
UBC has received multiple reports of emails claiming a printer order was just placed using the recipient's account, sent under the names of real companies like Staples and Dell. The emails don't contain a malicious link. Instead, they tell you to call a toll-free number if you want to dispute the charge or cancel the order.
That phone call is the attack.
This tactic is known as TOAD, short for Telephone-Oriented Attack Delivery. The email's only job is to create urgency and get you to pick up the phone. Once you call, you're speaking to a fraudulent "support agent" who will try to walk you through steps that hand over your credentials, your financial information, or remote access to your device.
By moving the interaction to a phone call, the attacker steps outside every automated protection UBC has in place. From that point on, the only thing standing between them and your information is your own judgment in the moment.
Our mail team has put content filters in place to catch this current wave of printer order scam emails. But this is a tactic, not a single campaign, and the theme changes regularly. Recent versions have impersonated:
- Printer or electronics purchases (Staples, Dell)
- iPhone or device orders
- Subscription renewals (PC support services, Zoom support, and similar)
- Generic "your payment is being processed" notices that don't even specify what was purchased
Expect the next wave to use a different brand and a different product. The pattern to watch for stays the same.
How to Spot a TOAD Email
- You don't recognize the purchase, and the email pushes you to call a number rather than log in to an account or visit a website
- The phone number is the only way offered to resolve the issue
- There's pressure to act quickly, cancel now, dispute immediately, before the charge processes
- The message may look legitimate, real logos, real formatting, sometimes even sent through the real company's systems
What to Do
- Never call the number in the email. If you're worried a charge might be real, go directly to the company's official website or the number on your card statement, not the one provided in the email.
- Never provide credentials, financial details, or remote access to anyone who calls you or whom you called in response to an unsolicited email.
- If you already called and shared information or installed something at their request, contact UBC Cybersecurity at security@ubc.ca.
- Report the email to security@ubc.ca.
The Bottom Line
If an email's main instruction is "call this number," treat that as the red flag itself, regardless of how convincing the rest of the message looks. Legitimate companies give you account access and official contact channels. They don't rely on a single toll-free number buried in an unexpected order confirmation.