Press play to start listening
Cybersecurity firm Check Point says it blocked a debt-relief phishing campaign linked to approximately 24,700 emails aimed at users at more than 9,000 organizations during a 14-day period.
The messages offered help with financial hardship, debt consolidation and reduced payments, then instructed recipients to call telephone numbers controlled by the attackers. According to Check Point’s report, the campaign did not depend on malware, attachments or conventional phishing links.
The organization count describes intended targets, not confirmed breaches or victims. Check Point did not say how many recipients called the numbers or whether anyone handed over money or personal information.
Fake Debt Relief Offers Push Recipients Toward Phone Calls
Unlike a common phishing email that directs someone to a fake login page, these messages use a phone conversation as the next stage of the fraud. The email only needs to make the financial offer seem believable enough for the recipient to call.
One email shared by Check Point claimed the recipient had been pre-approved for a hardship program. It referred to missed attempts to make contact, promised major reductions in outstanding balances, and provided a toll-free callback number with stated calling hours.
Once a call begins, the attacker may ask for personal details, financial records, card or bank information, or an upfront payment. The caller may also move the conversation to text messages, another phone number, or a separate service, placing the interaction outside the organization’s email controls.
No Malicious Link Is Needed
Moving the interaction to a phone call also removes many of the warning signs associated with phishing. The email may contain nothing more than text and a telephone number, leaving filters focused on suspicious URLs, malware files and spoofed domains with fewer technical clues. Debt assistance is a familiar commercial subject, so the message can resemble an ordinary promotional email.
In its report, Check Point said its Email Security service examined the language, sender behavior, context and requested action to determine that the messages were intended to push users into attacker-controlled conversations. The company said it blocked the emails before recipients could engage with them.
Employees receiving an unexpected debt-relief message should avoid calling the supplied number. Any offer should be checked through the lender, government agency or financial provider’s official website and published contact details.
Moreover, recipients should not disclose account credentials, payment card details, banking information or identity documents to an unverified caller.
Check Point did not identify the people operating the campaign, name the countries targeted or report confirmed financial losses. Its findings show that an email can begin a phishing attack even when it contains no harmful file or clickable link.

