Scammer's Own Script Betrays Voice Phishing Operation Targeting Google Users
A voice phishing scam advertised on Telegram ironically instructed applicants not to read scripts, while simultaneously providing the exact script to be used.

In a bizarre twist of criminal incompetence, a scammer advertising a voice phishing operation targeting Google Account users on Telegram ironically instructed potential recruits not to read from scripts, only to include the precise script in the same advertisement. The incident, highlighted by threat intelligence firm Trellix in its "Dark Web Roast" report, underscores the persistent and evolving threat of voice phishing, a tactic increasingly favored by cybercriminals.
The scammer, identified by Trellix as Derian (@crɑick), posted an advertisement in the UK Fraudsters Telegram channel seeking English-speaking callers for a purported "Google Security Team." The ad explicitly stated, "NO SCRIPT READING," yet immediately followed with the full script callers were expected to recite. This script included a pretext of calling from the "Google Account Security Team on a recorded line" to verify the identity of the target, a common social engineering tactic.
Trellix analysts noted the "recorded line" detail as a particularly amusing, yet telling, element of the scam, likening it to "cosplaying compliance theatre." They also pointed out the recruiter's apparent lack of quality assurance, suggesting their vetting process was as robust as the fake Google team they were impersonating.
This incident is emblematic of a broader trend. The FBI's Internet Crime Complaint Center (IC3) reported record losses from internet scams in 2025, totaling $20.87 billion. English-language social engineering skills are in high demand on underground forums, with one report indicating a more than doubling of job advertisements mentioning this talent between 2024 and 2025.
Voice phishing, in particular, has surged in prominence. Google data indicates that voice phishing became the second most common method for cybercriminals to gain initial access to victim IT environments last year, and alarmingly, the top tactic for breaching cloud environments. This highlights the growing sophistication and adoption of voice-based attacks, even as individual scams can be undermined by basic operational errors.
Trellix VP of threat intelligence strategy John Fokker described the "Dark Web Roast" initiative as an "almost psyops" approach to countering the criminal underground. The goal, he explained, is to mock and debunk the mystique surrounding threat actors, emphasizing that they are not mythical figures but individuals motivated by financial gain. By highlighting their mistakes, Trellix aims to demystify these actors and foster a more grounded industry conversation about cybersecurity.
The prevalence of such scams, despite their often amateurish execution, serves as a stark reminder for users to remain vigilant. Even seemingly legitimate-sounding calls or messages, especially those impersonating well-known companies like Google, should be treated with extreme caution. Verifying caller identity through independent channels and being wary of any requests for personal information or immediate action are crucial defenses against these evolving threats.