Credential phishing: Engaging language and other indicators (untrusted sender)
Credential phishing: Engaging language with IPFS link
Credential phishing: Fake card notification with tracking lure
Credential phishing: Fake password expiration from new and unsolicited sender
Credential phishing: Financial lure via ActiveCampaign infrastructure
Credential phishing: Generic document share with unicode and proceedural greeting template
Credential phishing: Generic document sharing
Credential phishing: Image as content, short or no body contents
Credential phishing language and suspicious indicators (unknown sender)
Credential phishing: Onedrive impersonation
Credential phishing: Re-Authentication lure
Credential phishing: 'Secure message' and engaging language
Credential Phishing: Suspicious language, link, recipients and other indicators
Credential phishing: Suspicious subject with urgent financial request and link
Credential theft: JavaScript date manipulation in HTML body
Credential theft with 'safe content' deception and social engineering topics
Deceptive Dropbox mention
Domain impersonation: Freemail reply-to local lookalike with financial request
EML attachment with credential theft language (unknown sender)
Employee impersonation with urgent request (untrusted sender)
Extortion / sextortion in attachment from untrusted sender
Extortion / sextortion (untrusted sender)
Fake email quarantine notification
Fake message thread with a suspicious link and engaging language from an unknown sender
Fake request for tax preparation
Fake shipping notification with suspicious language
Fake thread with suspicious indicators
Fake voicemail notification (untrusted sender)
Fake Zoom meeting invite with suspicious link
Fraudulent order confirmation/shipping notification from Chinese sender domain
Free subdomain link with credential theft indicators
Google Accelerated Mobile Pages (AMP) abuse
Google Drive abuse: Credential phishing link
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
Headers: System account impersonation with empty sender address
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
HTML content with print styling and credential theft language
Impersonation: Australian Federal Police with criminal case language
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: Recipient organization in sender display name with credential theft image
Impersonation: Salesforce fake campaign failure notification
Impersonation: Suspected supplier impersonation with suspicious content
Issuu document with suspicious embedded link
Job scam (unsolicited sender)
Job scam with specific salary pattern
Link: Adobe share with suspicious indicators
Link: Blogspot hosting explicit romance content