Telegram User Recruited Voice Phishing Callers in August
A documented job advertisement for impersonating Google security staff underscores the professionalization of voice-based social engineering.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Do you trust your ability to identify a voice-phishing attempt on your accounts?
In August 2026, a user named Derian posted a job advertisement in a UK-based Telegram channel seeking callers to conduct a voice-phishing scam impersonating the Google Account Security Team. This recruitment effort, documented by the Trellix Advanced Research Center, included a script for callers despite a stated prohibition against script reading.
Why it matters
Voice phishing has emerged as a primary tactic for breaching cloud environments, driving a shift in how cybercriminals organize their operations. The volume of job advertisements for social engineering skills on criminal marketplaces more than doubled between 2024 and 2025 as attackers move toward professionalized recruitment models.
Voice phishing became the second most common initial access method in 2025 and currently ranks as the primary tactic for breaking into cloud environments. These figures contrast with 2024 levels, reflecting a significant increase in the prevalence of social engineering as a formal criminal job market.
The players
Derian
An unidentified user who published a recruitment advertisement for voice-phishing services on a Telegram channel.
Trellix Advanced Research Center
A cybersecurity research organization that tracks emerging threat vectors and documents dark web activities through its Dark Web Roast project.
FBI Internet Crime Complaint Center
A division of the Federal Bureau of Investigation that aggregates and reports data on national internet-based criminal activity and fraud.
The details
The recruitment process used a Telegram channel to solicit callers for social engineering campaigns—the use of deception to manipulate individuals into divulging confidential information. By providing a specific script, the recruiter aimed to standardize the impersonation of the Google Account Security Team to facilitate the theft of data and money. This reflects a broader trend of criminal organizations using established labor market structures to scale their attack vectors against cloud environments.
Timeline
2024: Criminal job advertisement growth metrics established a baseline for current analysis.
2025: Reported internet scam losses reached a total of $20.87 billion.
August 2026: The Telegram user Derian posted the phishing job advertisement.
The Tech Race
This activity follows the pattern identified by the Trellix Dark Web Roast project regarding the growing professionalization of cybercrime recruitment. It marks a departure from solitary hacking toward organized, employment-based social engineering operations that mirror legitimate staffing models.
Users should be aware that unauthorized contacts claiming to represent the Google Account Security Team are frequently part of coordinated, professionalized scams. Vigilance is required as these attacks specifically target credentials to gain entry into cloud environments.
The takeaway
The professionalization of voice phishing represents a shift in how criminal groups acquire and deploy human labor for social engineering. Readers should watch for future reports from the FBI Internet Crime Complaint Center to see if the growth in social engineering job postings correlates with further increases in total financial losses.
Further reading
For broader context on how organizations monitor evolving digital threats, see the latest analysis in Cybersecurity.
Source note: This article includes information reported by TheRegister.
Live Poll
Do you trust your ability to identify a voice-phishing attempt on your accounts?






