Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with link to DMG file download
Attachment: PDF with link to zip containing a wsf file
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with password in filename matching body text
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious internal object reference identifier
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with View RFP Document lure with external link
Attachment: PDF with W-9 form indicators
Attachment: RFP/RFQ impersonating government entities
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: Suspicious employee policy update document lure
Attachment: Suspicious PDF created with headless browser
Attachment: SVG file execution
Attachment: SVG file with HTML entity encoded href attributes
Attachment: SVG file with hyperlinks and cursor styling
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
Attachment: USDA bid invitation impersonation
Attachment: Web files with suspicious comments
BEC: Employee impersonation with subject manipulation
BEC: Executive coaching vendor impersonation
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC/Fraud: Scam lure with freemail pivot
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
BEC/Fraud: Student loan callback phishing
BEC/Fraud: Unsolicited business acquisition offer
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
BEC: Tax document request
BEC: Wealth management lure from newly registered domain
BEC with unusual reply-to or return-path mismatch
Benefits enrollment impersonation
Body: CSS clamp() font obfuscation
Body: CSS Hidden text via clip-path
Body: CSS Hidden text via table-column
Body: CVE-2026-42897 Exchange OWA stored XSS
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Fake secure email portal with HTML obfuscation
Body HTML: Comment with 24-character hex token
Body: HTML whitespace stuffing with short initial message