A security professional was approached by an unknown, likely fake social-media profile offering $300 for a short “digital transformation” phone consultation. The pitch was a confidence trick designed to screen for useful access and then escalate into requests for non-public information that could push the target to misuse internal access and relationships. It’s a reminder that flattery and small-but-tempting payments can be used to turn trusted professionals into inadvertent insiders.
How the Scam Unfolded
According to Cisco Talos, the attack began with an unsolicited social media message from an unknown profile offering $300 for a one hour phone consultation on digital transformation. The offer was framed as a simple, low effort way to earn money, which made it feel plausible rather than alarming at first glance. Talos describes this initial contact as a confidence trick rather than a technical exploit, since it relied entirely on persuasion rather than malware or credential theft in its opening stage.
Why the Phone Call Was a Screening Step
The key finding in this case is that the paid consultation itself was not the real goal. Instead, it functioned as a screening process to determine whether the target had access or knowledge the attacker could later exploit. If the target seemed to have limited value, the interaction likely would have ended there. But if the target appeared useful, the attacker moved to the next stage: commissioning a written report and then a so called special report, which pushed the target toward sharing non-public insights.
Why the Approach Succeeded
This scam worked because it exploited trust and ego rather than technical weaknesses. The profile contacting the target was described as remarkably sparse, lacking the usual accumulated activity of a real professional account, yet the offer of payment for a simple service was tempting enough to lower guard. Talos points out that security professionals often assume they would recognize manipulation, and that this overconfidence is precisely what attackers count on. Flattery played a role too, with the target praised professionally before being asked to provide information that was not publicly available.
What to Watch For
- Unsolicited messages on social media offering payment for a simple service or a lucrative opportunity
- A sparse profile lacking the normal history and connections of a genuine account
- Requests that escalate from a harmless sounding call to written deliverables
- Pressure to provide insights or details that are not available in public sources
- Being asked, directly or indirectly, to contact coworkers or query internal systems to satisfy the request
Building Resistance
Organizations can reduce risk by training staff to verify unsolicited consulting or job offers independently before engaging, and by reinforcing that legitimate work never requires bypassing internal policy to gather non-public data for an outside party. Talos also notes that similar variants exist, including fake recruiter or job offers that push candidates toward installing trojanized software, so awareness training should cover the broader pattern of payment or opportunity based lures, not just this single scenario. Techniques referenced include spearphishing via service (T1566.003) and gathering victim information (T1598).
Key findings
- Attackers used an unsolicited social-media approach with a paid “consultation” offer as the lure.
- The scam is described as a confidence trick that starts with a phone call used to screen whether the target has valuable access or knowledge.
- If the target seems useful, the attacker escalates to written deliverables and a “special report” that pressures the target to provide non-public insights.
- The workflow attempts to induce the victim to misuse trusted access by contacting coworkers, probing internal systems, or leveraging professional relationships.
- The article notes similar variants, including fake recruiter/job offers that push candidates to install trojanized software.
Who’s being targeted
- Commonly targeted roles: Security, IT, Engineering, Executives, Anyone active on LinkedIn/social media for professional networking.
- Affected industries: Cybersecurity, Professional services, Technology consulting.
- Attack channels: linkedin, vishing.
- Impersonated: External consultant / consulting firm.
Red flags to watch for
- Sender profile is sparse or looks fake (no real footprint for the claimed employer).
- Payment is “plausible but tempting” for an unqualified first contact.
- Escalation to requests for non-public information that would require contacting coworkers or probing internal systems.
Frequently asked questions
What was the $300 consulting call scam?
An unsolicited social media profile offered a security professional $300 for an hour long phone consultation on digital transformation. The call was actually a screening step to see if the target had access or knowledge the attacker could exploit.
How did the scam escalate after the initial call?
If the target seemed useful, the attacker asked them to produce a written report and then a special report requesting non-public insights, which could require contacting coworkers or probing internal systems.
What are the red flags of this type of attack?
Warning signs include a sparse or fake looking social media profile, an unqualified stranger offering a tempting payment for a simple task, and gradual pressure to share information that is not publicly available.
Why do security professionals fall for this kind of scam?
The article notes that flattery and overconfidence remain a common vulnerability, since professionals often believe they would recognize social engineering, which is exactly the weakness attackers rely on.
Read the video transcript
You get a LinkedIn DM: “We’ll pay $300 for a one‑hour digital transformation call.” Sounds flattering, right? Here’s the trick: that paid call is just a screening test. They use the chat and phone to see what systems you know, who you can reach, and how much internal detail you’ll share. If you seem useful, it escalates: they commission a ‘special report’ and nudge you to ping coworkers, probe internal systems, and write up non‑public insights so you can ‘earn’ the fee. One move: if an unsolicited paid ‘consulting’ or expert call asks for anything non‑public, stop and route it through our security or compliance team before you answer.