Brand impersonation: Microsoft with low reputation links
Brand impersonation: Paperless Post
Brand impersonation: Proofpoint secure messaging without legitimate indicators
Brand impersonation: Punchbowl
Brand impersonation: QuickBooks notification from Intuit themed company name
Brand impersonation: Robinhood
Brand impersonation: Sharepoint
Brand impersonation: Sharepoint fake file share
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand impersonation: Social Security Administration
Brand impersonation: UK government Home Office
Brand impersonation: USPS
Brand impersonation: Wells Fargo
Brand impersonation: Zoom
Brand impersonation: Zoom via HTML styling
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Callback phishing in body or attachment (untrusted sender)
Callback phishing: SumUp infrastructure abuse
Callback phishing via Apple ID display name abuse
Callback phishing via Intuit service abuse
Callback phishing via Zelle Service Abuse
Callback phishing: Zero-width character obfuscation from freemail sender
Canva infrastructure abuse
Compensation review with QR code in attached EML
Credential phishing: Blue button styled link with file-sharing template artifacts
Credential phishing: Engaging language with IPFS link
Credential phishing: Fake password expiration from new and unsolicited sender
Credential phishing: Financial lure via ActiveCampaign infrastructure
Credential phishing link (unknown sender)
Credential phishing: Personalized document signing request
Credential phishing: Suspicious e-sign agreement document notification
Credential Phishing: W-2 lure with inline SVG Windows logo
Credential theft: Gophish abuse with hidden tracking image
Credential theft: JavaScript date manipulation in HTML body
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Deceptive Dropbox mention
EML attachment with credential theft language (unknown sender)
Evasion: Hidden content divs from freemail sender
Extortion / sextortion in attachment from untrusted sender
Extortion / sextortion (untrusted sender)
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Fake shipping notification with link to free file hosting
Fake thread with suspicious indicators
Fake voicemail notification (untrusted sender)
Fake Zoho Sign template abuse
Google share notification with suspicious comments
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML smuggling with atob in message body