Service abuse: Zohodesk reply-to mismatch with job scam indicators
Spam: Cold outreach from Cloudflare-hosted newly registered domain
Spam: Fake dating profile notification
Spam/fraud: Predatory journal/research paper request
Spam: Mastercard promotional content with image-based body
Spam: New job cold outreach from unsolicited sender
Spam: Sendersrv.com with financial communications and unsubscribe language
Spam: Sexually explicit content with emoji in subject from freemail provider
Spam: Website errors solicitation
Spoofable internal domain with suspicious signals
Suspected lookalike domain with suspicious language
Suspicious attachment with unscannable Cloudflare link
Suspicious invoice reference with missing or image-only attachments
Suspicious newly registered reply-to domain with engaging financial or urgent language
Suspicious recipient pattern and language with low reputation link to login
Suspicious recipients pattern with NLU credential theft indicators
Suspicious recipients pattern with no Compauth pass and suspicious content
Vendor compromise: GovDelivery message with suspicious link
Vendor impersonation: Thread hijacking with typosquat domain
Venmo payment request abuse
VIP impersonation: Fake thread with VIPs missing email metadata
VIP impersonation: Payment handoff with VIP display name authored fake threads
VIP Impersonation via Google Group relay with suspicious indicators
VIP impersonation: VIP payment redirect handoff via fake threads
VIP impersonation with BEC language (near match, untrusted sender)
VIP impersonation with charitable donation fraud
VIP impersonation with invoicing request
VIP impersonation with urgent request (strict match, untrusted sender)
VIP impersonation with w2 request with reply-to mismatch
Xero infrastructure abuse
X (Twitter) impersonation with credential phishing motives
Zoom Events newsletter abuse