Attachment: Single-page PDF with S3-hosted HTML link
Attachment: Small text file with link containing recipient email address
Body: Fake secure email portal with HTML obfuscation
Brand impersonation: AliExpress
Brand impersonation: Bids & Tenders
Brand impersonation: Chase bank with credential phishing indicators
Brand impersonation: Cloud services with credential theft intent
Brand impersonation: Coinbase with suspicious links
Brand impersonation: DocuSign
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
Brand impersonation: Fake Fax
Brand impersonation: Figma with malicious document access overlay
Brand Impersonation: Gemini Trust Company
Brand impersonation: Google Careers
Brand impersonation: Google Drive fake file share
Brand impersonation: Google fake sign-in warning
Brand impersonation: Google Meet with malicious link
Brand impersonation: Google Workspace alert notification
Brand impersonation: Government / Tax Authority document lure
Brand impersonation: LastPass
Brand impersonation: Microsoft logo or suspicious language with open redirect
Brand impersonation: Microsoft Planner with suspicious link
Brand impersonation: Microsoft Teams invitation
Brand impersonation: Microsoft with low reputation links
Brand impersonation: Navan
Brand impersonation: Paperless Post
Brand impersonation: Proofpoint secure messaging without legitimate indicators
Brand impersonation: Purdue ePlanroom with suspicious links
Brand impersonation: Robinhood
Brand impersonation: Sharepoint fake file share
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand impersonation: Social Security Administration
Brand impersonation: Stripe notification
Brand impersonation: UK government Home Office
Brand impersonation: Zoom
Brand impersonation: Zoom via lookalike domain
Brand impersonation: Zoom with deceptive link display
Callback phishing via Adobe Sign comment
Callback phishing via DocuSign comment
Callback Phishing via Signable E-Signature Request
Callback phishing via SignFree e-signature request
Callback phishing via Xodo Sign comment
Canva design with suspicious embedded link
Catbox.moe link from untrusted source
ClickFunnels link infrastructure abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
Credential phishing: AWS Lambda URL with recipient targeting
Credential phishing: Blue button styled link with file-sharing template artifacts