Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script
Trellix mocks a Telegram ad recruiting voice-phishers impersonating Google while forbidding script reading.
Trellix's Dark Web Roast described an August Telegram post by a user called Derian in a UK fraud channel that hired callers to pose as Google's Account Security Team. The ad forbade reading from scripts, then printed the exact call script, including a claim that the line was recorded. The article notes FBI IC3 reported $20.87 billion in 2025 internet-scam losses and that ReliaQuest saw English-language social-engineering job ads more than double from 2024 to 2025. Google said voice phishing became the second-most common initial-access method and the leading tactic against cloud environments.
- UK Telegram ad hired callers to impersonate Google Account Security.
- Post banned script reading, then printed the exact vishing script.
- Google ranked voice phishing second for initial access, first in cloud.
- FBI IC3 reported $20.87 billion in internet-scam losses for 2025.
Full article497 words · extracted from theregister.com · click to collapse
security
More mockery and memes from the Dark Web Roast
Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad that also included the exact script they had to read during these scam calls.
This and other true-crime tales of criminals making fools of themselves appear in the latest installment of the Trellix Advanced Research Center’s Dark Web Roast, which uses memes and mockery to troll criminals on the dark web.
It also acknowledges: “While these incidents are genuinely amusing, they represent real criminal activities causing significant harm.”
REG AD
One of these incidents from August involves a Telegram user identified by Trellix as Derian (@crɑick) who posted an ad in the UK Fraudsters Telegram channel. “Hiring - Female/Male Mail Callers,” the advertisement said, seeking “USA/CA (white sounding)” applicants and, in bold, “NO SCRIPT READING.”
REG AD
The ad then proceeded to print the exact script the callers would read: “Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with Larry Boyles?”
The Trellix threat-intel analysts note that the “‘recorded line’ flourish is a nice touch, because nothing says legitimacy like a fraudster cosplaying compliance theatre. The pretexting playbook is depressingly effective, but the recruiter’s QA process is roughly as robust as the fake Google team it impersonates.”
Burn, baby, burn.
The Register previously spoke with Trellix VP of threat intelligence strategy John Fokker about the Dark Web Roast, and he said the idea came from a desire to take an "almost psyops" approach to covering the criminal underground. "We don't want to glorify them, what's the opposite we can do? We're going to roast them," Fokker told us during a conversation at RSAC.
"I'm trying to spark a debate, or a healthy conversation, about what we can do as an industry," he said. "Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers."
The FBI’s Internet Crime Complaint Center (IC3) recently reported its most damaging year for internet scams, with 2025’s data pegging reported losses at $20.87 billion, and English-language social engineering is among the most in-demand skill sets on underground forums. One report by threat detection and response firm ReliaQuest found the number of job advertisements posted on criminal marketplaces mentioning this particular talent more than doubled between 2024 and 2025.
Plus, according to Google, voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate – and the No. 1 tactic used when breaking into cloud environments.
So when these criminals do dumb things, we’re happy to see Fokker’s team call them out.®