Attachment: QR code link with base64-encoded recipient address
Attachment: QR code with credential phishing indicators
Attachment: QR code with userinfo portion
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: RFP/RFQ impersonating government entities
Attachment: Risk assessment PDF with inline image
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: RTF file with suspicious link
Attachment: RTF with link to free-hosted Cloudflare Pages
Attachment: Self-sender PDF with minimal content and view prompt
Attachment soliciting user to enable macros
Attachment: Suspicious employee policy update document lure
Attachment: SVG files with evasion elements
Attachment: USDA bid invitation impersonation
Attachment with auto-executing macro (unsolicited)
Attachment with auto-opening VBA macro (unsolicited)
Attachment with encrypted zip (unsolicited)
Attachment with high risk VBA macro (unsolicited)
Attachment with suspicious author (unsolicited)
Attachment with VBA macros from employee impersonation (unsolicited)
Attachment: Word document with hyperlink and fraud language
BEC: Employee impersonation with subject manipulation
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC/Fraud: Scam lure with freemail pivot
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
BEC/Fraud: Student loan callback phishing
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
BEC: Tax document request
BEC with unusual reply-to or return-path mismatch
Benefits enrollment impersonation
Body: AI-generated invoice template artifacts
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Fake secure email portal with HTML obfuscation
Body HTML: Recipient SLD in HTML class
Brand impersonation: AARP
Brand impersonation: Adobe (QR code)
Brand impersonation: Adobe Sign with suspicious indicators
Brand impersonation: Adobe with suspicious language and link
Brand impersonation: Amazon
Brand impersonation: Amazon Web Services (AWS)
Brand impersonation: Amazon with suspicious attachment
Brand impersonation: American Express (AMEX)
Brand impersonation: Anthropic/Claude with newly registered domain
Brand impersonation: Apple
Brand impersonation: Aquent