Security1 publisher2 min readPublished
Talos describes $300 'consultancy' calls that screen security staff for insider access
Talos says a $300 offer for an hour's phone consultation is the first stage of a con that screens security practitioners for useful access. Targets who pass end up paid to pull non-public material from co-workers and internal systems.
The Watch · Security desk

What happened
- An unknown social media profile offered the author of Talos's Threat Source newsletter $300 for an hour's phone consultation on digital transformation.
- The profile was sparse, and the consulting firm it claimed to work for had no footprint and a single employee.
- Talos says the call screens for access, and targets who pass are commissioned for a written report, then a 'special report'.
- Talos lists fake recruiters who get candidates to install trojanised software as a second variant of the same approach.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost For the attacker, the price of finding out whether a practitioner is worth pursuing is a $300 hour on the phone.
- exposure Employers can lose non-public information with no malware involved, through a phone call and a paid report their own employee writes.
- decision Awareness training that covers email phishing now has a documented social media case, with profile and pricing checks, to add alongside it.
- constraint Without an actor, dates or a count, defenders cannot size this against other insider risks or tell a one-off from a sustained campaign.
The consultancy version needs no exploit and no malware [4][5]. The target provides the access [5]. At the report stage the practitioner is flattered and asked for insights that are not public [5]. Producing them to collect the fee means reaching out to co-workers, probing internal systems, or trading on professional relationships and friendships [5]. Talos says the target burns trust worth far more than the payment along the way [11].
The first contact asks for opinions on a general topic, and the non-public material comes later [1][5]. The price is set for that first hour [1]. "The figure is low enough to be plausible and high enough to be tempting, but at the same time suspiciously high for an initial consultation without prior qualification," the newsletter's author wrote [3].
On exploitability, the scheme is cheap to run and depends only on the target agreeing at each stage [4]. The people worth screening carry what Talos calls implicit trust not to abuse privileged access or knowledge of vulnerabilities, and the post says threat actors value that trust as much as clients do [9]. The author puts the weak point in the practitioner. "We are prone to believe that we could identify any social engineering, but this is exactly the weakness that attackers count on," the author wrote [8].
What is public is one approach, which the author judged fake from the profile and the price, and Talos's account of the stages that follow [2][3][4]. The post does not name an actor behind this pitch or the fake-recruiter variant, date the approach, say how many practitioners have received similar offers, or link either to a campaign [10].
Talos sets the pitch against clumsy phishing, which it calls easy to identify, and advises wariness of unsolicited social media messages offering payment for a simple service or a lucrative job [7].
What to watch
- Whether Talos or another vendor publishes a named actor, dates, or a count of practitioners who received these consultancy offers.
- A reported case where a practitioner delivered a 'special report', which would show the scheme reaching internal data.
- Whether the consultancy pitch and the fake-recruiter lure turn out to share operators or infrastructure.