Domain impersonation: Freemail reply-to local lookalike with financial request
EML attachment with credential theft language (unknown sender)
Employee impersonation: Payroll fraud
Employee impersonation with urgent request (untrusted sender)
Encrypted Microsoft Office files from untrusted sender
Evasion: Hidden content divs from freemail sender
Extortion / sextortion in attachment from untrusted sender
Extortion / sextortion (untrusted sender)
Fake email quarantine notification
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Fake message thread with a suspicious link and engaging language from an unknown sender
Fake request for tax preparation
Fake scan-to-email message
Fake shipping notification with link to free file hosting
Fake thread with suspicious indicators
Fake voicemail notification (untrusted sender)
Fake Zoom meeting invite with suspicious link
File sharing link from suspicious sender domain
File sharing link with a suspicious subject
Fraudulent e-commerce operators
Fraudulent order confirmation/shipping notification from Chinese sender domain
Free email provider sender with mismatched provider reply-to
Free subdomain link with login or captcha (untrusted sender)
Generic service abuse from newly registered domain
Google Accelerated Mobile Pages (AMP) abuse
Google Drive abuse: Credential phishing link
Google Drive direct download link from unsolicited sender
Google Notification alert link from non-Google sender
Google services using g.co shortlinks
Google share notification with suspicious comments
Hardbacon infrastructure abuse
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: Invalid recipient domain with mismatched reply-to from new sender
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
Headers: System account impersonation with empty sender address
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
HTML smuggling containing recipient email address
Impersonation: Australian Federal Police with criminal case language
Impersonation: Chrome Web Store policy
Impersonation: Employee name in subject with suspicious sender
Impersonation: Employee using fabricated identity in initial contact
Impersonation: Executive using numbered local part
Impersonation: Fake Gmail attachment
Impersonation: HR administrative center PDF password lure
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: Legal firm with copyright infringement notice
Impersonation: Recipient organization in sender display name with credential theft image