Breaking
Machine Learning

Cyberattack exploits voicemail transcripts to steal credentials

By Owen Fitzgerald 3 min read
Cyberattack exploits voicemail transcripts to steal credentials - cyberattack voicemail
Check Point researchers detected 58,000 malicious emails spoofing voicemail services between August 17 and 31.

More than 7,800 organizations fell victim to a sophisticated phishing scheme that manipulates trust in automated voicemail transcript services. Security researchers at Check Point uncovered over 58,000 malicious emails dispatched between August 17 and August 31. The campaign impersonates internal systems by spoofing sender addresses and using deceptive subject lines, tricking recipients into opening harmful SVG attachments that lead to credential-theft pages.

Attack Mechanics

The emails replicate the format of automated voicemail transcripts, with subject lines like “Automated transcript” followed by a masked phone number and tracking identifier. The sender address mimics an organization’s internal infrastructure, reinforcing credibility. Attachments are disguised as call recordings—examples include filenames like “▷, 001min 09sec_….svg”—but contain hidden scripts that redirect users to phishing sites pre-populated with their email addresses.

Unlike conventional phishing, this method avoids common warning signs. The sender domain aligns with the recipient’s own network, the SVG format appears benign (often bypassing filters designed for executables), and the malicious redirect only triggers after the file is opened. This client-side execution leaves no digital footprint before activation, complicating detection by traditional email defenses.

The phishing pages automatically insert the victim’s email, lowering resistance and boosting success rates. The campaign capitalizes on enterprises’ growing reliance on AI-driven email workflows, which process notifications without human scrutiny, a vulnerability attackers increasingly exploit.

Read Also: Microsoft CEO Calls AI Slowdown Plans Datacenter Surge

Defense Challenges

Standard email security tools depend on reputation checks or known threat signatures, but this attack evades those safeguards through randomized infrastructure, spoofed domains, and seemingly harmless file types. Many filters overlook SVGs, assuming they are static images, while client-side redirects prevent visible links from being flagged during inspection.

Check Point’s Email Security solution counters these tactics using ThreatCloud AI and over 60 specialized AI engines to assess sender behavior, message context, and attachment patterns. It detects spoofed domains, automated-transcript lures, and suspicious SVG activity, blocking threats before delivery. If an attack persists, the system can isolate attachments and block access to phishing sites during active browser sessions.

The risks escalate as organizations deploy AI agents to manage inbound emails, including opening attachments or processing links. These agents may lack the judgment of human users, potentially executing files labeled as “call recording” without verifying their origin. This creates new vulnerabilities as automated systems inherit the same trust assumptions as human workers.

Protective Measures

Owen Fitzgerald

Leave a Reply

Your email address will not be published. Required fields are marked *