Attack spotlight

Who are you trying to April Fool with that email scam?

April 1, 2025

Who are you trying to April Fool with that email scam?

Some of our favorite “worst” scam attempts from the past year

Ready to see Sublime 
in action
Get a demo
Authors
Threat Detection Team
Threat Detection Team
Sublime

The Detection team here at Sublime sees some of the worst email scams. Scams that take advantage of a target’s innate goodness, requesting charitable donations or asking for help after a disaster. Scams that take advantage of economic need, tricking people into clicking links in the hopes of a new job or a much needed bonus. And the scams we loathe the most, the ones using fear as a motivator, like invites to fake termination meetings and extortion messages that include images of your home pulled from Google Street View.

But we also get to see a different kind of “worst” email scams.

We get to see the scams that are so poorly crafted that even we have to laugh through the malicious intent. This April Fools’ Day, we present to you some of our favorite “worsts” from the past year.

Illumi-naughty!

While the Detection team can neither confirm nor deny the existence of the Illuminati (you know, the organization that secretly controls the world), we’re pretty sure they wouldn’t be using Yahoo Mail or Gmail for recruitment.

Keanu Reeves, the bassist for Dogstar

Celebrity impersonations are a common scam tactic, but generally, they don’t involve focusing on a celeb’s lesser known accomplishments (or use their full, non-SAG name).

You don’t have to be in it to win it

We’re not sure why the largest social media network would resort to starting a lottery to attract new users (or how they managed to get HSBC involved), but then we have no idea how much money Meta has spent on the Metaverse.

Generally speaking, Americans don’t pay other Americans in Euros… and lottery winners don’t randomly give away millions to strangers.

A thesaurus in the wrong hands…

Sending an ATM card by shipping container seems pretty inefficient, but if you’re going to do it, make sure you pick it up in a reasonable amount of time.

Don’t peek at these Looks

While Google Looker Studio service abuse is not a laughing matter, we do tip our hat to clever wordplay. Also, we definitely had to crop out the bottom of this email.

Go big or go home

This one was sent to a recipient list as big as the logos that were embedded.

Ok, this one got us

Do we want to open a suspicious message? No. Do we want to review the employee handbook? No. But do we want FREEEEEE FOOD!!!? Yes…

Don’t be April Fooled by a scammer this year

These are all funny examples, but most of the scams we see aren’t funny at all. Attacks are getting more sophisticated every day thanks to new tools and techniques:

  • AI/LLMs: Attackers can use free and low cost AI tools to learn about their targets and then rapidly generate highly-targeted spear phishing attacks at a never before seen speed and scale.
  • Phishing kits/Phishing as a service (PhaaS): Kits and PhaaS offerings (ex: Tycoon 2FA) help bad actors create and deploy large scale phishing campaigns with a low level of effort at an affordable rate.

These advancements have helped bad actors attack, iterate, and evolve at a velocity that exceeds the capabilities of default and traditional email security systems. Because of this, the most effective email security platforms are adaptive, using AI and machine learning to stay ahead of the latest tactics and techniques deployed by bad actors.

If you enjoyed these examples, check out our regular Attack Spotlights. While not funny, we think you’ll find them interesting and informative. Here are some recent posts:

Heading

About the authors

Threat Detection Team
Threat Detection Team
Sublime

The Threat Detection team at Sublime is responsible for monitoring environments to discover emerging email attacks and developing new Detection Rules for the Core Feed.

Get the latest

Sublime releases, detections, blogs, events, and more directly to your inbox.

check
Thank you!

Thank you for reaching out.  A team member will get back to you shortly.

Oops! Something went wrong while submitting the form.

Related Articles

December 29, 2025
5 email security trends from 2025
Sublime news

5 email security trends from 2025

Brian BaskinPerson
Brian Baskin
Threat Research
Person
December 18, 2025
How to build fast similarity search for email from the ground up
Sublime news

How to build fast similarity search for email from the ground up

Ross WolfPerson
Ross Wolf
Engineering
Person
December 16, 2025
Evolving our brand as Sublime grows
Sublime news

Evolving our brand as Sublime grows

Omar JalalzadaPerson
Omar Jalalzada
Head of Design
Kirk JohnsonPerson
Kirk Johnson
Creative Director

Frequently asked questions

What is email security?
Email security refers to protective measures that prevent unauthorized access to email accounts and protect against threats like phishing, malware, and data breaches. Modern email security like Sublime use AI-powered technology to detect and block sophisticated attacks while providing visibility and control over your email environment.

Now is the time.

See how Sublime delivers autonomous protection by default, with control on demand.

BG Pattern