Phish of the Week: VISA Unauthorized Card Charge – Callback Phishing
This callback phishing campaign abuses Visa Acceptance Solutions' Cybersource platform, a legitimate service that businesses use to manage online payment processing. The attacker-modified email claims an unauthorized $657 charge and provides a phone number to resolve it, drawing the recipient into a call with attackers posing as support to extract sensitive information.
How the attack works:
The recipient receives an email titled "Cybersource Account-Action required," sent from Visa Acceptance Solutions' genuine mail infrastructure. The email carries real Visa branding and is structured as a standard "User Creation" notification.
Rather than a legitimate username, the account's username field contains attacker-written text: a claim that a $657 charge was made on the recipient's Visa card and processed through PayPal, along with a phone number to call to cancel it. Because Visa displays this field directly in its automated email, the attacker's message appears inside a real, system-generated notification rather than a fabricated one.
The email also includes an "Organization ID" reading "paypal_billing_[identifier]," a value the attacker likely entered when creating the account to reinforce the PayPal billing narrative. The rest of the email reads as a standard email-verification message, asking the recipient to click a link to confirm their address. This link is not part of the attack.
If the recipient calls the included number out of concern over the unrecognized charge, they reach attacker-controlled operators posing as PayPal support. From there, the attack continues as a voice-based social engineering attempt, aiming to extract payment card details, account credentials, or authorization for a fraudulent transfer, and in some cases pushing the target to install remote access software.
Why the attack works:
This attack's core strength is infrastructure and its refusal to leave anything for technical controls to catch. The email's header address genuinely resolves to Visa's Cybersource mail servers, so it passes sender authentication checks that filters rely on; the visible sender name does show a look-alike domain string, but that detail sits in a part of the header most recipients never expand. There is also no malicious link or attachment for email security tools to scan, since the entire payload is a phone number embedded in plain text. Once the recipient dials it, the rest of the attack happens over a voice channel, outside the reach of any email or web-based control, and outside the organization's IT and security team's visibility.
The charge amount is a deliberate choice: $657 is large enough to alarm someone who doesn't recognize it, but not so large that it reads as an obvious scam. That calibration, paired with a lack of overt urgency language, makes the email feel like a plausible, if inconvenient, billing notice rather than a high-pressure con.
Finally, the mismatch between the email's stated purpose (account verification) and its actual content (a payment dispute) is easy to miss on a quick read, because most people skim automated notifications rather than checking whether each part of the message logically belongs together.
How to spot similar attacks:
- An unexpected account or user creation notification for a service the recipient never signed up for
- A payment or charge dispute embedded inside an email whose subject and structure suggest a routine account or verification notice
- A phone call presented as the only way to resolve a payment issue, with no option to manage it through a web portal or app
- Reference fields (such as an "Organization ID") naming a different company or service than the one that sent the email, for example a PayPal-related label inside a Visa-branded message
- A phone number without any accompanying company name, reference number, or way to independently confirm who will answer
What is Phish of the Week?
Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.