Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script
Google Account Security Team Impersonation Vishing Campaign (TL-2026-2695), also tracked as Google Account Security Team vishing scam, is a medium-severity phishing campaign, first published 2026-09-25. It is attributed to Derian with low confidence, affects Google Google Account (consumer Gmail / Google Workspace end-user, maps to 11 MITRE ATT&CK techniques (T1078, T1098, T1098.005), and is covered by 9 detection rules and 5 indicators of compromise.
Key facts for TL-2026-2695
- Threat ID
- TL-2026-2695
- Also known as
- Google Account Security Team vishing scam, Google Security Team phone scam
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution
- Derian
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer individual account holders, cloud-hosted enterprise environments broader vishing trend context
- Target regions
- united states of america, canada
- Detection rules
- 9
- Indicators of compromise
- 5
Trellix Advanced Research Center's Dark Web Roast (August 2026 edition) surfaced a Telegram recruitment ad — posted by "Derian" (@crɑick) in the "UK Fraudsters" channel — hiring US/Canada-based, 'white sounding' callers for a voice-phishing (vishing) operation impersonating Google's Account Security Team. The ad demanded 'NO SCRIPT READING' while printing the exact required opener, which falsely claims the call is on a 'recorded line' from Google. The Register (2026-09-25) broke the story, tying it to a broader 2025-2026 surge in vishing-as-initial-access and dark-web recruitment for social engineers.
How Google Account Security Team Impersonation Vishing Campaign works
In the August 2026 edition of its "Dark Web Roast" series, Trellix's Advanced Research Center identified a hiring post in the Telegram channel "UK Fraudsters" from a user going by "Derian" (handle @crɑick). The ad, titled "Hiring - Female/Male Mail Callers," sought USA/Canada-based applicants with a "white sounding" voice and stated in bold, "NO SCRIPT READING" — immediately followed by the exact call script applicants were required to use. That script opens: "Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with [target name]?" (the leaked example used the name "Larry Boyles"), indicating callers are handed pre-researched target names rather than cold-dialing at random.
The scam pattern the script is built to execute is independently documented by Google itself: Google's official scam-warning FAQ (support.google.com/faqs/answer/17170932) describes callers impersonating Google Security who claim an account "has been compromised or hacked," then ask the victim to read back a verification code or approve a device/recovery prompt "over the phone" — while Google states flatly that it "will never call you about your account security." Independent technical breakdowns of this exact scam (e.g., Caldera Cybersecurity) describe the caller simultaneously triggering a genuine Google account-recovery or MFA prompt during the call so the victim receives an authentic-looking notification that appears to corroborate the caller's claims; once the victim reads back the code or approves the prompt, the attacker changes the account's recovery email and phone number, locking the legitimate owner out.
No technical network/file IOCs (phone numbers, calling infrastructure, domains, malware) were disclosed in the source reporting — this is a labor-recruitment ad for a social-engineering operation, not a leaked technical intrusion set. The find is contextualized against a documented surge: Google's own Threat Intelligence Group/Mandiant data (cited via The Register's March 2026 vishing feature and the Google Cloud Threat Horizons reporting) found voice phishing became the second-most-common initial access vector overall in 2025 (11%, versus ~8 hours-to-22-seconds initial-access handoff acceleration) and the single most common vector for cloud-environment intrusions (23%). ReliaQuest independently documented that dark-web job postings seeking English-speaking social-engineering skill more than doubled between 2024 and 2025, corroborating Trellix VP John Fokker's on-record observation of a rising trend in social-engineering job postings. The FBI's IC3 2025 Internet Crime Report (published 2026-04-07) recorded $20.87 billion in total cyber-enabled crime losses for 2025, a 26% year-over-year increase, cited by The Register as the backdrop against which this recruitment ad should be read. Google's own June 2026 fraud and scams advisory separately documents a rise in vishing/impersonation campaigns abusing official-sounding personas to coerce victims, reinforcing that voice-based impersonation of trusted brands and authorities is an active, growing consumer-fraud vector rather than an isolated incident.
