Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- Reported by
- 1 outlet
security
More mockery and memes from the Dark Web Roast
Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad that also included the exact script they had to read during these scam calls.
This and other true-crime tales of criminals making fools of themselves appear in the latest installment of the Trellix Advanced Research Center’s Dark Web Roast, which uses memes and mockery to troll criminals on the dark web.
It also acknowledges: “While these incidents are genuinely amusing, they represent real criminal activities causing significant harm.”
One of these incidents from August involves a Telegram user identified by Trellix as Derian (@crɑick) who posted an ad in the UK Fraudsters Telegram channel. “Hiring - Female/Male Mail Callers,” the advertisement said, seeking “USA/CA (white sounding)” applicants and, in bold, “NO SCRIPT READING.”
The ad then proceeded to print the exact script the callers would read: “Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with Larry Boyles?”
The Trellix threat-intel analysts note that the “‘recorded line’ flourish is a nice touch, because nothing says legitimacy like a fraudster cosplaying compliance theatre. The pretexting playbook is depressingly effective, but the recruiter’s QA process is roughly as robust as the fake Google team it impersonates.”
Burn, baby, burn.
The Register previously spoke with Trellix VP of threat intelligence strategy John Fokker about the Dark Web Roast, and he said the idea came from a desire to take an "almost psyops" approach to covering the criminal underground. "We don't want to glorify them, what's the opposite we can do? We're going to roast them," Fokker told us during a conversation at RSAC.
"I'm trying to spark a debate, or a healthy conversation, about what we can do as an industry," he said. "Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers."
The FBI’s Internet Crime Complaint Center (IC3) recently reported its most damaging year for internet scams, with 2025’s data pegging reported losses at $20.87 billion, and English-language social engineering is among the most in-demand skill sets on underground forums. One report by threat detection and response firm ReliaQuest found the number of job advertisements posted on criminal marketplaces mentioning this particular talent more than doubled between 2024 and 2025.
Plus, according to Google, voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate – and the No. 1 tactic used when breaking into cloud environments.
So when these criminals do dumb things, we’re happy to see Fokker’s team call them out.®
Originally published by The Register. © The Register.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-25 19:13 UTC
Related stories
- US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
The Hacker News · 2026-09-30
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- FBI tells ShinyHunters members to turn themselves in after recent arrest
BleepingComputer · 2026-09-29
- Former US Air Force members sent to prison over BEC attacks
BleepingComputer · 2026-09-29
- Alleged ShinyHunters leader arrested in the Netherlands
CyberScoop · 2026-09-29