Security News

Voice Phishing Scam Impersonates Google Security Team, Recruiter Ad Blunders Expose the Trick

The Register · 26 Sept 2026
Key Takeaway Train staff to be suspicious of unsolicited calls claiming to be from Google, Microsoft, or other tech providers' security teams, and verify identity through official channels before sharing any information.

Security researchers at Trellix have uncovered a recruitment ad on Telegram seeking callers for a voice phishing scam that impersonates Google's Account Security Team. The ad, posted by a user identified as Derian, instructed applicants not to read from a script in bold text, then immediately printed the exact script callers were expected to use, including a line falsely claiming the call was being recorded to add a sense of legitimacy.

This discovery was part of Trellix's Dark Web Roast series, which highlights mistakes made by cybercriminals while noting that the underlying scams still cause real harm to victims. Voice phishing (vishing) scams impersonating well known companies like Google remain a common tactic, relying on callers sounding credible and using pretexting techniques to trick victims into handing over account access or personal information.

Trellix's threat intelligence team pointed out that despite the scam's amateur execution, the pretexting approach used, posing as a trusted brand's security team on a supposedly recorded line, remains effective against unsuspecting targets. The research reinforces that cybercriminals are often ordinary people running low effort operations rather than sophisticated masterminds.

vishing phishing social engineering Google impersonation dark web

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.