"Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with Larry Boyles?" — the exact script printed inside a criminal recruitment post on Telegram, even as the same ad insisted, in bold, "NO SCRIPT READING."
Derian's Telegram ad in the UK Fraudsters channel
In August, a Telegram user identified by Trellix as Derian (@crɑick) posted an advertisement in the UK Fraudsters Telegram channel seeking telephone callers for an apparent Google Security Team voice-phishing operation. The ad headline read "Hiring - Female/Male Mail Callers" and specified a preference for "USA/CA (white sounding)" applicants. In bold the advert declared "NO SCRIPT READING." Immediately afterwards, however, the ad printed the exact call script the applicants were meant to deliver — the very script quoted above.
Trellix’s threat-intelligence analysts highlighted the oddity as emblematic of the broader operation. They pointed to the inclusion of the "recorded line" flourish, calling it "a nice touch, because nothing says legitimacy like a fraudster cosplaying compliance theatre," and added that the recruiter’s quality-assurance process "is roughly as robust as the fake Google team it impersonates."
Trellix’s Dark Web Roast as a tactic
The ad appears in the Trellix Advanced Research Center’s Dark Web Roast, a regular feature that uses memes and mockery to troll actors on the criminal underground. Trellix frames the Roast not as glorification but as a counter—"While these incidents are genuinely amusing, they represent real criminal activities causing significant harm," the Roast notes.
John Fokker, Trellix vice president of threat intelligence strategy, described the initiative as an "almost psyops" approach when The Register spoke with him at RSAC. "We don't want to glorify them, what's the opposite we can do? We're going to roast them," Fokker said. He added that he is "trying to spark a debate, or a healthy conversation, about what we can do as an industry" and argued that "Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleVoice phishing: demand, scale, and criminal recruitment
The Trellix example sits against a backdrop of rising voice-phishing activity and organized criminal recruitment for social-engineering talent. The FBI’s Internet Crime Complaint Center (IC3) reported that 2025 was its most damaging year for internet scams, pegging reported losses at $20.87 billion. English-language social engineering was identified as one of the most in-demand skill sets on underground forums.
Supporting that observation, a ReliaQuest report found that the number of job advertisements on criminal marketplaces referencing English-language social engineering more than doubled between 2024 and 2025. Google has said voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to victims' IT estates, and the No. 1 tactic used when breaking into cloud environments.
What this means for technologists, affected enterprises, and the public
- Technologists and security teams: The script in the ad demonstrates how simple pretexts — invoking a "Google Account Security Team" and a "recorded line" — are weaponized in social-engineering playbooks. Teams defending corporate environments should note Google’s observation that voice phishing is a leading technique for initial access and for compromising cloud accounts.
- Affected enterprises and procurement leaders: The explicit call for "USA/CA (white sounding)" voices shows how attackers market and recruit human talent to improve success rates. Procurement and risk teams should consider that threat actors are investing in human resources and QA processes (however flawed) when assessing exposure to social-engineering risks.
- End users and the general public: The combination of familiar brand names and compliance theatre language — "on a recorded line" — is deliberately crafted to lower suspicion. The public should be aware that such pretexts can be scripted and widely circulated by criminal groups.
The episode is, on its face, comic: a recruiter bans script-reading while printing the script verbatim. But the larger picture Trellix paints is less amusing — a market for English-language social engineers, documented multi-billion-dollar losses reported to the IC3, and confirmation from Google that voice phishing is a core vector for access and cloud compromise. Trellix’s Roast aims to puncture any glamor around those actors and to remind defenders that the threat is both mundane and consequential.




