Security researchers at Check Point have identified a large-scale phishing campaign that is using debt-relief lures to target a vast number of organizations. Over a two-week period, the campaign sent approximately 24,700 emails to more than 9,000 organizations. The attack is a classic example of vishing (voice phishing), where the primary goal is not to get a user to click a link, but to manipulate them into calling a phone number controlled by the attackers. Once on the phone, the scammers use social engineering to persuade victims to divulge sensitive personal and financial information.
The campaign leverages a common and often effective social engineering tactic: the promise of financial gain or relief. The emails are crafted to create a sense of urgency, suggesting the recipient is eligible for a debt-relief program. Instead of a malicious link or attachment, the call to action is a phone number.
This vishing approach has several advantages for the attackers:
The ultimate goal is to harvest credentials, credit card numbers, bank account details, and other personally identifiable information (PII) for financial fraud.
The attack chain is straightforward but effective:
T1566 - Phishing.T1598 - Phishing for Information.This campaign runs parallel to other major threats, such as the disruption of infrastructure used by the China-linked group QTFY, demonstrating the diverse range of threats organizations face daily.
No specific Indicators of Compromise (IOCs) such as phone numbers, email addresses, or domains were provided in the source articles.
M1017 - User Training.The primary defense against social engineering and vishing is to train users to recognize and report suspicious communications.
Modern email security gateways use reputation and content analysis to block large-scale phishing campaigns.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.