Service abuse: Nylas tracking subdomain with suspicious content
Service abuse: Payoneer callback scam
Service abuse: QuickBooks notification from new domain
Service abuse: QuickBooks notification with suspicious comments
Service abuse: SendGrid-formatted link with actor-controlled fragment
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: Suspicious Zoom Docs link
Service abuse: Task management message sent via SendGrid
Service abuse: Wix redirect through bulk mailer domains
Sharepoint file share with suspicious recipients pattern
Sharepoint online with external recipients and external display name
Shopify infrastructure abuse
Spam: BlackBaud infrastructure abuse
Spam: Firebase password reset from suspicious sender
Spam/fraud: Predatory journal/research paper request
Spam: Sendersrv.com with financial communications and unsubscribe language
Spam: Unsolicited malformed PDF
Subject and sender display name contains matching long alphanumeric string
Subject: Suspicious bracketed reference
Suspected cross-site scripting (XSS) found in subject
Suspected lookalike domain with suspicious language
Suspicious attachment: Duplicate decoy PDF files
Suspicious attachment with unscannable Cloudflare link
Suspicious DocuSign share from new domain
Suspicious link to Looker Studio (lookerstudio.google.com) from a new and unsolicited sender
Suspicious message with unscannable Vercel link
Suspicious recipients pattern with NLU credential theft indicators
Suspicious sender display name with long procedurally generated text blob
Suspicious subject with long procedurally generated text blob
Truth Social infrastructure abuse via link redirect
Twitter infrastructure abuse via link shortener
Unusually long local part from untrusted sender address
URI protocol handler: search-ms
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
Vendor compromise: GovDelivery message with suspicious link
Venmo payment request abuse
VIP impersonation: Fake thread with display name match, email mismatch
VIP Impersonation via Google Group relay with suspicious indicators
Xero infrastructure abuse