Attachment: ICS calendar with embedded file from internal sender with SPF failure
Attachment: PDF with credential theft language and invalid reply-to domain
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Suspicious date format
Brand impersonation: DocuSign
Brand impersonation: Navan
Brand impersonation: State Farm
Brand impersonation: Survey request with credential theft indicators
Business Email Compromise (BEC) attempt from unsolicited sender
Cyrillic vowel substitution in subject or display name from unknown sender
DocuSign impersonation via spoofed Intuit sender
Extortion / sextortion in attachment from untrusted sender
Extortion / sextortion (untrusted sender)
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: Outlook Express mailer
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
Headers: System account impersonation with empty sender address
Headers: X-Source-Auth mismatch with mismatched reply-to domain
Impersonation: SharePoint reply header anomaly
Link: BEC with newly registered domains and financial keywords
Reconnaissance: Empty subject with mismatched reply-to from new sender
Sender: IP address in local part
Service Abuse: Nifty.com with impersonation
Service abuse: PayPal manager account creation with callback scam indicators
Spoofable internal domain with suspicious signals
Vendor impersonation: Thread hijacking with typosquat domain
VIP impersonation: Fake thread with display name match, email mismatch
VIP Impersonation via Google Group relay with suspicious indicators
VIP local_part impersonation from unsolicited sender