24,700 Fake Debt Relief Emails Target Over 9,000 Organizations

24,700 Fake Debt Relief Emails Target Over 9,000 Organizations in 14 Days

The fake debt relief emails contain no malicious links or attachments, but direct recipients to attacker-controlled phone numbers for vicrim’s data.

Listen to this article

0:00

Press play to start listening

Cybersecurity firm Check Point says it blocked a debt-relief phishing campaign linked to approximately 24,700 emails aimed at users at more than 9,000 organizations during a 14-day period.

The messages offered help with financial hardship, debt consolidation and reduced payments, then instructed recipients to call telephone numbers controlled by the attackers. According to Check Point’s report, the campaign did not depend on malware, attachments or conventional phishing links.

The organization count describes intended targets, not confirmed breaches or victims. Check Point did not say how many recipients called the numbers or whether anyone handed over money or personal information.

Fake Debt Relief Offers Push Recipients Toward Phone Calls

Unlike a common phishing email that directs someone to a fake login page, these messages use a phone conversation as the next stage of the fraud. The email only needs to make the financial offer seem believable enough for the recipient to call.

One email shared by Check Point claimed the recipient had been pre-approved for a hardship program. It referred to missed attempts to make contact, promised major reductions in outstanding balances, and provided a toll-free callback number with stated calling hours.

Once a call begins, the attacker may ask for personal details, financial records, card or bank information, or an upfront payment. The caller may also move the conversation to text messages, another phone number, or a separate service, placing the interaction outside the organization’s email controls.

24,700 Fake Debt Relief Emails Target Over 9,000 Organizations
Screenshot via Check Point

Moving the interaction to a phone call also removes many of the warning signs associated with phishing. The email may contain nothing more than text and a telephone number, leaving filters focused on suspicious URLs, malware files and spoofed domains with fewer technical clues. Debt assistance is a familiar commercial subject, so the message can resemble an ordinary promotional email.

In its report, Check Point said its Email Security service examined the language, sender behavior, context and requested action to determine that the messages were intended to push users into attacker-controlled conversations. The company said it blocked the emails before recipients could engage with them.

24,700 Fake Debt Relief Emails Target Over 9,000 Organizations
Understanding the scam

Employees receiving an unexpected debt-relief message should avoid calling the supplied number. Any offer should be checked through the lender, government agency or financial provider’s official website and published contact details.

Moreover, recipients should not disclose account credentials, payment card details, banking information or identity documents to an unverified caller.

Check Point did not identify the people operating the campaign, name the countries targeted or report confirmed financial losses. Its findings show that an email can begin a phishing attack even when it contains no harmful file or clickable link.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts