Credential phishing: Tax form impersonation with payment request
Cyrillic vowel substitution in subject or display name from unknown sender
Deceptive Dropbox mention
Display name and subject impersonation using recipient SLD (new sender)
Display Name Emoji with Financial Symbols
Display name impersonation using recipient SLD
DocuSign impersonation via CloudHQ links
DocuSign impersonation via spoofed Intuit sender
Domain impersonation: Freemail reply-to local lookalike with financial request
EML attachment with credential theft language (unknown sender)
Employee impersonation with urgent request (untrusted sender)
Extortion / sextortion (untrusted sender)
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Fake message thread with a suspicious link and engaging language from an unknown sender
Fake shipping notification with link to free file hosting
Fake thread with suspicious indicators
Fake Zoom meeting invite with suspicious link
File sharing link with a suspicious subject
Fraudulent e-commerce operators
Free email provider sender with mismatched provider reply-to
Free subdomain link with credential theft indicators
Generic service abuse from newly registered domain
Google Notification alert link from non-Google sender
Google services using g.co shortlinks
Google share notification with suspicious comments
Hardbacon infrastructure abuse
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: Invalid recipient domain with mismatched reply-to from new sender
Headers: iOS/iPadOS mailer with invalid build number
Headers: Outlook Express mailer
Headers: risky-recover-production message ID
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
Headers: System account impersonation with empty sender address
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Headers: Zimbra mailer from a non-supported OS version
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
Impersonation: Australian Federal Police with criminal case language
Impersonation: Chrome Web Store policy
Impersonation: Executive using numbered local part
Impersonation: HR administrative center PDF password lure
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: Legal firm with copyright infringement notice
Impersonation: SAM/SBA federal registration
Impersonation: SharePoint reply header anomaly
Impersonation: Suspected supplier impersonation with suspicious content
Impersonation using recipient domain (untrusted sender)
Inbound message from popular service via newly observed distribution list
Invoicera infrastructure abuse