// AUTO-GENERATED IOC LIST - DO NOT EDIT MANUALLY
// Managed by automated IOC system
type.inbound
and hash.sha256(sender.email.email) in (
'00d63ceac2fd6e0420e5b39810077268b95dc4f4596d6185fdd68a634acfa1e0', // Attacker-registered domain - BEC reconnaissance campaigns
'01ae75e3d4e040a184e7ffdff91eadc3f0c136cd6ec754a10200a67cb529c771', // Compromised account - assigned ticket ID credential phishing hosted on a lovable.app subdomain
'01eb9fff727d15c5fac229c9db4173d44988389daf483be57e7b8f35e66bb51f', // Observed malicious sender - advance-fee investment fraud campaigns
'0540b57e20e05cdb2ae89fcebc55b4788ae00b93381f30458544674b3a44ff00', // Compromised account - accounts payable lure with EML attachment containing an HTML credential phishing page
'0567d195baff61f8eb84184476011ada4e8d57466aa4833841c592996e7f8cd9', // Compromised account - statement lure with fake PDF tile image linking to a fake Adobe Acrobat password prompt that drops a password-protected zip containing a VBS loader
'05c2551b17530710c9edbfd9bb7aaf8ec145b216edcbab069daae96f4aae908b', // Attacker-controlled throwaway account - executive impersonation BEC reply lures in a shared campaign
'074a551f4b57f71c7f051b4fce84f8e3b50f85e28afc45e3b55384279571a268', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
'08361fdb828f15abcfaf7e041cdf3c6653157ca99c95fd8bf2ba8fde1fbc8f64', // Attacker-controlled domain - serialized new business inquiry BEC lures targeting real estate brokerage agents
'08706553fd4f1e3d3c1ea05f9b2520e210cc810d93c3f34036db5a119544178d', // Compromised account - timecard authorization credential phishing with randomized display name suffixes
'0914d7505e63c31c497bac8cc2001315edee6cbb14d7dd2a125efd06ce0deda9', // Compromised mailbox - BEC enquiry and proposal lures with fake email quarantine notifications
'09c62e04e73beed174d8470d9d212a0ec0127b5a2972cdfd2ad8a654eee4f458', // Newly registered lookalike domain - fake insurance policy delivery lures with typosquat reply-to
'0b02e4dd86f69c17a3fb3b579904120bb3be026eb4049a710627c6631b574bb8', // Attacker-controlled domain - fake SecureSign document delivery credential phishing
'0b9c2c2dd64d54049e0e53507880a250e675ce3d68b51b0ee2165f2ea5ef8903', // Compromised account - IRS and e-signature document credential phishing
'0ba5a0bc781991396b6f347ad6f9be553affaf88a09515f8c3b51419776f23f6', // Compromised account - QuickBooks profit and loss file share credential phishing delivered through legitimate Intuit notification tracking links
'0d3de488a096b39ceb2db13ba7f68374049e2de2e0be6c2da9ef0d83c9337d24', // Observed malicious sender - advance-fee investment fraud campaigns
'0d9d6401c0cffb024be34cedf19034966d01454e802cd2df9206a9eead1823a8', // Compromised account used in BEC/credential phishing campaigns
'0eb988e9f6aca75714c0aaf827336471dda7294b94b0e6d45617fbddae4c5f60', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
'0f8669d310832e5e053a7c29e9d08f43c143f13a66e48d7e0e9852659083cf2f', // Attacker-registered domain - supplier quotation request BEC with lookalike reply-to domain
'0fd0ddb531936d777000be33631274260d81250c833ebf7c06838a896ea3601f', // Compromised domain - SiteGround branded domain expiry phishing hosted on compromised WordPress sites
'103dbd3c01a1e8ab0701fa982e5e3e4b0f1a93cdd85c5fe6e74d75b837818de1', // Attacker-controlled throwaway account - executive impersonation BEC reply lures in a shared campaign
'123cd0a3912744f55f3a3c8ad7401f44112428ea6fedae38eca48a468bab87d7', // Compromised nonprofit executive account - EFT remittance payment fraud and thread hijacking
'126ca3d8255f5e75ddae997d747eb0f5d9626c8a88dfa25687f314e640b873ac', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'14e2a6e8c3b0aa75f25cafed155f6bd2c6111adc9bd239c1f48e394b5fe69d9d', // Attacker-controlled lookalike domain - subjectless campaign delivered via SendGrid with Klaviyo click tracker
'15e7f8cef27a0cad985b0a21496fa70a28897ed56e9d8700ade048bab5307850', // Throwaway freemail account - executive impersonation requesting mobile number for SMS pivot
