happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

Are users becoming more wary of link clicking in email? Are they getting savvy to the tricks of the email phisher? Certainly there is some evidence that the security message is starting to get through to the masses, but not nearly quickly enough to turn the phishing tide in my opinion. Whatever the case, it appears that ID thieves need to find their own unique selling point in order to stand out in a sea of scam. Anti-virus specialist Sophos has uncovered one such attempt, where the phisher uses a new twist to con PayPal users into revealing credit card details.

It starts off as any other PayPal scam, claiming fraudulent activity on the recipients account and requiring contact to confirm personal details to reactivate it. But there is no typical ‘click here to confirm’ link that opens a convincing fake site with login screen to capture username and password followed by a form to capture financial detail. What there is, is a telephone number to call in the US that leads to a voice message purporting to be ‘account verification’ and asking the caller to enter their credit card number to match the one they supposedly have on file. This is a lot cleverer than at first it may seem, as users have been conditioned by security experts and the media alike to be rightly wary of link clicking in email messages. What is more, those same advisors will often say that if in doubt you should telephone the company concerned. With companies like PayPal operating almost exclusively online, including support, and not exactly publicizing telephone numbers it plays right into the scammer’s hands on all counts.

What is more, the phishing crew behind this one has used software that knows what a genuine credit card is, and if the user enters an incorrect one they will be prompted to re-enter: so enhancing the feel of legitimacy and reducing suspicion. Although this particular phishing attempt is far from crude, it seems certain that the phone phishers will quickly become more mature and accomplished. Sophos warn that the harvesting of messages from corporate switchboard systems, so as to fool callers into thinking they have the real thing on the end of the line, is a likely next move.

You can read more and listen to an actual recording of the VoIP phishing scam at .

Dani AI

Generated

As pointed out, phishing has moved beyond fake links: attackers now use unsolicited calls or recorded messages to try to extract financial details. That change matters because standard advice ("don't click links") is no longer sufficient — the same social-engineering rules apply, but the channel is voice instead of a web form. The paragraphs below add practical, time-tested steps to recognize these scams and to limit damage if a call succeeds.

Immediate rules to follow if you get an unexpected verification call

  • Do not give full card numbers, CVV, PINs, passwords, or Social Security numbers to an unsolicited caller.
  • Ask for the caller’s name, department and a call-back number, then hang up. Do not call the number the caller gives you.
  • Independently look up the company’s official phone number (bank statement, official website, mobile app) and call that line if you want to verify anything.
  • Log into your account directly (never via a link in an email or message) and check messages or alerts there.

If you already gave information

  • Contact your card issuer immediately to cancel or block the card and dispute any unauthorized charges.
  • Change passwords on affected accounts and enable multi-factor authentication.
  • Place a fraud alert or credit freeze with the major credit bureaus if identity data was exposed, and monitor statements closely.
  • Report the incident to your financial institution and to consumer-fraud authorities (and keep records of the call).

Prevention and workplace steps

  • Turn on transaction/text/email alerts for new charges, train staff on voice-based social engineering, and use carrier or device call-filtering services to block repeat numbers.
  • Treat any unsolicited request for financial data as suspicious and verify by contacting the company through independent, official channels.
  • If you consider recording a suspicious call for evidence, check local law about consent to record.

This complements the original post by focusing on concrete, immediate actions that reduce risk and speed recovery if a voice-based phishing attempt succeeds.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.