We recently helped a client who received a very convincing “Sage auto-renewal notification” email. At first glance it looked normal: branding, renewal date, a link to “update your credit card,” and a phone number to call for questions.
But two things didn’t add up:
That small mismatch is exactly what these threat actors are counting on.
This is the exact image that appears in the email. (Names, numbers, and dates have been changed. except for the Phone Number at the bottom of the Ad).
This is to bring attention to the Actual Phone Number used in the Phishing Scam.
This is a callback / phone-based phishing scam dressed up as a billing notice.
Here’s the typical flow we’re seeing (Sage and QuickBooks themes are being used):
