Brand impersonation: Venmo
Brand impersonation: Wells Fargo
Brand impersonation: Wise
Brand impersonation: Xodo Sign
Brand impersonation: Zoom
Brand impersonation: Zoom (strict)
Brand impersonation: Zoom via HTML styling
Brand impersonation: Zoom via lookalike domain
Business Email Compromise (BEC) attempt from unsolicited sender
Business Email Compromise (BEC) attempt from untrusted sender
Business Email Compromise (BEC) attempt from untrusted sender (French/Français)
Business Email Compromise (BEC) with request for mobile number
Business Email Compromise: Request for mobile number via reply thread hijacking
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Callback phishing in body or attachment (untrusted sender)
Callback phishing: Social Security Administration fraud
Callback phishing solicitation in message body
Callback phishing: SumUp infrastructure abuse
Callback phishing via Adobe Sign comment
Callback phishing via Apple ID display name abuse
Callback phishing via calendar invite
Callback phishing via DocuSign comment
Callback phishing via e-signature service
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Callback phishing via Intuit service abuse
Callback phishing via Microsoft comment
Callback Phishing via Signable E-Signature Request
Callback phishing via SignFree e-signature request
Callback phishing via Xodo Sign comment
Callback phishing via Yammer comment
Callback phishing via Zelle Service Abuse
Callback phishing via Zoho service abuse
Callback Phishing via Zoom comment
Callback scam: Impersonation via TimeTrade infrastructure
Canva design with suspicious embedded link
Canva infrastructure abuse
Catbox.moe link from untrusted source
ClickFunnels link infrastructure abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
Compensation review with QR code in attached EML
Constant Contact link infrastructure abuse
COVID-19 themed fraud with sender and reply-to mismatch or compensation award
Credential phishing: AWS Lambda URL with recipient targeting
Credential phishing: Blue button styled link with file-sharing template artifacts
Credential phishing content and link (untrusted sender)
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links