Attachment: QuickBooks PDF lure
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: RFP/RFQ impersonating government entities
Attachment: Risk assessment PDF with inline image
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: Small text file with link containing recipient email address
Attachment: Soda PDF producer with encryption themes
Attachment: Suspicious employee policy update document lure
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
Attachment: USDA bid invitation impersonation
Attachment with VBA macros from employee impersonation (unsolicited)
Attachment: Word document with hyperlink and fraud language
BEC: Employee impersonation with subject manipulation
BEC: Executive coaching vendor impersonation
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
BEC/Fraud: Student loan callback phishing
BEC/Fraud: Unsolicited business acquisition offer
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
BEC: Tax document request
BEC: Wealth management lure from newly registered domain
BEC with unusual reply-to or return-path mismatch
Benefits enrollment impersonation
Body: AI-generated invoice template artifacts
Body: CSS clamp() font obfuscation
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Fake secure email portal with HTML obfuscation
Body HTML: Recipient SLD in HTML class
Body: HTML whitespace stuffing with short initial message
Body: Invisible Unicode obfuscation student loan callback phishing
Body: PayApp transaction reference pattern
Body: Suspicious date format
Body: Suspicious table template fingerprint
Brand impersonation: AARP
Brand impersonation: Adobe Sign with suspicious indicators
Brand impersonation: Adobe with suspicious language and link
Brand impersonation: AliExpress
Brand impersonation: Amazon
Brand impersonation: Amazon Web Services (AWS)
Brand impersonation: Amazon with suspicious attachment
Brand impersonation: American Express (AMEX)
Brand impersonation: Anthropic/Claude with newly registered domain
Brand impersonation: Apple