HR impersonation via e-sign agreement comment
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Australian Federal Police with criminal case language
Impersonation: Employee name in subject with suspicious sender
Impersonation: Employee using fabricated identity in initial contact
Impersonation: Executive using numbered local part
Impersonation: Fake product discount promotion
Impersonation: HR administrative center PDF password lure
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: IT Department mailbox storage alert
Impersonation: Legal firm with copyright infringement notice
Impersonation: Recipient organization in sender display name with credential theft image
Impersonation: Salesforce fake campaign failure notification
Impersonation: SAM/SBA federal registration
Impersonation: SharePoint reply header anomaly
Impersonation: Suspected supplier impersonation with suspicious content
Impersonation using recipient domain (untrusted sender)
Inbound message from popular service via newly observed distribution list
Investor solicitation with organization targeting
Invoicera infrastructure abuse
Issuu document with suspicious embedded link
Job scam (unsolicited sender)
Job scam with specific salary pattern
Link abuse: Self-service creation platform link with suspicious recipient behavior
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: BEC with newly registered domains and financial keywords
Link: Blogspot hosting explicit romance content
Link: Breely link masquerading as PDF
Link: chatbot.page platform abuse
Link: Compromised WordPress site redirecting to suspicious root domain
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential harvesting with excess padding evasion
Link: Credential phishing traversing Russian infrastructure
Link: Credential phishing via WordPress
Link: Credential phishing with obfuscated JavaScript redirect
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: Delimited encoded path parameters (~V~ scheme)
Link: Direct link to Dropbox Paper file
Link: Direct link to Zoom Docs from non-Zoom sender
Link: Direct POWR.io Form Builder with suspicious patterns
Link: Display text is 'unsb'
Link: Display text matches subject line
Link: Document sharing invitation template