Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script

Google Account Security Team Impersonation Vishing Campaign (TL-2026-2695), also tracked as Google Account Security Team vishing scam, is a medium-severity phishing campaign, first published 2026-09-25. It is attributed to Derian with low confidence, affects Google Google Account (consumer Gmail / Google Workspace end-user, maps to 11 MITRE ATT&CK techniques (T1078, T1098, T1098.005), and is covered by 9 detection rules and 5 indicators of compromise.

Key facts for TL-2026-2695

Threat ID
TL-2026-2695
Also known as
Google Account Security Team vishing scam, Google Security Team phone scam
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-09-25
Last reviewed
2026-09-25
Attribution
Derian
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer individual account holders, cloud-hosted enterprise environments broader vishing trend context
Target regions
united states of america, canada
Detection rules
9
Indicators of compromise
5

Trellix Advanced Research Center's Dark Web Roast (August 2026 edition) surfaced a Telegram recruitment ad — posted by "Derian" (@crɑick) in the "UK Fraudsters" channel — hiring US/Canada-based, 'white sounding' callers for a voice-phishing (vishing) operation impersonating Google's Account Security Team. The ad demanded 'NO SCRIPT READING' while printing the exact required opener, which falsely claims the call is on a 'recorded line' from Google. The Register (2026-09-25) broke the story, tying it to a broader 2025-2026 surge in vishing-as-initial-access and dark-web recruitment for social engineers.

How Google Account Security Team Impersonation Vishing Campaign works

In the August 2026 edition of its "Dark Web Roast" series, Trellix's Advanced Research Center identified a hiring post in the Telegram channel "UK Fraudsters" from a user going by "Derian" (handle @crɑick). The ad, titled "Hiring - Female/Male Mail Callers," sought USA/Canada-based applicants with a "white sounding" voice and stated in bold, "NO SCRIPT READING" — immediately followed by the exact call script applicants were required to use. That script opens: "Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with [target name]?" (the leaked example used the name "Larry Boyles"), indicating callers are handed pre-researched target names rather than cold-dialing at random.

The scam pattern the script is built to execute is independently documented by Google itself: Google's official scam-warning FAQ (support.google.com/faqs/answer/17170932) describes callers impersonating Google Security who claim an account "has been compromised or hacked," then ask the victim to read back a verification code or approve a device/recovery prompt "over the phone" — while Google states flatly that it "will never call you about your account security." Independent technical breakdowns of this exact scam (e.g., Caldera Cybersecurity) describe the caller simultaneously triggering a genuine Google account-recovery or MFA prompt during the call so the victim receives an authentic-looking notification that appears to corroborate the caller's claims; once the victim reads back the code or approves the prompt, the attacker changes the account's recovery email and phone number, locking the legitimate owner out.

No technical network/file IOCs (phone numbers, calling infrastructure, domains, malware) were disclosed in the source reporting — this is a labor-recruitment ad for a social-engineering operation, not a leaked technical intrusion set. The find is contextualized against a documented surge: Google's own Threat Intelligence Group/Mandiant data (cited via The Register's March 2026 vishing feature and the Google Cloud Threat Horizons reporting) found voice phishing became the second-most-common initial access vector overall in 2025 (11%, versus ~8 hours-to-22-seconds initial-access handoff acceleration) and the single most common vector for cloud-environment intrusions (23%). ReliaQuest independently documented that dark-web job postings seeking English-speaking social-engineering skill more than doubled between 2024 and 2025, corroborating Trellix VP John Fokker's on-record observation of a rising trend in social-engineering job postings. The FBI's IC3 2025 Internet Crime Report (published 2026-04-07) recorded $20.87 billion in total cyber-enabled crime losses for 2025, a 26% year-over-year increase, cited by The Register as the backdrop against which this recruitment ad should be read. Google's own June 2026 fraud and scams advisory separately documents a rise in vishing/impersonation campaigns abusing official-sounding personas to coerce victims, reinforcing that voice-based impersonation of trusted brands and authorities is an active, growing consumer-fraud vector rather than an isolated incident.

