Researchers spotted a Telegram job ad recruiting callers to impersonate the “Google Account Security Team” and run voice-phishing calls. The ad absurdly claimed “NO SCRIPT READING” while also publishing the exact phone script to use, showing a repeatable, real-world vishing workflow.
How the attack worked
A Telegram recruiter posted a job ad seeking callers to run a voice-phishing operation impersonating the Google Account Security Team. The ad tried to insist on improvisation by stating "NO SCRIPT READING," yet it then printed the exact script recruits were expected to use. That script opened with a formal, official-sounding line: the caller identifies themselves, claims to represent the Google Account Security Team, states the call is on a recorded line, and asks the target to confirm their identity by name before the conversation continues.
The ad also specified that applicants should sound like they are from the USA or Canada and be "white sounding," suggesting the operation cared about voice and accent profiling as part of making the call sound credible to targets.
Why it succeeded
The script leans on formality and procedural language to create a false sense of legitimacy. Phrases like "on a recorded line" mimic the tone of real corporate security or compliance calls, which can lower a target's guard even though nothing about that phrasing actually proves the caller is legitimate. Asking the target to confirm their own identity before the caller has proven anything also flips the normal verification process, making the target feel like they are the one being vetted rather than the other way around.
This kind of attack also succeeds because it targets a wide audience: anyone with a Google account is a potential victim, and the pretext of an account security issue is broadly believable and urgent-sounding.
What to watch for
- Unsolicited calls claiming to be from a "Google Account Security Team" or similar big-brand security group
- Compliance-sounding language such as "this call is being recorded" used to build false trust
- A caller asking you to confirm your identity before they have verified who they are or why they're calling
- Any account-related call that pressures immediate action or information sharing
Building resistance
Organizations and individuals should treat unsolicited security-related phone calls with the same skepticism as suspicious emails. If a caller claims to represent a known company's security team, hang up and contact that company through an official, independently verified channel rather than continuing the call or calling back a number the caller provides.
Security awareness programs should expand beyond email phishing to include voice phishing scenarios, since voice phishing has become a significant method for attackers to gain initial access. Training that includes real call scripts, like the one exposed in this ad, can help employees recognize the specific phrasing and pressure tactics used in these calls before they cause harm.
Key findings
- A Telegram recruiter sought callers for an apparent “Google Security Team” voice-phishing operation and tried to enforce “NO SCRIPT READING.”
- The same ad included the verbatim call script, providing a clear, simulation-ready vishing opener.
- The ad targeted “USA/CA (white sounding)” applicants, implying accent/voice profiling as part of the scam’s success criteria.
- Trellix framed this as real criminal activity despite the mocking tone of its “Dark Web Roast” series.
Who’s being targeted
- Commonly targeted roles: All employees, Executives, IT helpdesk/service desk, Finance teams, Customer support/call center staff.
- Affected industries: All sectors (Google account users / general public), Technology / cloud service users.
- Attack channels: telegram, vishing.
- Impersonated: Google Account Security Team.
Red flags to watch for
- Unsolicited call claiming to be “Google Account Security Team”
- Pressure created by faux formality like “on a recorded line”
- Caller asks to confirm identity (“Am I speaking with…?”) before proving legitimacy
Frequently asked questions
What is the fake Google Security Team vishing scam?
It's a voice-phishing operation where callers impersonate the Google Account Security Team using a scripted opening line to convince targets they are speaking with a legitimate representative.
How was this scam discovered?
Researchers found a Telegram job ad recruiting callers for the scam. The ad claimed 'NO SCRIPT READING' but then published the exact call script to use.
Why did the ad target 'white sounding' US/Canada applicants?
The ad's targeting criteria implies accent and voice profiling was used to increase the likelihood that targets would trust the caller as a legitimate Google representative.
How common is voice phishing as an attack method?
According to Google, voice phishing surged to become the second most common method cybercriminals use to gain initial access, making it a growing concern beyond email-based phishing.
Read the video transcript
Imagine this call: “Good afternoon, this is Alex from the Google Account Security Team on a recorded line…” Researchers found a Telegram ad recruiting callers to fake that exact Google Security intro, “NO SCRIPT READING”… right next to the full script. Here’s the play: they sound formal, drop “on a recorded line,” then ask, “Am I speaking with…?” before proving anything. That’s compliance theatre, not security. If anyone calls saying they’re Google security, hang up and check your account yourself at myaccount.google.com or the Google app, never by staying on that call.