Generic service abuse from newly registered domain
Google Drive direct download link from unsolicited sender
Google Notification alert link from non-Google sender
Google presentation open redirect phishing
Hardbacon infrastructure abuse
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: Invalid recipient domain with mismatched reply-to from new sender
Headers: System account impersonation with empty sender address
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Honorific greeting BEC attempt with sender and reply-to mismatch
HR impersonation via e-sign agreement comment
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Australian Federal Police with criminal case language
Impersonation: Employee name in subject with suspicious sender
Impersonation: Employee using fabricated identity in initial contact
Impersonation: Executive using numbered local part
Impersonation: Fake product discount promotion
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: IT Department mailbox storage alert
Impersonation: Legal firm with copyright infringement notice
Impersonation: Recipient organization in sender display name with credential theft image
Impersonation: Salesforce fake campaign failure notification
Impersonation: SharePoint reply header anomaly
Impersonation: Suspected supplier impersonation with suspicious content
Impersonation using recipient domain (untrusted sender)
Inbound message from popular service via newly observed distribution list
Investor solicitation with organization targeting
Invoicera infrastructure abuse
Issuu document with suspicious embedded link
Job scam (unsolicited sender)
Job scam with specific salary pattern
Link abuse: Self-service creation platform link with suspicious recipient behavior
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: BEC with newly registered domains and financial keywords
Link: Blogspot hosting explicit romance content
Link: Breely link masquerading as PDF
Link: chatbot.page platform abuse
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential harvesting with excess padding evasion
Link: Credential phishing traversing Russian infrastructure
Link: Credential phishing via WordPress
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: Direct link to Zoom Docs from non-Zoom sender