Service abuse: Google Drive share from an unsolicited reply-to address
Service abuse: Google Drive share from new reply-to domain
Service abuse: Google Firebase sender address with suspicious content
Service abuse: Google Groups callback scam
Service abuse: Google OAuth with suspicious redirect destination
Service abuse: HelloSign from an unsolicited sender address
Service Abuse: HelloSign share with suspicious sender or document name
Service abuse: IBM IAM account notification with callback scam indicators
Service abuse: Kagoya.net-hosted domains sending English business lures
Service abuse: Microsoft Forms Pro with suspicious links or QR codes
Service abuse: Microsoft Power Apps callback scam
Service abuse: Microsoft Power Automate callback scam impersonation
Service abuse: Microsoft Power BI callback scam
Service abuse: Microsoft with suspicious indicators in subject
Service abuse: Monday.com callback scam
Service abuse: Monday.com infrastructure with phishing intent
Service abuse: MongoDB Atlas callback scam
Service abuse: Notion free-tier account impersonating VIP
Service abuse: Nylas tracking subdomain with suspicious content
Service abuse: Oracle Cloud Workflow callback scam
Service abuse: Outlook Groups with Google Sites link and evasion tag
Service abuse: Payoneer callback scam
Service abuse: PayPal manager account creation with callback scam indicators
Service abuse: Postman reply-to mismatch with credential theft intent
Service abuse: Power Automate callback scam
Service abuse: QuickBooks notification from new domain
Service abuse: QuickBooks notification with suspicious comments
Service abuse: Recruiting with suspicious language patterns from legitimate platforms
Service abuse: Roomsy with unrelated body content
Service abuse: Sendgrid credential theft with personalized request targeting single recipient
Service abuse: SendGrid-formatted link with actor-controlled fragment
Service abuse: SendGrid impersonation via Sendgrid from new sender
Service abuse: SendThisFile with credential theft and financial language
Service abuse: Settime.io sender with callback scam intent
Service abuse: Soundestlink.com Microsoft impersonation
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: SurveyMonkey with suspicious outbound links
Service abuse: Suspicious Zoom Docs link
Service abuse: Task management message sent via SendGrid
Service abuse: Trello board invitation with VIP impersonation
Service abuse: Vimeo with external plain-text links in message
Service abuse: WeTransfer callback scam
Service abuse: Wufoo credential theft
Service abuse: Zohodesk reply-to mismatch with job scam indicators
Service abuse: Zoom Clips with suspicious reply-to address or links
Service Abuse: Zoom with freemail reply-to and recipient address in greeting
Service abuse: Zoom with newly registered reply-to domain
Sharepoint link likely unrelated to sender
SharePoint OTP for filename matching org name