Credential phishing: Re-Authentication lure
Credential phishing: Suspicious e-sign agreement document notification
Credential Phishing: Suspicious language, link, recipients and other indicators
Credential phishing: Suspicious subject with urgent financial request and link
Credential phishing: Tax form impersonation with payment request
Credential Phishing via Dropbox comment abuse
Credential Phishing: W-2 lure with inline SVG Windows logo
Credential theft: Gophish abuse with hidden tracking image
Credential theft with 'safe content' deception and social engineering topics
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Cyrillic vowel substitution in subject or display name from unknown sender
Cyrillic vowel substitutions with suspicious subject from unknown sender
Deceptive Dropbox mention
Display Name Emoji with Financial Symbols
DocuSign impersonation via CloudHQ links
Domain impersonation: Freemail reply-to local lookalike with financial request
EML attachment with credential theft language (unknown sender)
Employee impersonation: Payroll fraud
Employee impersonation with urgent request (untrusted sender)
Evasion: Hidden content divs from freemail sender
Evasion: Hidden text using CSS-obscured HTML option labels
Evasion: Variation selectors in subject line
Extortion / sextortion in attachment from untrusted sender
Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
Extortion / sextortion (untrusted sender)
Fake email quarantine notification
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Fake message thread with a suspicious link and engaging language from an unknown sender
Fake request for tax preparation
Fake scan-to-email message
Fake shipping notification with link to free file hosting
Fake shipping notification with suspicious language
Fake thread with suspicious indicators
Fake voicemail notification (untrusted sender)
Fake warning banner using confusable characters
Fake Zoho Sign template abuse
Fake Zoom meeting invite with suspicious link
Fraudulent e-commerce operators
Fraudulent order confirmation/shipping notification from Chinese sender domain
Free subdomain link with credential theft indicators
Google Accelerated Mobile Pages (AMP) abuse
Google Drive direct download link from unsolicited sender
Google Notification alert link from non-Google sender
Google services using g.co shortlinks
Google share notification with suspicious comments
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation