or Best Buy subscription renewal notices.
- McAfee antivirus billing alerts.
- Norton LifeLock renewal or cancellation emails.
- Fake refund or overpayment messages.
- Account security alerts that ask users to call support.
- Shipping, order confirmation, or transaction verification messages.
Why phone numbers should become indicators of compromise
Talos says defenders should treat phone numbers as primary indicators of compromise in scam investigations. A phone number can connect emails that appear unrelated at first glance.
This matters because scammers often change sender addresses, subject lines, attachments, and brand themes quickly. The phone number may remain the strongest link between campaigns.
Clustering scam emails by shared phone numbers can reveal call center infrastructure, repeated lures, number blocks, provider abuse patterns, and reuse windows.
What security teams should do
- Extract phone numbers from email bodies, subject lines, images, and attachments.
- Track phone numbers as indicators of compromise in SIEM and email security tools.
- Cluster campaigns by shared numbers, number blocks, and impersonated brands.
- Monitor VoIP-heavy campaigns that use invoice, renewal, refund, or support themes.
- Block or warn on high-risk numbers across email and collaboration tools.
- Train users to verify support numbers through official websites, not emails.
- Share malicious number intelligence with telecom, VoIP, and security partners.
What users should watch for
Users should treat unexpected emails with phone numbers carefully, especially if the message claims a payment, subscription, or account problem. A scam email may contain no link at all, but it can still be dangerous.
The safest response is to avoid calling the number in the message. Users should go to the companyโs official website, use the official app, or check a known support channel instead.
Businesses should also update phishing training. Employees need to understand that callback scams can bypass classic link-based warnings because the real attack begins during the phone call.
FAQ
Reused numbers can connect campaigns that use different subjects, attachments, brands, or sender addresses. This makes them useful for clustering and blocking scam activity.
Cisco Talos observed campaigns impersonating brands such as PayPal, Geek Squad, McAfee, and Norton LifeLock.
Telephone-oriented attack delivery is a scam method where attackers use emails to convince victims to call a phone number. The scam then continues through a live conversation.
VoIP numbers are cheap, easy to provision in bulk, and easier to discard than physical phone lines. This helps scammers rotate infrastructure quickly.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages