Callback phishing in body or attachment (untrusted sender)
Callback phishing: Social Security Administration fraud
Callback phishing solicitation in message body
Callback phishing: SumUp infrastructure abuse
Callback phishing via Adobe Sign comment
Callback phishing via Apple ID display name abuse
Callback phishing via calendar invite
Callback phishing via DocuSign comment
Callback phishing via e-signature service
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Callback phishing via Intuit service abuse
Callback phishing via Microsoft comment
Callback Phishing via Signable E-Signature Request
Callback phishing via SignFree e-signature request
Callback phishing via Xodo Sign comment
Callback phishing via Yammer comment
Callback phishing via Zelle Service Abuse
Callback phishing via Zoho service abuse
Callback Phishing via Zoom comment
Callback phishing: Zero-width character obfuscation from freemail sender
Callback scam: Impersonation via TimeTrade infrastructure
Callback Scam: Outlook groups
Canva design with suspicious embedded link
Canva infrastructure abuse
Catbox.moe link from untrusted source
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
ClickFunnels link infrastructure abuse
Cloud storage impersonation with credential theft indicators
Commonly abused sender TLD with engaging language
Compensation review with QR code in attached EML
Constant Contact link infrastructure abuse
COVID-19 themed fraud with sender and reply-to mismatch or compensation award
Credential phishing: AWS Lambda URL with recipient targeting
Credential Phishing: Bitcoin portfolio confirmation
Credential phishing: Blue button styled link with file-sharing template artifacts
Credential phishing content and link (untrusted sender)
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links
Credential phishing: Email delivery failure impersonation
Credential phishing: Engaging language and other indicators (untrusted sender)
Credential phishing: Fake card notification with tracking lure
Credential phishing: Fake password expiration from new and unsolicited sender
Credential phishing: Fake storage alerts (unsolicited)
Credential phishing: Financial lure via ActiveCampaign infrastructure
Credential phishing: Generic document share with unicode and proceedural greeting template
Credential phishing: Generic document sharing
Credential phishing: Hyper-linked image leading to free file host
Credential phishing language and suspicious indicators (unknown sender)
Credential phishing link (unknown sender)
Credential phishing: Onedrive impersonation