Link: Suspicious SharePoint document name
Link: Uncommon SharePoint document type with sender's display name
Link: URL scheme obfuscation via split HTML anchors
Link: Zoho form link from unsolicited sender
Microsoft device code phishing
Open redirect (go2.aspx) leading to Microsoft credential phishing
Open Redirect: Google domain with /url path and suspicious indicators
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Potential prompt injection attack in body HTML
QR Code with suspicious indicators
Reconnaissance: All recipients cc/bcc'd or undisclosed
Reconnaissance: Empty message from uncommon sender
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Self-impersonation: Sender matches recipient with bolded name and suspicious link
Self-sent fake PDF attachment with misleading link
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Amazon invitation with suspected callback phishing
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: Google classroom solicitation
Service abuse: Google Firebase sender address with suspicious content
Service abuse: HelloSign from an unsolicited sender address
Service Abuse: HelloSign share with suspicious sender or document name
Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
Service abuse: Meetup.com redirect with brand impersonation
Service abuse: Payoneer callback scam
Service abuse: QuickBooks notification with suspicious comments
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: Suspicious Zoom Docs link
Service abuse: Trello board invitation with VIP impersonation
Sharepoint link likely unrelated to sender
Spam: Attendee list solicitation
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Spam: Commonly observed formatting of unauthorized free giveaways
Spam/fraud: Predatory journal/research paper request
Spam: Item giveaway spam template
Spam: Unsolicited WordPress account creation or password reset request
Spam: Website errors solicitation
Suspicious invoice reference with missing or image-only attachments
Tax Form: W-8BEN solicitation
Venmo payment request abuse
VIP impersonation: Fake thread with display name match, email mismatch
VIP impersonation with charitable donation fraud
Zoom Events newsletter abuse