A campaign researchers tracked over two weeks sent roughly 24,700 messages built to make recipients dial rather than click, leaving email gateways nothing to inspect.

 

What happened

Researchers have documented a phishing campaign using fake debt forgiveness offers and financial hardship programs to push recipients into calling numbers the attackers control, with approximately 24,700 associated emails detected across more than 9,000 organizations during fourteen days ending in late August 2026. The messages carry no malicious links, no attachments, and no spoofed sender domain, which removes every artifact a security gateway is built to examine. Security teams and government agencies classify the method as telephone-oriented attack delivery, or TOAD, where the email exists only to prompt a phone call and the actual manipulation happens on the line. The New Jersey Cybersecurity and Communications Integration Cell has tracked the same pattern against state employees.

 

Going deeper

Getting the victim to place the call is the design choice that makes this work. A person who dials a number believes they initiated the contact, which lowers suspicion in a way an incoming call never does, and the pretext usually arrives as a fake bill or receipt for a payment large enough to demand immediate attention. Attackers build the target list from data exposed in past breaches, information purchased on criminal markets, and social media profiles, according to NJCCIC, then run the calls through fraudulent centers staffed to sound like customer service. Once a victim is on the phone, operators work toward account credentials, a payment, or installation of remote access software described as a fix. Earlier campaigns of this type impersonated Norton, PayPal, McAfee, and Geek Squad, sent through ordinary consumer email accounts with the sender display name matched to the recipient's own name.

 

What was said

These messages "may bypass email security due to limited indicators within the phishing email and the reliance upon the potential victim to initiate interaction," NJCCIC noted in an advisory on the technique. Its guidance to recipients is to avoid responding to unexpected messages from unverified senders and to contact the company named in the message using the telephone number published on that company's own website.

 

In the know

Roughly 41% of American adults carry some form of health care debt when credit card balances, provider payment plans, and money borrowed from family are counted, according to KFF's health care debt survey, with about half of all adults saying they could not cover an unexpected $500 medical bill without borrowing. Analysis of federal survey data puts the total owed at a minimum of $220 billion, with roughly 14 million people owing more than $1,000 and about three million owing more than $10,000, per the Peterson-KFF Health System Tracker. An email offering debt forgiveness therefore lands on a population where a substantial share have a genuine reason to open it, including the administrative and clinical staff who work inside provider organizations.

 

The big picture

Detection has to move from what the message contains to how the message behaves, since content inspection produces a clean verdict every time in this format. Useful signals include financial urgency paired with a telephone number as the sole action available, an absence of any URL in a message that would ordinarily contain one, and a mismatch between the sending domain and the brand being claimed. Healthcare organizations carry a second exposure through their own billing correspondence, because patients receive genuine statements and payment plan communications by email and cannot easily distinguish an authentic one from a counterfeit. Publishing the numbers a patient should call, stating that the organization never contacts patients about debt forgiveness by email, and giving staff a clear instruction never to authorize a credential reset or remote access based on an inbound call are all controls that operate without depending on anyone spotting a forgery. Social engineering conducted by voice sits outside every filter an organization has configured on the email path.

 

FAQs

Why do gateways struggle with an email containing no links?

Filtering works by checking URLs against reputation databases, detonating attachments in isolated environments, and matching content against known malicious patterns. A message with none of those elements gives each of those engines nothing to assess, so it returns a clean result, and the message is delivered.

 

What happens on the call itself?

Operators pose as customer service or support staff and work toward one of three outcomes: obtaining account credentials, securing a fraudulent payment, or persuading the victim to install remote access software so the attacker can reach the device directly. Some sessions end with malware or ransomware deployed after the call concludes.

 

Can caller ID be trusted when verifying a number?

No. Caller identification is straightforward to spoof, so a call appearing to come from a known organization proves nothing about who is on the line. Verification requires hanging up and dialing a number obtained independently from a billing statement, an insurance card, or the organization's published website.

 

How should staff report a suspicious message with no link to analyze?

Through the same reporting process used for any phishing attempt, since security teams can still examine the sending infrastructure, the telephone number, and the message pattern. Organizations should confirm their reporting tools accept messages that contain no attachment or link, as some workflows assume one is present.

 

Does this technique affect patients differently from staff?

Patients face it as consumer fraud directed at payment details and personal information, while staff face it as a route into organizational systems through credential theft or remote access. The same message can serve both purposes, which is why awareness efforts aimed at employees and communications aimed at patients need to carry consistent instructions.