'16f9b3c2bb2663806fe91a6c76c0033018b7d090488076cd3fd4c9bc0c3ff799', // Observed malicious sender - advance-fee investment fraud campaigns
'1872dac4f5e1bf41b98b805dd5cd6b9d49b85a72e52ef5aa1d8432573e133517', // Compromised consumer ISP account - BEC first contact with rotating display names and a padded dot-delimited review subject targeting municipal government recipients
'1899d688514d0651536482339e377683b86b96a0eb673de2badef384a8f7f3d4', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
'18adc07eaac029b344fa1b4652c684df704ea88ff468eae0caeedbab0851715d', // Attacker-registered domain - Pearson Japan impersonation soliciting LINE contact via QR code
'1c34e20d013ca77c292b3ed03164bb4e99984323ae42bfd38724fae5dec884d4', // Compromised account - purchase order lure with compromised WordPress credential phishing payload
'1cd319937d59bfa6aa933172e8f0b63fdb82645372e524c4424cc4b1094e1450', // Compromised domain - scope of work and quote BEC lures; second mailbox on domain already observed in myGov credential phishing
'1dc7009cf08e4a9891c9e9fa26201263f29826ea71bfd629400ec376a58fda00', // Compromised account - fake financial planning report credential phishing campaigns
'1ed0614fc9117f62d629d47f93bf2bb7ab0ca5371557818eb8a983f41b2f0f9c', // Compromised account - Zoom meeting and e-signature credential phishing with link shortener redirect
'1fc806377e831e2a995bcd156644adbe2807db9c2b6c1a8c1fd0df9cb206e101', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'204eba38fc8bee6f69aec26501c467259dc7edf2bf0bab8f90ca9d73e382c38b', // Observed malicious sender - advance-fee investment and project financing fraud campaigns
'204f687ffc062cec92de70d4ff5e75d78dc017271ceb6e2c02e26f43fe999822', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
'227595e0898844a4836cd4d986b822f8c30c3b6aa6c46fc5dd83e593e15d2ac1', // Compromised account - high-volume document review lures with randomized reference IDs and Adobe-branded QR code PDF attachments
'239438cad30f816998539c67804547c18737a486989ce5da2e8e85a28f903f04', // Attacker typosquat domain impersonating STALAM S.p.A. - request for quotation BEC targeting industrial equipment suppliers
'244e5cf2fff832b4cb24714ad7113bd475d3e0347f1abf97756e825ba0154154', // Compromised account - collaboration and proposal review BEC pretexting under a fabricated sender identity inconsistent with the sending domain
'245e37a1bf65bb14a41e88c064f2bb0da3416c3fce1571df00095d885b848c8b', // Compromised education account - fake photo share spam with image attachments and a URL shortener redirect
'25e051ba53581c25f8ce6281b74e56e027c421e090c2d4fa6c16db9da9cf0919', // Compromised account - DocuSign branded document portal credential phishing with recipient address in URL fragment
'2608a6edfde80841aef1493fa0a515bfee920a971bacf4adf40f6a4e0fe575c7', // Attacker-controlled domain - Purchase order phishing from a recently registered domain
'26b456acbf4b9e71ab3f94c9c535aa7d280d99b00933dd152be5b7962639e224', // Compromised account - domain renewal payment phishing campaigns
'2948295e37b555a1b3fd2318a0f4672eeb69a0dfc67283d8f6db19664729f089', // Observed malicious sender - blank subject campaign with unrendered mail merge tags redirecting to an attacker-controlled host
'2a9b9e226f23ec6375ea7fbc73d2dfe2bfe4d0e09a8ed002226ad2c54659ba50', // Observed malicious sender - Chinese-language enterprise mailbox credential phishing campaigns
'2c61e0a0f6d48553de52c70d5c84242ee8b550016aa6fdb36abd9c8d7daf624c', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
'2d08678c9e7efa286265cc1f3786c86f01c9910fad67f98dc9d36dc312808f6e', // Compromised marketing automation account - Adobe branded secure document credential phishing
'2f8d025a9102603953c1a16e888bed90edc72e9eb34b0a8ef05de2e666ec4292', // Compromised account - ICS calendar invite fake document share
'2fe6784be1bc4926bf3bc0e3df70ffeb0c21008f74b685c05657989c0ae481d5', // Attacker-controlled Amazon SES infrastructure - mail delivery report quarantine release credential phishing with recipient domain in body