MITRE ATT&CK techniques used in TL-2026-2695

Initial Access

T1078 Valid Accounts; T1566.004 Spearphishing Voice

Persistence

T1098 Account Manipulation; T1098.005 Device Registration

Credential Access

T1111 Multi-Factor Authentication Interception; T1621 Multi-Factor Authentication Request Generation

Impact

T1531 Account Access Removal; T1657 Financial Theft

Resource Development

T1585.001 Social Media Accounts

Reconnaissance

T1589 Gather Victim Identity Information

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Google Account Security Team Impersonation Vishing Campaign

  • Google — Google Account (consumer Gmail / Google Workspace end-user account-recovery and MFA workflow)
    Vulnerable versions: Not a software version issue — any Google Account holder reachable by phone is a potential target
    Fixed in: Not applicable — mitigated by user behavior (never share codes/approvals) and phishing-resistant authentication, not a vendor patch

Remediation for Google Account Security Team Impersonation Vishing Campaign

Patches

  • Not applicable — this is a social-engineering/labor-recruitment campaign targeting human trust and account-recovery workflows, not a software vulnerability; no vendor patch exists.

Immediate actions

  • Treat any inbound phone call claiming to be from 'Google Account Security' or a 'Google Account Security Team' as fraudulent — Google states it will never call about account security.
  • Never read a verification/recovery code or approve a device/sign-in prompt to someone who called you, regardless of how legitimate the accompanying notification looks.
  • If a suspicious call is received, hang up and independently verify account status at myaccount.google.com / the Google Security Checkup rather than continuing the call.

Workarounds

  • Enable and regularly review Google's Security Checkup for unrecognized recovery-email/phone changes or sign-in activity.
  • Set a verbal 'never share' policy for MFA codes and recovery prompts across household/organization members who may be targeted individually by name.

Longer-term hardening

  • Move high-value accounts to phishing-resistant authentication (hardware security keys or passkeys) that cannot be relayed by a caller reading back a one-time code.
  • Train users and helpdesk-adjacent staff that voice channels are now a leading initial-access vector (Google/Mandiant: ~11% of 2025 intrusions, ~23% of cloud intrusions) and should be treated with the same suspicion as email phishing.
  • Report recruitment ads and channels for criminal calling operations (e.g., via Telegram's in-app reporting) to accelerate takedown of active hiring pipelines.

Timeline of Google Account Security Team Impersonation Vishing Campaign

  • ReliaQuest reports dark-web recruitment/self-promotion posts already matching 2024's full-year total by mid-2025, with English-speaking social-engineering job postings more than doubling year-over-year — the recruitment trend this ad is part of.
  • Google Threat Intelligence Group / Mandiant full-year 2025 data shows voice phishing rose to the second-most-common initial access vector overall (~11%) and the top vector for cloud-environment intrusions (~23%).
  • The Register publishes a special feature, 'Voice phishing skyrockets as smooth crims talk their way in,' detailing the 2025 vishing initial-access surge and interactive social-engineering escalation.
  • FBI's Internet Crime Complaint Center (IC3) publishes its 2025 Internet Crime Report, recording $20.87 billion in cyber-enabled crime losses, a 26% year-over-year increase.
  • Google publishes its June 2026 frauds and scams advisory, documenting rising voice-based impersonation of trusted brands/authorities and citing an estimated $580 billion in global fraud losses for 2025.
  • Trellix Advanced Research Center publishes the 'Dark Web Roast – August 2026 Edition,' identifying the 'UK Fraudsters' Telegram post by 'Derian' (@crɑick) recruiting US/Canada-based callers for the Google Account Security Team vishing operation and quoting the leaked call script.
  • The Register breaks public coverage of the Trellix finding ('Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script'), tying it to FBI IC3 2025 loss figures and the ReliaQuest recruitment-doubling data.

Sources cited for Google Account Security Team Impersonation Vishing Campaign

More in phishing

Detection coverage for TL-2026-2695

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2695 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats