Brand impersonation: TikTok
Brand impersonation: Toronto-Dominion Bank
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Callback phishing in body or attachment (untrusted sender)
Callback phishing: Social Security Administration fraud
Callback phishing via e-signature service
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Callback phishing via Intuit service abuse
Callback phishing via Zoho service abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
Compensation review with QR code in attached EML
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
Credential phishing: Image as content, short or no body contents
Extortion / sextortion in attachment from untrusted sender
Fake scan-to-email message
Free subdomain link with credential theft indicators
Google Accelerated Mobile Pages (AMP) abuse
Google Drive abuse: Credential phishing link
Impersonation: Recipient organization in sender display name with credential theft image
Issuu document with suspicious embedded link
Link: Figma design deck with credential theft language
Link: Microsoft Dynamics 365 form phishing
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Link: Multistage landing - Ludus presentation
Link: Multistage landing - Scribd document
Link: QuickBooks image lure with suspicious link
Link to auto-downloaded file with Adobe branding
Link to auto-downloaded file with Google Drive branding
Open Redirect: Google domain with /url path and suspicious indicators
Spam: Mastercard promotional content with image-based body
Suspicious attachment: Duplicate decoy PDF files
Suspicious recipient pattern and language with low reputation link to login
X (Twitter) impersonation with credential phishing motives