Free cybersecurity training for organizations of any size. Schedule yours today ›

Don’t Call That Number: The Phishing Scam With No Link

The Security BriefMay 13, 2026

Scammers have swapped suspicious links for phone numbers, and calling feels safe. Here's how callback phishing works and how to keep your team out of it.

Most of us have finally internalized the number-one rule of email safety: don’t click suspicious links. Cybercriminals know that, too. So they’ve quietly changed the play.

The newest wave of phishing emails doesn’t contain a link at all. Instead, it gives you a phone number, and asks you to call.

How the scam works

It starts with an email about something urgent. A fraudulent charge on your account. A software update you need to install immediately. A subscription you never authorized.

The email looks legitimate enough. But instead of a “click here” button, it lists a phone number and encourages you to call to sort things out.

Here’s the clever part: calling a phone number feels safe. It feels like the responsible, careful thing to do. That feeling is exactly what this scam is built on.

If you call, one of two things usually happens.

Scenario one: an automated system answers and walks you through “verifying your identity,” prompting you to enter your credit card number, Social Security number, or account credentials. Everything you punch in goes straight to the scammers.

Scenario two: a real person picks up. They sound professional and helpful. They tell you there’s an issue with your account, then walk you through downloading software onto your device to fix it. That software is malware.

Either way, by the time anything feels off, the damage is usually already done.

How to protect yourself

The good news: this scam is easy to beat once you know the pattern. A few simple habits go a long way:

  • Don’t call phone numbers from unexpected emails. If the message arrived out of the blue, treat the number inside it as part of the scam.
  • Go to the source. If the email claims to be from a company you actually use, open their official website yourself and call the number listed there.
  • Make them verify first. Before sharing anything over the phone, ask the caller what information they already have on file. A legitimate organization can verify itself, and if they can’t, hang up.
  • Watch for urgency. Phishing is designed to make you act before you think. “Immediately” and “within 24 hours” are red flags, not deadlines.
  • Already called? If you shared sensitive information, contact your bank or the relevant organization right away to report it and lock things down.

A heads-up for business owners

These emails don’t only target personal accounts. Your employees receive them too, often dressed up as HR software, payroll platforms, or IT support.

If an employee calls the number and follows the “helpful” instructions, that’s a direct path into your business. One installed remote-access tool or one shared password can open the door to your whole network.

It’s worth a two-minute mention at your next team meeting: if an email asks you to call a number, verify it first.

The phone call felt safer than the link, and that was the whole point. Taking ten seconds to verify before you dial is still one of the simplest, most effective security habits you can build, at home and at work.

Keeping our clients ahead of threats like this is part of how we approach Cybersecurity-Driven IT at Vertical IT Solutions. If you’d like to know where your business stands, take our free 60-second Security Score, or talk to our team and we’ll walk you through it, no pressure and no jargon.

Ready to get started?

Get a free quote, or talk to our team about your IT needs.