Fake scan-to-email message
Fake shipping notification with link to free file hosting
Fake shipping notification with suspicious language
Fake thread with suspicious indicators
Fake voicemail notification (untrusted sender)
Fake warning banner using confusable characters
Fake Zoho Sign template abuse
Fake Zoom meeting invite with suspicious link
Fraudulent e-commerce operators
Fraudulent order confirmation/shipping notification from Chinese sender domain
Free subdomain link with credential theft indicators
Google Accelerated Mobile Pages (AMP) abuse
Google Drive direct download link from unsolicited sender
Google Notification alert link from non-Google sender
Google services using g.co shortlinks
Google share notification with suspicious comments
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML smuggling with atob in message body
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Australian Federal Police with criminal case language
Impersonation: Chrome Web Store policy
Impersonation: Employee name in subject with suspicious sender
Impersonation: Employee using fabricated identity in initial contact
Impersonation: Fake Gmail attachment
Impersonation: Fake product discount promotion
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: IT Department mailbox storage alert
Impersonation: Legal firm with copyright infringement notice
Impersonation: Recipient organization in sender display name with credential theft image
Impersonation: Salesforce fake campaign failure notification
Impersonation: SharePoint reply header anomaly
Impersonation: Suspected supplier impersonation with suspicious content
Inline image as message with attachment or link
Investor solicitation with organization targeting
Invoicera infrastructure abuse
Job scam (unsolicited sender)
Job scam with specific salary pattern
Link: Abused Adobe Express
Link: Adobe share from unsolicited sender
Link: Adobe share with suspicious indicators
Link: Apple App Store link to apps impersonating AI adveristing
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Base64 encoded recipient address in URL fragment with hex subdomain