'3104c37963b8bcbeddbf158f6607384109dc6a9ec24f4610468690fb66f00cf3', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'35023d982780f5605437e9983a3a7e16246440087687647967df0e7ac899f306', // Attacker-controlled domain - account update credential phishing via self-hosted link tracker with freemail reply contact
'396651544737fd8be74a6eca3624e1cbdc8f6380e700f7d3482287f9ec3eebf2', // Attacker-controlled throwaway account - Meta business page verification credential phishing with Unicode-obfuscated subject and display name and numbered Netlify payload subdomains
'3a11180346d6de0d66d38dfe9482b0fd998183d30f10d02940d1caf458457d16', // Compromised account - Polish school domain used in BEC campaigns
'3bc454b83d39fb07a9c9de41111f58acd2f301f7f7b8357d91eca16056a56a44', // Compromised account - advance-fee investment inquiry BEC lures with a typosquat reply contact domain impersonating Nera Capital
'3bec8e1bc42caa470c611cc5d481a2e0da08c240813a7427b9390f765a4304cc', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
'3cf5c3a0b8481997224e3397bc52c754d52558e9a3c3ee1faf02c5e58ecc58c9', // Compromised account - ICS calendar invite ACH payment verification lure
'3d36ba171280784accd5b7bc6f0571664f87ec6954e1c4ac92f1833d67313f44', // Compromised account - EML attachment with a QR code compensation review credential phishing lure
'3d3f43292b599f983be6822151540437c86fce4dcf9f05e7dad94f3cfd7aff31', // Compromised account - purchase inquiry BEC campaigns with typosquat reply-to domain
'3f9e2c465ed00925b6904065f599c2a605ee8f15f9fac73626754d28839e370a', // Compromised SendGrid account - credential phishing with randomized document review subjects
'3fa83cd162a4f95f91d8cd28016dd8b1e557ee3a96e98ec0110ce7f22e387a24', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
'3fda2f6d720a5a519de4486bb82f0fe089a7f03dc283edcf3d0a1bfc7b12eaed', // Compromised education account - callback phishing fake invoice lure blind copied to Microsoft 365 group addresses, matching an active multi-sender campaign template
'40742af9c50cbbdd54fda2fedaf88429d78e34f6df5cc0b34fe7851b354472cb', // Attacker registered domain - fake billing review credential phishing
'41510787bec9cf8433d8a725e9cf8026a27c420e9e2ed20d4fb0218b95813e6d', // Compromised account - advance fee fraud workers compensation fund and inheritance lures with a freemail reply contact pivot
'416423ad3b195a68f1f8cea67899e4eaf97428c128e2ae30c3fa607f8951c0d6', // Compromised account - Vietnamese university domain used in BEC campaigns
'4644ba88c2f2fce73f570e2cf5e8d0c6de0d4d8e50bbe62bd14f6364c5748981', // Compromised account - high-volume multi-template credential phishing via Google Workspace SMTP relay, landing pages on compromised sites reached through google.com/url open redirects and reputable click-trackers
'48736e8d6c36f5232121bc9d9f0a148a09430a3b718695ca296abcb067530284', // Compromised account - Austrian school domain used in BEC campaigns
'498030e0191b3c9b464b6c92e852a99e6ccd7989d95afd60c7124f45daec7ffd', // Compromised account - quotation request lure BEC campaigns with mismatched display name
'4992b89b6a829fb3b2df195a325c6c73c4c0706f87ca663e7b92d14700bd4533', // Compromised account - rotating display names in targeted payroll and treasury document credential phishing
'4bd8d89c85ab0a7ebe69f6a9136f5eea8506e4bc5c8a09108db6bf48e5d8ee97', // Attacker-controlled domain - ICS calendar invite with Google share.google redirect
'4c254e837ad5e81e0d5316f4a12030b6112577955af3ab7900481835f555bd7f', // Observed malicious sender - advance-fee investment fraud campaigns
'4c4801bea710a8a5653b1396d139cc4fbf731791dbbf3f21305f2b651cd62d29', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
'4df47bebfb4e8c9f8b486fad6e3045ce529835572cedfcd6890bad30cebfa8d9', // Attacker-controlled domain - N26 bank credential phishing targeting German speakers
'4e6e32b31f295cc2fdd1f88bb32c7855ab2e760f21cf834f97abac9e9db68d47', // Compromised account - strategic partnership solicitation BEC with randomized reference IDs
'50956a216c7edbacd20275707a65dadd1a22cf9e5e00001afaf1c24692124f44', // Attacker-controlled domain behind a privacy registrar - request for quotation reply-chain BEC targeting manufacturing recipients
