Attachment with encrypted zip (unsolicited)
Attachment with macro calling executable
Attachment with unscannable encrypted zip
Attachment: XLSX file with suspicious print titles metadata
Attachment: ZIP file with CVE-2026-0866 exploit
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC with unusual reply-to or return-path mismatch
Benefits enrollment impersonation
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Fake secure email portal with HTML obfuscation
Body HTML: Comment with 24-character hex token
Body HTML: Recipient SLD in HTML class
Body: HTML whitespace stuffing with short initial message
Body: Invisible Unicode obfuscation student loan callback phishing
Body: Suspicious date format
Body: Suspicious table template fingerprint
Body: Yellow highlighted text markers
Brand impersonation: Coinbase with suspicious links
Brand impersonation: DocuSign with embedded QR code
Brand impersonation: File sharing notification with template artifacts
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
Brand impersonation: Microsoft Planner with suspicious link
Brand impersonation: QuickBooks notification from Intuit themed company name
Brand Impersonation: ShareFile
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand impersonation: Stripe notification
Brand impersonation: Zoom
Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
Callback phishing: Social Security Administration fraud
Callback phishing: SumUp infrastructure abuse
Callback phishing via Adobe Sign comment
Callback phishing via calendar invite
Callback phishing via DocuSign comment
Callback phishing via Intuit service abuse
Callback phishing via Zelle Service Abuse
Callback phishing via Zoho service abuse
Canva design with suspicious embedded link
Credential phishing: Generic document share with unicode and proceedural greeting template
Credential phishing: Generic document sharing
Credential phishing: Hyper-linked image leading to free file host
Credential phishing: Image as content, short or no body contents
Credential Phishing: Suspicious language, link, recipients and other indicators
Credential Phishing via Dropbox comment abuse
Credential Phishing: W-2 lure with inline SVG Windows logo
Credential theft: Gophish abuse with hidden tracking image
Credential theft: JavaScript date manipulation in HTML body
Credential theft with 'safe content' deception and social engineering topics
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Cyrillic vowel substitution in subject or display name from unknown sender
Cyrillic vowel substitutions with suspicious subject from unknown sender