Attachment: Calendar invite with suspicious link leading to an open redirect
Attachment: Cold outreach with invitation subject and not attachment
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Body: Embedded email headers indicative of thread hijacking/abuse
Body HTML: Comment with 24-character hex token
Brand impersonation: Hulu
Brand impersonation: KnowBe4
Brand impersonation: SendGrid
Brand Impersonation: Shein
Brand impersonation: SiriusXM
Brand impersonation: Vanguard
Brand impersonation: WeTransfer
Credential theft: Gophish abuse with hidden tracking image
Encrypted Microsoft Office files from untrusted sender
Fake shipping notification with link to free file hosting
Fake shipping notification with suspicious language
Fake thread with suspicious indicators
Headers: Invalid recipient domain with mismatched reply-to from new sender
Headers: risky-recover-production message ID
Invoicera infrastructure abuse
Link abuse: Self-service creation platform link with suspicious recipient behavior
Link: Blogspot hosting explicit romance content
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Link: Romance/Sexual Language With Suspicious Link
Link: Spam website with evasion indicators
Link: Squarespace infrastructure abuse
Mass campaign: Cross Site Scripting (XSS) attempt
Mismatched links: Free file share with urgent language
Open redirect: Cartoon Network
Potential prompt injection attack in body HTML
Reconnaissance: Email address harvesting attempt
Reconnaissance: Empty message from uncommon sender
Sender: IP address in local part
Service abuse: Adobe Sign notification from an unsolicited reply-to address
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: Domains By Proxy sender
Service abuse: Google Firebase sender address with suspicious content
Sharepoint online with external recipients and external display name
Shopify infrastructure abuse
Spam: Attendee list solicitation
Spam: BlackBaud infrastructure abuse
Spam: Campaign with excessive display-text and keywords found
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Spam: Commonly observed formatting of unauthorized free giveaways
Spam: Cryptocurrency airdrop/giveaway
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
Spam: Fake dating profile notification
Spam: Firebase password reset from suspicious sender