Brand Impersonation Emails Push Victims to Call

Cofense · Medium sophistication
Last updated August 18, 2026

Cofense reports ongoing mass email campaigns that impersonate trusted brands (and even government agencies) to trick recipients into calling a phone number for “remediation.” The lures typically claim an unauthorized purchase or a password reset and use urgency to pressure victims into acting quickly, shifting the interaction to a phone call where scammers have more control.

How the Attack Worked

Cofense reports mass email campaigns hitting client inboxes daily that impersonate well-known brands, and in some cases government agencies, to trick recipients into calling a phone number for remediation. The lures typically claim a password reset is needed or that an unauthorized purchase has occurred, creating a sense of loss or account compromise that pressures the recipient to act fast.

Rather than asking the victim to click a link or enter credentials directly in the email, the goal is to move the conversation off email and onto a phone call. Once on the phone, scammers have far more control over the interaction and can manipulate the victim through live conversation rather than a static message.

Why It Succeeded

Several factors make these campaigns effective:

  • Familiar brand names build immediate trust, and email spoofing is executed well enough that messages appear to come from reputable organizations.
  • The urgency of an unauthorized purchase or a password reset creates fear of financial or account loss, pushing recipients to act before verifying.
  • Some variants add a layer of authenticity with operational links, including ones that appear to be hosted on GitHub, which redirect to a fake invoice page.
  • Attackers can rapidly generate many variations of these campaigns, making them harder to detect and block at scale.

What to Watch For

  • Unexpected messages about a password reset or a purchase you do not recognize, especially ones that include a phone number instead of a way to reply or log in directly.
  • Language that discourages replying to the email and instead insists you call immediately.
  • Invoice or confirmation links that do not match the sender's stated brand context, or that lead somewhere unexpected upon closer inspection.
  • Any message that leans heavily on urgency and brand familiarity to short-circuit normal skepticism.

How to Build Resistance

Employees should treat unsolicited purchase or password reset alerts as high-risk until verified independently, using a known official number or website rather than any contact information provided in the email itself. Finance and AP staff should be especially cautious with purchase-related lures, and IT or helpdesk teams should expect to be an escalation point when employees receive these messages. Building awareness around the specific pattern of these attacks, brand impersonation, urgency, and a push toward a phone call, gives employees a concrete way to recognize the scam even as the impersonated brand or exact wording changes from campaign to campaign.

Key findings

  • Cofense observes these “phonescam” emails hitting client inboxes daily and at scale.
  • Messages impersonate well-known brands to build trust and create fear of loss (account compromise or fraudulent charges).
  • The primary goal is to push the victim off email and into a phone call by providing a number to contact.
  • Some campaigns add authenticity with links, including “operational GitHub links that redirect to a fake invoice.”
  • Attackers can rapidly generate many variations (polymorphic campaigns), making detection harder.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/AP, IT/Helpdesk, Executives (high likelihood of brand-targeted scams).
  • Affected industries: Multiple industries (Cofense client organizations).
  • Attack channels: email, vishing, website.
  • Impersonated: A trusted brand’s support/billing team (e.g., Microsoft, Amazon, PayPal, Norton/Geek Squad), Geek Squad (purchase confirmation / invoice team).

Red flags to watch for

  • Creates urgency and pressure to act quickly
  • Pushes you to call instead of replying in email
  • Brand familiarity used to override skepticism
  • Unexpected purchase confirmation/invoice
  • Uses a legitimate-sounding platform link (e.g., GitHub) to appear authentic
  • Mismatch between sender context and where the link ultimately leads (redirect to a fake invoice)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a phonescam email?

It is a mass email campaign that impersonates a trusted brand or agency, claims an unauthorized purchase or password reset, and pressures the recipient to call a phone number for remediation instead of replying by email.

Why do attackers push victims to call a phone number?

Moving the interaction to a phone call gives scammers more control over the conversation and lets them manipulate the victim in real time, away from any email-based security controls.

How do these scams add authenticity?

Some campaigns include links hosted on legitimate-seeming platforms like GitHub that redirect to a fake invoice page, adding a layer of credibility to the fraudulent claim.

Which departments are most at risk?

All employees are targeted, but finance and accounts payable staff are more likely to react to purchase-related lures, while helpdesk and IT teams are likely escalation targets.

Read the video transcript

You get an email from “Geek Squad” or “PayPal” screaming: CALL IMMEDIATELY about an unauthorized charge. This is a phonescam: mass emails pretending to be Microsoft, Amazon, or Norton, all trying to push you off email and onto a phone call where scammers take over. One Geek Squad scam even uses a real-looking GitHub link to a 'completed purchase' invoice, but it quietly redirects to a fake invoice and the same pressure to call their number. If an email says there’s an unauthorized purchase or password reset and tells you to call a number, don’t call it, go to the brand’s website or app yourself and check from there.

Similar attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Fake Google Ads “Sync” Alert Steals Credentials

Fake Google Ads “Sync” Alert Steals Credentials

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials.…

July 21, 2026