Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: Exodus
Brand impersonation: GitHub with callback scam indicators
Brand impersonation: Government / Tax Authority document lure
Brand impersonation: Interac
Brand impersonation: Internal Revenue Service
Brand impersonation: LastPass
Brand impersonation: Mailchimp
Brand impersonation: McAfee
Brand impersonation: MetaMask
Brand impersonation: Microsoft logo or suspicious language with open redirect
Brand impersonation: Microsoft Planner with suspicious link
Brand impersonation: Microsoft quarantine release notification in image attachment
Brand impersonation: Microsoft with embedded logo and credential theft language
Brand impersonation: Microsoft with low reputation links
Brand impersonation: Morgan Stanley
Brand impersonation: Navan
Brand impersonation: SendGrid
Brand impersonation: Sharepoint
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand Impersonation: Shein
Brand impersonation: Square
Brand impersonation: Survey request with credential theft indicators
Brand impersonation: TikTok
Brand impersonation: Toronto-Dominion Bank
Brand impersonation: Trust Wallet
Brand impersonation: UK government Home Office
Brand impersonation: USPS
Brand impersonation: Vanguard
Brand impersonation: Wise
Brand impersonation: Zoom
Business Email Compromise (BEC) attempt from untrusted sender
Business Email Compromise (BEC) with request for mobile number
Business Email Compromise: Request for mobile number via reply thread hijacking
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Callback phishing in body or attachment (untrusted sender)
Callback phishing via Apple ID display name abuse
Callback phishing via calendar invite
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Callback phishing via Microsoft comment
Callback phishing via Yammer comment
Canva design with suspicious embedded link
Canva infrastructure abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
COVID-19 themed fraud with sender and reply-to mismatch or compensation award
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
Credential phishing: Email delivery failure impersonation