TL;DR A teacher at a public school district received a Google Calendar invite dressed up as a McAfee subscription renewal. The organizer address sat on a domain registered the very same day, with no MX, SPF, DMARC, or DKIM records, only a Google site-verification token. There was no link and no attachment to scan. The lure was pure callback phishing, and it could not keep its story straight: two different renewal charges, a misspelled brand, and three different phone numbers. Adaptive AI flagged it on domain age and internal inconsistency.
Severity: High Callback-Phishing Brand-Impersonation Consumer-Scam MITRE: T1566.004 MITRE: T1583.001

A teacher at a public school district opened what looked like a routine Google Calendar invitation. The subject read like a McAfee subscription renewal, the kind of notice a home antivirus customer sees once a year. Nothing about the delivery format tripped a filter. There was no attachment to detonate and no link to follow. The invite simply asked the recipient to confirm a charge, and if anything looked wrong, to call a support number.

That is the whole trick. This was a callback phishing lure, a TOAD attack, and the payload was a telephone number. The attacker did not want a click. They wanted a call, so they could talk a worried person into "reversing" a charge that never existed and, in the process, hand over card details or remote access to their machine.

A domain with no past and no records

The organizer address sat on a domain we will call gammacode[.]org. A WHOIS lookup told the real story in one line: the domain had been registered the same day the message arrived. It had no history, no reputation, and no reason to exist beyond this campaign.

The DNS posture was just as hollow. There was no A record, no MX record, no DMARC policy, and no DKIM selector. DNSSEC was disabled. The single TXT record present was a Google site-verification token, the kind you add to claim a property in Google Search or Workspace. In other words, whoever stood this domain up did the bare minimum to plug it into a Google account and fire off a calendar invite, then walked away. There was no functioning mail server behind it at all.

That absence is itself the signal. A legitimate business that sends renewal notices publishes SPF and DMARC to protect its brand and get its mail delivered. A domain that publishes nothing but a verification token, on its first day of life, is not running a mail program. It is running a scam.

How it slipped past the usual checks

On paper, one authentication result looked reassuring. DKIM passed. But it passed for the wrong reason. Google's calendar-invite transport signed the outbound message itself, the way it signs any invite sent through its infrastructure. The signature vouched for the delivery pipe, not for gammacode[.]org. SPF returned none, because the domain published no SPF record to check against. DMARC was none as well. There was no alignment to evaluate and nothing to enforce.

This is the uncomfortable part of calendar-invite abuse. The delivery channel is trusted, the transport signing is real, and there is no link or file for a secure email gateway to sandbox. A gateway tuned to hunt for malicious URLs and weaponized attachments finds neither and passes the message through. The 2024 Verizon Data Breach Investigations Report notes that the median time for a user to click a phishing link is around 21 seconds. Callback lures skip the link entirely and go straight for the reflex to pick up the phone, which is harder still to train away.

The message could not agree with itself

The most human tell was in the body. This scam template had clearly been assembled in a hurry, and it contradicted itself several times over.

First, the price. The invite claimed the account had been "charged USD437.76" in one place, then listed an "Amount Charged: USD526.50" in another. One renewal notice, two different totals. A real billing system does not disagree with itself about how much it just charged you.

Second, the brand. The name was rendered as "Mc Afee" in one spot and attributed to a "Team McAfee Service" in another, neither of which is how McAfee writes its own name. A physical mailing address in the body did not belong to McAfee at all.

Third, the callback numbers. The invite offered three different phone numbers to reach "support": 1-828-279-0168, +1-(828) 259-7953, and 810-213-3665. A single vendor does not publish three inconsistent support lines in one renewal notice. Those numbers were the actual payload, the destinations the attacker hoped a rattled recipient would dial.

What actually caught it

With no link and no attachment, conventional scanning had nothing to grab. The catch came from IRONSCALES Adaptive AI and our Themis analyst reasoning about the message the way a suspicious human would.

Two signals stacked up. The first was infrastructure: a sending domain registered the same day, with no mail-authentication records at all, is a near-textbook indicator of acquired attacker infrastructure. The second was internal consistency: a single message that quotes two different charge amounts and three different phone numbers is contradicting itself, and that contradiction is machine-detectable even when every transport-level check looks clean. Domain age plus zero DNS posture plus self-contradiction added up to a confident phishing verdict, and the invite was pulled from the teacher's mailbox before anyone dialed a number.

Callback scams like this one lean on urgency and the fact that most people never inspect who really sent a calendar invite. The durable defense is twofold. Detection has to weigh sender behavior and infrastructure, not just payload, because increasingly there is no payload to weigh. And employees need to see these lures in a controlled setting first, which is exactly what phishing simulation and training is built for. A renewal you never signed up for, from a brand that misspells its own name, is a call you should never make.

Want to see how Adaptive AI catches the attacks that have nothing for a scanner to find? Request a demo.

Indicators of Compromise

IndicatorValueNote
Sending domaingammacode[.]orgRegistered same day; no A/MX/SPF/DMARC/DKIM, DNSSEC off; only a Google site-verification TXT
Organizer addresskristie.phillipseq1@gammacode[.]orgGoogle Calendar organizer, personal-sounding name
Delivery formatGoogle Calendar inviteNo link, no attachment; DKIM passes via Google transport signing only
Contradictory chargesUSD437.76 and USD526.50Two different totals in one notice
Callback numbers1-828-279-0168, +1-(828) 259-7953, 810-213-3665Three inconsistent support lines; the real payload
Impersonated brand"Mc Afee" / "Team McAfee Service"Misspelled brand, non-McAfee mailing address

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing VoiceT1566.004Callback lure; phone numbers are the payload
Acquire Infrastructure: DomainsT1583.001Same-day domain registration for the campaign

For broader guidance on interrupting the phishing attack cycle, see the CISA phishing guidance and the 2024 Verizon Data Breach Investigations Report.

See You Next Friday

Callback phishing keeps winning because it removes the very things scanners are built to catch. When the payload is a phone number and the sender is a one-day-old domain, the only defense left is judgment, whether human or machine. Check back next week for another teardown.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Amazon Order That Wanted You to Call, Not ClickA fake Amazon order confirmation for an iPhone the recipient never bought.
The Phish Zoom Signed With Its Own DKIM KeyBy every cryptographic measure, this email really was from Zoom: DKIM verified, DMARC passed under a reject policy, sent on Zoom infrastructure.
McAfee Invoice Scam Weaponized a Google Calendar Invite 71 Minutes After Domain RegistrationA same-day registered domain abused Google Calendar invites to deliver a McAfee/Webroot invoice scam with a callback phone number.
The Fireflies Meeting Recap That Never Happened: Dual-Brand Impersonation via Amazon SESA phishing campaign combined Fireflies.ai meeting recap templates with Microsoft Teams branding to target a financial controller.
The Law Firm Name That Used Invisible Characters to Pass AuthenticationA phishing email impersonating Alston & Bird LLP used homoglyph characters in the display name and rode Google Drive sharing infrastructure to pass SPF.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.