One-ring and wangiri scams
The simplest form: your phone rings once and stops. The missed call shows an unfamiliar number sometimes local, sometimes international. Curiosity or concern prompts you to call back. If it's a premium-rate number, the return call generates revenue for the attacker with every second you stay on the line. If it's a more sophisticated operation, you reach a live scammer who escalates from there.
The name "wangiri" comes from the Japanese for "one cut"—a single ring, then nothing.
Tech support and refund scams
You receive a pop-up alert, a voicemail, or an email warning of a virus, a suspicious charge, or an expiring subscription. The message looks like it's from Microsoft, Norton, Amazon, PayPal, or a well-known brand. A phone number is provided.
When you call, a "support agent" walks you through granting remote access to your device typically via legitimate remote monitoring tools. They then stage a fake refund, "accidentally" overpaying you in a way only visible to them. They pressure you to repay the difference with gift cards. No refund was ever coming. The remote access tool stays installed long after the call ends.
Huntress SOC analysts have investigated real incidents where attackers gained initial access to business environments through exactly this technique—using legitimate remote management tools as their foothold.
Callback phishing — the business threat
This is the variant that keeps security teams up at night, and it's growing fast.
The attack starts with an email that contains no links and no attachments just a PDF or a plain-text message claiming you've been charged for a service. There's nothing for an email filter to catch. The only "payload" is a phone number.
When you call, the scammer walks you through steps that end with malware installed, credentials stolen, or a ransomware deployment in progress. Security researchers call this technique TOAD—Telephone Oriented Attack Delivery. The BazaCall campaign, linked to the Conti ransomware group, used this method to deliver BazaLoader and set the stage for ransomware across hundreds of organizations.
The reason it works: there's no suspicious link to hover over, no malicious file for your endpoint to flag. The entire attack runs through a phone call and the trust that comes with it.