Check Point flags fake voicemail transcript phishing campaign targeting 7,800 organizations
Check Point Research says fake voicemail transcript emails hit over 7,800 organizations in credential phishing campaign.
The lure exploits a workplace habit that has spread as AI-backed tools have made automated voicemail transcripts common. When someone receives a voicemail, the system can email a transcript to the recipient's inbox, allowing the person to read the message instead of listening to it. Because employees are used to receiving that type of notification, they may not be suspicious enough when a similar message arrives, Check Point Research said. The researchers explained that the operation used more than 38,400 spoofed sender addresses across more than 9,300 spoofed domains. Each email's subject line begins with 'Automated transcript', followed by a partially redacted phone number and a random tracking string. Check Point Research said the effect is deliberately understated: a notification that appears to have been generated by a trusted workplace system. The email domains are also spoofed to make the messages appear to come from within the same organization.
Every email in the campaign carries an attachment that is designed to look like a call recording file. The names resemble audio files, but the file type is SVG, short for Scalable Vector Graphics, which is an image format rather than an audio format. Check Point Research said SVG is an XML-based document that can contain JavaScript. When a browser opens the SVG, that JavaScript can execute and redirect the victim to a spoofed login page where they are asked to enter their credentials. Because the recipient's email address is hardcoded in the URL, the fake login form auto-fills the username field. That makes the page more personalized and credible, the researchers said.
The SVG format also helps the campaign evade email security systems, according to the report. If attackers put a hyperlink in the body of an email, a security system can scan the link and sanitize it if it is found to be malicious. Without a link, a security system may inspect attachments instead. The usual attachment types that draw scrutiny are .exe, .docx or .pdf files, and very few systems focus on SVG files, the researchers said. Check Point Research warned that the campaign demonstrates how quickly attackers adapt to enterprise workflows as automation becomes more common. The researchers said businesses should treat automated notifications as signals that need to be verified, especially when the sender appears to match the recipient's domain. They also said businesses should define which file types and domains AI agents are allowed to access without human confirmation, and should inspect SVG attachments as active content rather than simply as images.