MITRE ATT&CK techniques used in TL-2026-2695
Initial Access
T1078 Valid Accounts; T1566.004 Spearphishing Voice
Persistence
T1098 Account Manipulation; T1098.005 Device Registration
Credential Access
T1111 Multi-Factor Authentication Interception; T1621 Multi-Factor Authentication Request Generation
Impact
T1531 Account Access Removal; T1657 Financial Theft
Resource Development
T1585.001 Social Media Accounts
Reconnaissance
T1589 Gather Victim Identity Information
Defense Evasion
Affected products and versions in Google Account Security Team Impersonation Vishing Campaign
- Google — Google Account (consumer Gmail / Google Workspace end-user account-recovery and MFA workflow)
Vulnerable versions: Not a software version issue — any Google Account holder reachable by phone is a potential target
Fixed in: Not applicable — mitigated by user behavior (never share codes/approvals) and phishing-resistant authentication, not a vendor patch
Remediation for Google Account Security Team Impersonation Vishing Campaign
Patches
- Not applicable — this is a social-engineering/labor-recruitment campaign targeting human trust and account-recovery workflows, not a software vulnerability; no vendor patch exists.
Immediate actions
- Treat any inbound phone call claiming to be from 'Google Account Security' or a 'Google Account Security Team' as fraudulent — Google states it will never call about account security.
- Never read a verification/recovery code or approve a device/sign-in prompt to someone who called you, regardless of how legitimate the accompanying notification looks.
- If a suspicious call is received, hang up and independently verify account status at myaccount.google.com / the Google Security Checkup rather than continuing the call.
Workarounds
- Enable and regularly review Google's Security Checkup for unrecognized recovery-email/phone changes or sign-in activity.
- Set a verbal 'never share' policy for MFA codes and recovery prompts across household/organization members who may be targeted individually by name.
Longer-term hardening
- Move high-value accounts to phishing-resistant authentication (hardware security keys or passkeys) that cannot be relayed by a caller reading back a one-time code.
- Train users and helpdesk-adjacent staff that voice channels are now a leading initial-access vector (Google/Mandiant: ~11% of 2025 intrusions, ~23% of cloud intrusions) and should be treated with the same suspicion as email phishing.
- Report recruitment ads and channels for criminal calling operations (e.g., via Telegram's in-app reporting) to accelerate takedown of active hiring pipelines.
Timeline of Google Account Security Team Impersonation Vishing Campaign
- ReliaQuest reports dark-web recruitment/self-promotion posts already matching 2024's full-year total by mid-2025, with English-speaking social-engineering job postings more than doubling year-over-year — the recruitment trend this ad is part of.
- Google Threat Intelligence Group / Mandiant full-year 2025 data shows voice phishing rose to the second-most-common initial access vector overall (~11%) and the top vector for cloud-environment intrusions (~23%).
- The Register publishes a special feature, 'Voice phishing skyrockets as smooth crims talk their way in,' detailing the 2025 vishing initial-access surge and interactive social-engineering escalation.
- FBI's Internet Crime Complaint Center (IC3) publishes its 2025 Internet Crime Report, recording $20.87 billion in cyber-enabled crime losses, a 26% year-over-year increase.
- Google publishes its June 2026 frauds and scams advisory, documenting rising voice-based impersonation of trusted brands/authorities and citing an estimated $580 billion in global fraud losses for 2025.
- Trellix Advanced Research Center publishes the 'Dark Web Roast – August 2026 Edition,' identifying the 'UK Fraudsters' Telegram post by 'Derian' (@crɑick) recruiting US/Canada-based callers for the Google Account Security Team vishing operation and quoting the leaked call script.
- The Register breaks public coverage of the Trellix finding ('Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script'), tying it to FBI IC3 2025 loss figures and the ReliaQuest recruitment-doubling data.
Sources cited for Google Account Security Team Impersonation Vishing Campaign
- Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script
- Dark Web Roast - August 2026 Edition
- Google Account Security Scam via Phone Call
- "This Is Google Security…" – Don't Fall for This MFA Scam
- 2025 IC3 Annual Report
- Voice phishing skyrockets as smooth crims talk their way in
- Help Wanted: Dark Web Job Recruitment is Up
- Google's June 2026 frauds and scams advisory
- Cybercrime groups speed up initial access handoff through planning, coordination
More in phishing
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect Chain
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
Detection coverage for TL-2026-2695
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2695 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.