Brand impersonation: McAfee
Brand impersonation: MetaMask
Brand impersonation: Microsoft logo or suspicious language with open redirect
Brand impersonation: Microsoft Planner with suspicious link
Brand impersonation: Microsoft quarantine release notification in image attachment
Brand impersonation: Microsoft with embedded logo and credential theft language
Brand impersonation: Microsoft with low reputation links
Brand impersonation: Navan
Brand impersonation: SendGrid
Brand impersonation: Sharepoint
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand Impersonation: Shein
Brand impersonation: Square
Brand impersonation: Survey request with credential theft indicators
Brand impersonation: TikTok
Brand impersonation: Toronto-Dominion Bank
Brand impersonation: Trust Wallet
Brand impersonation: UK government Home Office
Brand impersonation: USPS
Brand impersonation: Vanguard
Brand impersonation: Wise
Brand impersonation: Zoom
Business Email Compromise (BEC) attempt from untrusted sender
Business Email Compromise (BEC) with request for mobile number
Business Email Compromise: Request for mobile number via reply thread hijacking
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Callback phishing in body or attachment (untrusted sender)
Callback phishing via Apple ID display name abuse
Callback phishing via calendar invite
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Callback phishing via Microsoft comment
Callback phishing via Yammer comment
Canva design with suspicious embedded link
Canva infrastructure abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
COVID-19 themed fraud with sender and reply-to mismatch or compensation award
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
Credential phishing: Email delivery failure impersonation
Credential phishing: Engaging language and other indicators (untrusted sender)
Credential phishing: Engaging language with IPFS link
Credential phishing: Fake card notification with tracking lure
Credential phishing: Fake password expiration from new and unsolicited sender
Credential phishing: Financial lure via ActiveCampaign infrastructure
Credential phishing: Generic document share template
Credential phishing: Generic document sharing
Credential phishing: Image as content, short or no body contents
Credential phishing language and suspicious indicators (unknown sender)
Credential phishing: Onedrive impersonation