'50a5e066da1a7d65d81b3f233272b208c782688634445aeb3f4ae355a6ae6699', // Newly registered burner domain - executive impersonation requesting mobile number for SMS pivot
'51085bd2a15074f19fd307da1867258dcba93a33ea9a672079a85efd54ed243f', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
'52460bcbe479bdce1c737d0af3f611143a81d5f12c8457b29c900905834bf0e0', // Attacker-controlled domain behind a privacy registrar - fake Microsoft 365 undelivered message quarantine release credential phishing delivered through Amazon SES
'53ed891f2c0fb15fcce73a4e6731f1433874dea7d3ba000af1b7e840ed7e329a', // Compromised consumer ISP account - awaiting feedback reply-chain BEC pretexting with a mismatched reply-to
'548edab40e3bff052d6357c81662ae9d67d1f7fa75bd0491e3e94751fcb1bbcc', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
'5502acdf89fe972ba391e8aa9355919a1c3f920947169bbd23da5c6383e18433', // Attacker-registered lookalike domain - fake Google review removal scam campaigns
'57a8b399739a513c38fa4c2f88162f5890f9149b68c34f23e34c60b0fbeab39a', // Compromised education account - fake photo share spam with rotating display names and low reputation redirect link domains
'598a485295137301401ff1465e9b304a38d6581d7c1e03a3d4de52921bbf38b2', // Lookalike domain impersonating Bapco Energies - export inquiry BEC with mismatched reply-to domain
'5a03383efec90551b7cd2dca400b07dc9c99479d94d904fc0133dac1814a4d91', // Compromised account - ICS calendar invite fake contract lure
'5b4a30d023e44f51a487a586db67267773ed53454f4fb7e14fb9782b3bc7ed4e', // Attacker-registered domain - real estate acquisition BEC lures targeting brokerage agents
'5c04ec6dce7c935c0ef934e88f8757b16aa9b9f400b6433395ea001549bc1f39', // Compromised account - supply enquiry BEC lures with a newly registered reply-to domain
'5d9e7e39076ea435f8576988c43d553a100d4cae977be38be72c523ea3c083d9', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'5dd6751ee719a5b57e2e739450bbe782a9db7c1efb8768f7bc5e1b1bee59f578', // Compromised account - Costco and Paramount billing deactivation phishing with payloads on free dynamic DNS hosts
'6042175ee7fade7184f2fea3c5e9008eaa6ee0b2777d6e1d90987bf66d7d1cb1', // Compromised account - payroll update and banking details BEC campaigns
'6052f572ae56a3ddf1e0c2d9912c80be182312605cbe9d6a4b38041d0811d0a9', // Compromised account - request for quotation BEC with a newly registered lookalike reply-to domain
'607317145cd319c8e765744a3bc9571743ba8c6d8e2d73c56e3eac33e51c0c09', // Observed malicious sender - blank subject campaign with unrendered mail merge tags redirecting through a relay host
'6106f4d9431f6f990a68d8de4bf194e5ef5341ac1ba918697c0635b3f93fc77c', // Attacker-registered domain - fraudulent purchase order BEC impersonating equipment manufacturer procurement with typosquat reply-to
'61fffa77073ca73875d1c738fa8a9628440a07128e50d4b6be57e8a195a4afd5', // Compromised domain - myGov impersonation credential phishing with Australian tax payment lure
'64fa0322c197928c6d991de6c564eb43a03265cebdd60ce3bf200a0c120daec7', // Compromised account - project inquiry and partnership opportunity BEC lures impersonating CBRE
'6551838f7e4a651df49fd405ca80fb5832ec26817339dcf2f1f05f0b0f207359', // Compromised account - part-time spokesperson job scam and product inquiry BEC campaigns
'6784f5d07e939e55fea76d13fa9ac6119ada247536447bb594fb98e4d7ed1717', // Compromised account - mail delivery failure notification credential phishing
'6977556ab6dade2725e77073483b74294ce491013ff2f1f33a1cc30cb15f8bb3', // Compromised consumer ISP account - BEC first contact with single-word subjects
'6a9576645d5e70778b6bde0d16285415a2dea7496c54fcfb4885d274dcaabee7', // Compromised account - request for quotation BEC first contact with newly registered lookalike reply-to domain and fictitious contact number
'6bc270fac6bed884311689fc339a2d5953638d7909359c61348a440de9caf9c1', // Compromised account - purchase order fraud impersonating Manitou Group with typosquat reply-to domain
'6d2c29e0d973404059aa517e8bacbbbef7fb7644486f1fdce6c4924c32e3d9fd', // Compromised account - ICS calendar invite voicemail lure
