Headers: System account impersonation with empty sender address
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
HTML content with print styling and credential theft language
Impersonation: Australian Federal Police with criminal case language
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: Recipient organization in sender display name with credential theft image
Impersonation: Salesforce fake campaign failure notification
Impersonation: Suspected supplier impersonation with suspicious content
Issuu document with suspicious embedded link
Job scam (unsolicited sender)
Job scam with specific salary pattern
Link: Adobe share with suspicious indicators
Link: Blogspot hosting explicit romance content
Link: chatbot.page platform abuse
Link: Credential phishing traversing Russian infrastructure
Link: Credential phishing with obfuscated JavaScript redirect
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: Display text matches subject line
Link: Executable file download with suspicious message content
Link: Figma design deck with credential theft language
Link: File sharing impersonation with suspicious language and sending patterns
Link: File sharing pretext with suspicious body and link
Link: Financial account issue with suspicious indicators
Link: Fraudulent state business filing notice
Link: Free file hosting with undisclosed recipients
Link: Free file host links from suspicious support sender with credential theft language
Link: Generic financial document with proceedural timeline template
Link: Google Forms link with credential theft language
Link: HR impersonation with suspicious domain indicators and credential theft
Link: Intuit link abuse with file share context
Link: Microsoft Dynamics 365 form phishing
Link: Microsoft impersonation using hosted png with suspicious link
Link: Mismatched free file host links with document lure
Link: Multistage Landing - Abused Buildin.ai
Link: Multistage landing - FreshDesk knowledge base abuse
Link: Multistage landing - Ludus presentation
Link: Multistage landing - Published Google Doc
Link: Multistage landing - Scribd document
Link: MyActiveCampaign Link Abuse
Link: PDF filename impersonation with credential theft language
Link: Personal SharePoint with invalid recipients and credential theft language
Link: QR Code with suspicious language (untrusted sender)
Link: Self-sender credential theft with configuration placeholder
Link: Self-sender with sender org in subject and credential theft indicator
Link: Single character path with credential theft body and self sender behavior or invalid recipient