Fake Google Security Team ad bans script reading, then prints the script

Fake Google Security Team ad bans script reading, then prints the script

Trellix's Advanced Research Center runs a recurring feature called the Dark Web Roast, which uses memes and mockery to call out criminals for their mistakes on the dark web. Its latest installment highlights a Telegram user identified by Trellix as Derian, handle @crɑick, who posted a recruiting ad in the UK Fraudsters Telegram channel in August. The ad read 'Hiring - Female/Male Mail Callers', sought applicants who sounded 'USA/CA (white sounding)', and stated in bold 'NO SCRIPT READING'. Immediately after, the same ad printed the exact script callers were expected to read: 'Good afternoon, this is [name] reaching you on behalf of the Google Account Security Team on a recorded line. Am I speaking with Larry Boyles?' Trellix's threat-intel analysts mocked the contradiction, writing that the 'recorded line' flourish is 'a nice touch, because nothing says legitimacy like a fraudster cosplaying compliance theatre', and that 'the pretexting playbook is depressingly effective, but the recruiter's QA process is roughly as robust as the fake Google team it impersonates.' The Dark Web Roast also acknowledges the more serious side of the story: 'While these incidents are genuinely amusing, they represent real criminal activities causing significant harm.' The Register had previously spoken with Trellix VP of threat intelligence strategy John Fokker about the Dark Web Roast concept. He said the idea came from a desire to take an 'almost psyops' approach to covering the criminal underground: 'We don't want to glorify them, what's the opposite we can do? We're going to roast them.' Fokker added that he is 'trying to spark a debate, or a healthy conversation, about what we can do as an industry', arguing that 'everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers.' The story is set against a backdrop of a worsening scam landscape: the FBI's Internet Crime Complaint Center reported $20.87 billion in losses from internet scams in 2025, its most damaging year on record, and English-language social engineering is among the most in-demand skills on underground forums. ReliaQuest found that job ads on criminal marketplaces seeking that skill more than doubled between 2024 and 2025. Google has said voice phishing surged last year to become the second most common method criminals use to gain initial access to victims' IT systems, and the top tactic for breaking into cloud environments.

Key facts

  • A Telegram ad recruiting callers for a fake Google Security Team voice-phishing scam banned 'script reading' while printing the exact script to use, per Trellix's Dark Web Roast.
  • The ad, posted in August by a user Trellix identified as Derian (@crɑick) in the UK Fraudsters Telegram channel, sought 'USA/CA (white sounding)' callers.
  • The FBI's IC3 reported $20.87 billion in internet scam losses in 2025, its worst year on record.
  • ReliaQuest found job ads on criminal marketplaces seeking English-language social engineering skills more than doubled between 2024 and 2025.
  • Google says voice phishing became the second most common initial access method for cybercriminals last year, and the top method for breaching cloud environments.

Why it matters

Voice phishing has become a major initial access vector: Google says it was the second most common way criminals broke into victims' IT systems last year and the top method for cloud breaches. Trellix's Dark Web Roast is a deliberate attempt to counter the 'mythologizing' of threat actors by publicly mocking their sloppiness, on the theory that puncturing their competence is more useful to defenders than treating them as sophisticated adversaries.

Who it affects

Anyone targeted by calls impersonating a 'Google Account Security Team', plus security teams and researchers tracking vishing recruitment on criminal Telegram channels. The story also concerns the callers themselves, recruited with promises of easy scripted work who receive contradictory instructions from the outset.

How to use it

There is no product here, but the account doubles as an awareness note: genuine account security teams do not run scripted 'recorded line' calls confirming identity like the one Trellix quoted, and that kind of scripted pretext is itself a red flag worth recognizing.

How solid is it

The account rests on Trellix's Dark Web Roast research and a prior on-record conversation The Register had with Trellix VP of threat intelligence strategy John Fokker at RSAC. The framing is openly mocking and meme-driven by design, though Trellix itself notes the underlying crime is real and damaging, and The Register reports it as such rather than as pure comedy.

Risks and caveats

The source gives only the month, August, for the recruiting-ad incident, with no year specified beyond that, and does not say whether Derian/@crɑick was identified, caught or held accountable, nor how many people responded to the ad or how much money the operation made.

“We don't want to glorify them, what's the opposite we can do? We're going to roast them”

— John Fokker, Trellix VP of threat intelligence strategy