Skip to main content

Phonescams: Casting a Wide Net in an Orchard of Low-Hanging Fruit

August 17, 2026

By: Joseph Hoggle, Cofense Phishing Defense Center

Phonescams that impersonate some of America’s favorite brands—and some less expected ones—are distributed en masse to Cofense client email inboxes daily. In the digital age, everyone is looking to get ahead, and while one innovation breeds another, some things never change. Just as the humble wheel has been used for thousands of years, the easiest apple to pick off a tree is still the lowest hanging. Why fetch a ladder when the fruit is within reach? Here in the Cofense Phishing Defense Center, we have noticed that contemporary threat actors are all too aware of the concepts of wide nets and low-hanging fruit. The knowledge required to create complex web-based phishing campaigns and malware is high, and creating them can be time-consuming, but there is an alternative. An alternative that empowers fraudsters to cast their malicious nets far and wide. Even people who know the warning signs can hesitate when a message seems legitimate. Scammers exploit this uncertainty by impersonating trusted organizations and creating the illusion that immediate action is required.

 

Figure1 (20)

Figure 1: Big Brand Phonescams

Figure 1 shows examples of a few phone scams we routinely see at Cofense. Notice how email spoofing has become so well executed that the scams appear to have been distributed from well-known, reputable brands. Most people today are made aware of phishing attacks by their workplace IT staff. They know to be weary of clicking on phishing links and to always check the email sender. But what if the emails appear to have come from a trusted source like Microsoft, Target, or Amazon? What if their inaction results in the loss of their account? These questions enable phone scam distributors to manipulate their email recipients by feigning familiarity and exploiting a perceived fear of loss. Although the impersonated brands are different, each scam alerts its recipient that something has occurred and provides a contact number for remediation. 
 
What makes phone scam campaigns so alluring to threat actors? With the help of AI, adversaries with little technical expertise can distribute thousands of convincing phone scam emails in seconds. AI also enables them to rapidly generate countless variations of the same scam, making these campaigns more difficult for advanced email security systems to detect. These scams are easy to produce, infinitely scalable, and simply effective. Although phone scams can range in complexity, with some going as far as to include links to fake invoices, the barriers of entry into a basic phone scam operation are typically a free email address, a text or photo editor, and a free Voice over Internet Protocol (VoIP) number. From there, threat actors follow a simple, repeatable process to generate endless scam campaigns. 

  1. Select a brand that the email recipient will recognize, such as Amazon, GitHub, or Canva. 
  2. Create a text or image-based lure email claiming there has been a purchase or password reset.
  3. Distribute that lure using a free email address.
  4. Wait for the lure recipient to contact the included VoIP number.
  5. Exploit the lure recipient’s fear of perceived loss.
  6. Wash, rinse, repeat.


Figure2 (21)

Figure 2: Phonescams Group 2


Some of the rarer brand impersonations can be seen in Figure 2. What do Temu, Canva, and the Federal Trade Commission have in common? Besides what appears to be the setup for the world’s worst joke, they and many other lesser-known brands are not are vulnerable to being impersonated by fraudsters in the pursuit of ill-gotten gains.


Figure3 (18)

Figure 3: Phonescams Group 3


Phone scam lures commonly point the recipient to a problem such as a password reset or an unauthorized purchase, but some go even farther. The phone scam in Figure 3 features a Geek Squad impersonation that contains the usual lure of a completed purchase and a phone number, but also includes operational GitHub links that redirect to a fake invoice. This is an example of threat actors employing every tactic they can to add a layer of authenticity.

These campaigns are created and distributed so quickly that their creators do not need to meet a quota or a percentile goal. Phone scammers blast as many polymorphic phone scams as possible and wait to reap the benefits. They cast a wide net to capture as much low-hanging fruit as possible. Cofense’s position is unique in this area of cyberspace. Where secure email gateways and spam filters can fail to detect these types of scams, Cofense’s hands-on, human-led analysis is a phone scammer's worst nightmare. Our analysts are trained to rapidly identify phone scams and and share the details with our customers. Our proprietary software then helps us more accurately identify and predict future scams.

Behavioral Indicators

Why it matters

Sense of urgency (Call Immediately)

Pressures the receiver to act without thinking

Impersonated brands (Paypal, Norton, GeekSquad, Microsoft, Amazon, Temu, the Federal Trade Commission, and Canva)

Using familiar brand names builds trust with scam recipients

Discourages replying to the email

Pushes communication to the phone call where scammers have more control.


Page Break

All third-party trademarks referenced by Cofense whether in logo form, name form or product form, or otherwise, remain the property of their respective holders, and use of these trademarks in no way indicates any relationship between Cofense and the holders of the trademarks. Any observations contained in this blog regarding circumvention of end point protections are based on observations at a point in time based on a specific set of system configurations. Subsequent updates or different configurations may be effective at stopping these or similar threats. Past performance is not indicative of future results.

The Cofense® and PhishMe® names and logos, as well as any other Cofense product or service names or logos displayed on this blog are registered trademarks or trademarks of Cofense Inc.