Why are fake voicemail transcript emails a new phishing threat?
Phishers are exploiting a growing workplace trend—the use of automated voicemail transcript emails—to deceive users. These notifications, which convert voicemail audio into text and email it, are common in busy or sensitive office environments. Because these emails appear routine and trustworthy, recipients often let their guard down, making them prime targets for attackers.
Between mid to late August, over 7,800 organizations were targeted with tens of thousands of these fraudulent emails, which mimic trusted internal systems and use spoofed sender domains that look legitimate.
How do attackers use SVG attachments to steal credentials?
Rather than traditional audio files, the phishing emails include Scalable Vector Graphics (SVG) attachments disguised as call recordings. Uniquely, SVG files can embed JavaScript, which when opened by the victim’s browser, executes automatically. This script redirects the victim to a fake login page, pre-filled with their email address to increase credibility, aiming to capture usernames and passwords.
This method cleverly bypasses many email security filters. While filters commonly check attachments like .exe, .pdf, or .docx for malicious content, SVG files are often overlooked. Also, since the emails avoid suspicious links in the body, automatic link scanning won't catch the threat.
What steps should organizations take to protect themselves?
As attackers quickly adapt to changes in workplace automation, organizations must adjust their defenses accordingly:
- Verify all automated notifications: Treat any automated message, even those appearing internal, as potentially suspicious until confirmed.
- Scrutinize SVG attachments: Configure email and endpoint protection to analyze SVG files as active content, not just images.
- Control automation permissions: Define which file types and domains AI or automation tools can access without manual review.
- Enhance user awareness: Train employees to recognize unusual email patterns and report suspicious voicemail transcripts.
What is the practical takeaway for cybersecurity?
This campaign highlights the sophistication and evolving tactics of phishing attackers. Credential theft can have severe impacts, including unauthorized access to email, business systems, and sensitive information. Businesses should not only rely on standard security measures but also adapt policies to emerging threats like malicious SVG files and seemingly benign automated notifications. Enhanced vigilance, verification procedures, and updated security controls are essential to mitigate these risks effectively.
