Service abuse: GitHub notification with excessive mentions and suspicious links
Service abuse: Google account notification with links to free file host
Service abuse: Google application integration redirecting to suspicious hosts
Service abuse: Google Calendar notification with callback scam language
Service abuse: Google classroom solicitation
Service abuse: Google Drive share from an unsolicited reply-to address
Service abuse: Google Drive share from new reply-to domain
Service abuse: Google Firebase sender address with suspicious content
Service abuse: HelloSign from an unsolicited sender address
Service Abuse: HelloSign share with suspicious sender or document name
Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
Service abuse: Meetup.com redirect with brand impersonation
Service abuse: Microsoft Power Apps callback scam
Service abuse: Microsoft Power Automate callback scam impersonation
Service abuse: Microsoft Power BI callback scam
Service abuse: Monday.com callback scam
Service abuse: Monday.com infrastructure with phishing intent
Service Abuse: Nifty.com with impersonation
Service abuse: Payoneer callback scam
Service abuse: QuickBooks notification from new domain
Service abuse: QuickBooks notification with suspicious comments
Service abuse: Recruiting with suspicious language patterns from legitimate platforms
Service abuse: Roomsy with unrelated body content
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
Service abuse: SendGrid impersonation via Sendgrid from new sender
Service abuse: SendThisFile with credential theft and financial language
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: Suspicious Zoom Docs link
Service abuse: Task management message sent via SendGrid
Service abuse: Trello board invitation with VIP impersonation
Service abuse: Vimeo with external plain-text links in message
Service abuse: WeTransfer callback scam
Service abuse: Wix redirect through bulk mailer domains
Sharepoint link likely unrelated to sender
Sharepoint online with external recipients and external display name
Spam: Attendee list solicitation
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Spam: Commonly observed formatting of unauthorized free giveaways
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
Spam: Fake dating profile notification
Spam: Firebase password reset from suspicious sender
Spam/fraud: Predatory journal/research paper request
Spam: Ghostwriting services scam with manipulative language
Spam: Item giveaway spam template
Spam: Link to blob.core.windows.net from new domain (<30d)
Spam: Mastercard promotional content with image-based body
Spam: New job cold outreach from unsolicited sender
Spam: New link domain (<=10d) and emojis