Brand impersonation: Vanta
Brand impersonation: Venmo
Brand impersonation: Wells Fargo
Brand impersonation: WeTransfer
Brand impersonation: Wise
Brand impersonation: Xodo Sign
Brand impersonation: Zoom (strict)
Brand impersonation: Zoom via lookalike domain
Business Email Compromise (BEC) attempt from unsolicited sender
Business Email Compromise (BEC) attempt from untrusted sender
Business Email Compromise (BEC) attempt from untrusted sender (French/Français)
Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
Business Email Compromise (BEC) with request for mobile number
Business Email Compromise: Request for mobile number via reply thread hijacking
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Callback phishing in body or attachment (untrusted sender)
Callback phishing: Social Security Administration fraud
Callback phishing solicitation in message body
Callback phishing: SumUp infrastructure abuse
Callback phishing via Adobe Sign comment
Callback phishing via Apple ID display name abuse
Callback phishing via calendar invite
Callback phishing via DocuSign comment
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Callback phishing via Microsoft comment
Callback Phishing via Signable E-Signature Request
Callback phishing via SignFree e-signature request
Callback phishing via Xodo Sign comment
Callback phishing via Zelle Service Abuse
Callback Phishing via Zoom comment
Callback scam: Impersonation via TimeTrade infrastructure
Canva design with suspicious embedded link
Canva infrastructure abuse
Catbox.moe link from untrusted source
ClickFunnels link infrastructure abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
Constant Contact link infrastructure abuse
COVID-19 themed fraud with sender and reply-to mismatch or compensation award
Credential phishing content and link (untrusted sender)
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
Credential phishing: Email delivery failure impersonation
Credential phishing: Engaging language and other indicators (untrusted sender)
Credential phishing: Fake card notification with tracking lure
Credential phishing: Fake password expiration from new and unsolicited sender
Credential phishing: Fake storage alerts (unsolicited)
Credential phishing: Financial lure via ActiveCampaign infrastructure