Adobe branded PDF file linking to a password-protected file from untrusted sender
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
Attachment: Calendar invite with Google redirect and invoice request
Attachment: Cold outreach with invitation subject and not attachment
Attachment: Compensation review lure with QR code
Attachment: Compensation-themed DOCX with QR code credential theft
Attachment: Credit card application with WhatsApp contact
Attachment: EML with link to credential phishing page
Attachment: Encrypted PDF with credential theft body
Attachment: Encrypted PDF with credential theft language in EML
Attachment: Fake attachment image lure
Attachment: Fake scan-to-email
Attachment: Fake secure message and suspicious indicators
Attachment: Fake Slack installer
Attachment: Fake Zoom installer
Attachment: Fictitious invoice using LinkedIn's address
Attachment: GZ archive with credential theft content
Attachment: HTML smuggling - QR Code with suspicious links
Attachment: ICS calendar invite with photo/file share lure
Attachment: ICS file with credential theft indicators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: Office file contains OLE relationship to credential phishing page
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Attachment: PDF proposal with credential theft indicators
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with suspicious language and redirect to suspicious file type
Attachment: QR code link with base64-encoded recipient address
Attachment: QR code with credential phishing indicators
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: RFP/RFQ impersonating government entities
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: USDA bid invitation impersonation
Attachment: Word document with hyperlink and fraud language
BEC: Employee impersonation with subject manipulation
BEC: Executive coaching vendor impersonation
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
BEC/Fraud: Student loan callback phishing
BEC: Tax document request
BEC: Wealth management lure from newly registered domain
BEC with unusual reply-to or return-path mismatch
Body: AI-generated invoice template artifacts