Abuse: Robinhood injected content
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
Attachment: Any .sap file (unsolicited)
Attachment: Callback phishing solicitation via text-based file
Attachment: Compensation review lure with QR code
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: Dropbox image lure with no Dropbox domains in links
Attachment: EML file contains HTML attachment with login portal indicators
Attachment: EML file with HTML attachment (unsolicited)
Attachment: EML with link to credential phishing page
Attachment: EML with Sharepoint link likely unrelated to sender
Attachment: Fake secure message and suspicious indicators
Attachment: HTML smuggling Microsoft sign in
Attachment: HTML smuggling - QR Code with suspicious links
Attachment: ICS calendar invite with financial lure and suspicious link
Attachment: ICS calendar invite with photo/file share lure
Attachment: ICS calendar with embedded file from internal sender with SPF failure
Attachment: ICS file with meeting prefix
Attachment: ICS invite meeting lure
Attachment: ICS Link With Valueless Base64 Query Parameter
Attachment: ICS voicemail lure with suspicious link
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Microsoft 365 credential phishing
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: QR code with credential phishing indicators
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: Risk assessment PDF with inline image
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: USDA bid invitation impersonation
Attachment with auto-executing macro (unsolicited)
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC/Fraud: Scam lure with freemail pivot
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
BEC: Tax document request
BEC with unusual reply-to or return-path mismatch
Benefits enrollment impersonation
Body: AI-generated invoice template artifacts
Body: Embedded email headers indicative of thread hijacking/abuse
Body HTML: Recipient SLD in HTML class
Body: HTML whitespace stuffing with short initial message
Brand impersonation: AARP
Brand impersonation: Adobe (QR code)