Service abuse: Cisco secure email service with financial request
Service abuse: Elastic alerts extortion
Service abuse: Facebook mail notification callback scam
Service abuse: FileMail callback scam
Service abuse: FlipHTML5 with attachment deception and credential theft language
Service abuse: GetAccept callback scam content
Service Abuse: GoDaddy infrastructure
Service abuse: Google Calendar notification with callback scam language
Service abuse: Google Firebase sender address with suspicious content
Service abuse: Google Groups callback scam
Service abuse: IBM IAM account notification with callback scam indicators
Service abuse: Microsoft Power Apps callback scam
Service abuse: Microsoft Power Automate callback scam impersonation
Service abuse: Microsoft Power BI callback scam
Service abuse: Monday.com callback scam
Service abuse: MongoDB Atlas callback scam
Service abuse: Nylas tracking subdomain with suspicious content
Service abuse: Oracle Cloud Workflow callback scam
Service abuse: PayPal manager account creation with callback scam indicators
Service abuse: Recruiting with suspicious language patterns from legitimate platforms
Service abuse: Roomsy with unrelated body content
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
Service abuse: SendThisFile with credential theft and financial language
Service abuse: Settime.io sender with callback scam intent
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: WeTransfer callback scam
Service abuse: Zohodesk reply-to mismatch with job scam indicators
Spam: Fake dating profile notification
Spam/fraud: Predatory journal/research paper request
Spam: Mastercard promotional content with image-based body
Spam: New job cold outreach from unsolicited sender
Spam: Sendersrv.com with financial communications and unsubscribe language
Spam: Sexually explicit content with emoji in subject from freemail provider
Spam: Website errors solicitation
Spoofable internal domain with suspicious signals
Suspected lookalike domain with suspicious language
Suspicious attachment with unscannable Cloudflare link
Suspicious invoice reference with missing or image-only attachments
Suspicious newly registered reply-to domain with engaging financial or urgent language
Suspicious recipient pattern and language with low reputation link to login
Suspicious recipients pattern with NLU credential theft indicators
Suspicious recipients pattern with no Compauth pass and suspicious content
Vendor compromise: GovDelivery message with suspicious link
Vendor impersonation: Thread hijacking with typosquat domain
Venmo payment request abuse
VIP impersonation: Fake thread with VIPs missing email metadata
VIP impersonation: Payment handoff with VIP display name authored fake threads
VIP Impersonation via Google Group relay with suspicious indicators
VIP impersonation: VIP payment redirect handoff via fake threads
VIP impersonation with BEC language (near match, untrusted sender)