Attachment: Calendar invite from recently registered domain
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: PDF with multistage landing - ClickUp abuse
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
Brand impersonation: Microsoft fake sign-in alert
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand impersonation: Silicon Valley Bank
Brand impersonation: Stripe notification
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Fraudulent order confirmation/shipping notification from Chinese sender domain
Generic service abuse from newly registered domain
Impersonation: Suspected supplier impersonation with suspicious content
Link: Abused Adobe Express
Link: Commonly Abused Web Service redirecting to ZIP file
Link: Cryptocurrency fraud with suspicious links
Link: Financial account issue with suspicious indicators
Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - ClickUp abuse
Link: Multistage landing - Published Google Doc
Link: Romance/Sexual Language With Suspicious Link
New link domain (<=10d) from untrusted sender
Newly registered sender or reply-to domain with newly registered linked domain
New sender domain (<=10d) from untrusted sender
Recruitee Infrastructure Abuse
Service abuse: AppSheet infrastructure with suspicious indicators
Service abuse: Google Drive share from new reply-to domain
Service abuse: Google Firebase sender address with suspicious content
Spam/fraud: Predatory journal/research paper request
Spam: New link domain (<=10d) and emojis
Suspected lookalike domain with suspicious language
Suspicious newly registered reply-to domain with engaging financial or urgent language
Vendor compromise: GovDelivery message with suspicious link
Vendor impersonation: Thread hijacking with typosquat domain
VIP impersonation: Fake thread with display name match, email mismatch