HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Chrome Web Store policy
Impersonation: Fake Gmail attachment
Impersonation: IT Department mailbox storage alert
Impersonation: SAM/SBA federal registration
Impersonation: SharePoint reply header anomaly
Inline image as message with attachment or link
Link: Adobe share with suspicious indicators
Link: Credential harvesting with excess padding evasion
Link: Display text with excessive right-to-left mark characters
Link: Fake forwarded message with suspicious URL in plain text
Link: Fake secure message notification template
Link: File sharing pretext with suspicious body and link
Link: Microsoft impersonation using hosted png with suspicious link
Link: Mismatched Shopify template button href
Link: PDF and financial display text to free file host
Link: PDF display text with fake copyright claim template
Link: RTL text reversal with recipient email in URL
Link: Self-sender with sender org in subject and credential theft indicator
Link: Self-sent PDF lure with subject correlation
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Suspicious HTML structure with subject mirrored in body and single link
Link: Suspicious SharePoint document name
Link: Suspicious single-domain link with suspicious path and financial lure indicators
Link: Uncommon SharePoint document type with sender's display name
Link: URL fragmented by hidden spans
Link: URL scheme obfuscation via split HTML anchors
Link: Zoho form link from unsolicited sender
Microsoft device code phishing
Open redirect (go2.aspx) leading to Microsoft credential phishing
Open Redirect: Google domain with /url path and suspicious indicators
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Potential prompt injection attack in body HTML
QR Code with suspicious indicators
Reconnaissance: All recipients cc/bcc'd or undisclosed
Reconnaissance: Empty message from uncommon sender
Reconnaissance: Fake real estate inquiry with empty body
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Self-impersonation: Sender matches recipient with bolded name and suspicious link
Self-sent fake PDF attachment with misleading link
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Amazon invitation with suspected callback phishing
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: Cognito Forms with short body from unknown sender
Service abuse: Google classroom solicitation
Service abuse: Google Firebase sender address with suspicious content
Service abuse: HelloSign from an unsolicited sender address
Service Abuse: HelloSign share with suspicious sender or document name