'6ed87d7442a9c67238272ffda2bc11ab7635fdec57fd58cfb289da585eb7314a', // Compromised hosting provider account - Adobe-themed credential phishing with rotating display names
'6ee212661325038d04e5652c95726f08d55724429bcc28b7a3637dad745acf5c', // Compromised account - NetSuite accounts receivable aging report share impersonation with VIP invoicing request
'6fcd011c929ff7d871d21375e5e9468b49397a566524bc9f57ec022dbe047c04', // Observed malicious sender - advance-fee investment fraud campaigns
'731e54574f28629bfce11244200e89c40b22f24482c6148f883283b45892067e', // Compromised account - project inquiry BEC lures reusing the sender persona from a parallel compromised domain
'75553065a29e3398457e07de37cfba1ed1c87671a7efac9ec50da431e59b1b79', // Compromised domain mailer - Portuguese language security re-registration credential phishing
'77629fbddfba6fbb8423b8f3d9e32891424aa5ba11073b6c8e65f04718970982', // Compromised university account - fake photo share and fake forwarded thread campaigns
'77df91f5bd3c2e212d6a97a37f9096c7066a38ef5df4da445a83a5a8f8f94500', // Compromised account - fake voicemail and remittance notice credential phishing campaigns
'7c117ed39641278555ae674d9e4d469eae35f1321a45934a31f09cddccabd3a7', // Attacker-controlled domain - fake document share via attacker-provisioned Dynamics 365 marketing tenant redirecting to compromised site with recipient email in URL fragment
'7c711457c1affc6bdf1a622a22f81f624e034448548e625117d1091f848ddc7c', // Compromised account - ICS calendar invite document review lure
'7c8569f4156a396673e5509f5c3a4b1aaf30761802631478bd59bec9c2ff0459', // Attacker-registered domain - German language inheritance advance fee fraud campaigns
'7da8a342aa3d2e085f144bdcc9554df29c4419581c86b09e48ca8f602e645ace', // Compromised university account - advance fee fraud congratulations lure with an attacker-controlled reply contact domain
'7e7cb86170d9d8c6c183222448955820f67d9cfdd08b95ebd7e163be6077454a', // Compromised education account - booking confirmation reply lure linking to credential phishing HTML hosted on Amazon S3
'7f82c9f6763c54de2ac9ba07db314f0c99a4828c895aa7a0b139b22206e642c1', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'7f866abd59466f633368c2c658e388794d4a26c8cfc1c4122ea2eef5a87ec0fb', // Compromised account - empty subject reply-chain BEC pretexting with a freemail reply-to pivot
'7f997ff6ee6e189af585d4291b8944fd22cb02358f4294886cc755518efa60aa', // Compromised account - part-time spokesperson job scam and product inquiry BEC campaigns
'81c391208275700266de52f05176151b490fc98ac303c69aade60c4dd7733e6e', // Attacker-controlled domain - numeric-hex reference code reconnaissance
'82f54cefc0ea8ea3344762e170acf0511ec0102e845c2b72c0373de521fa36d8', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
'858214f8881d63a66b52ab87585f04465a31875e77755fe489b8e2291fe1c593', // Compromised school account - digital invoice lure with PDF attachment
'87014bc8f121aa71f5319e62375d4574abac28b8c32005a2c85db2b227bc4e06', // Compromised account relay - advance fee fraud, DocuSign contract, email deactivation and billing review credential phishing campaigns with payloads on compromised sites
'875a5fa3440dc3e03efd0ccdc4b3006ffa6ab23eb8f1287dcd27ac6578c5ee41', // Compromised Amazon SES tenant - Toast payroll notification impersonation with credential phishing payload reached via neogrid open redirect and diverted reply-to
'87eb1efe1ab4ff5ef8767c19f6ccd837b2dac092b70092b56e3e59302035ad84', // Observed malicious sender - Norton subscription renewal credential phishing campaigns
'88653d86088efa5cbf02791a9f2480e507abd28c463b288e1220d5cf2a9c19f8', // Compromised account - company proposal lures with Zoho Writer published document payload
'896ce3441bc7c3d3dfee3f8947965492ed7160596b8f09eff9f625412b5a619d', // Attacker-controlled typosquat domain - ICS calendar invite fake document share
'8b6199148560383d2fca031052475ca2627637fdf4a883dd475c9f3a51d39887', // Attacker-registered domain - Kroger Boost membership renewal credential phishing campaigns
'8c4ffc408b379a7649bef8b6fe6dedf467960627897eae7742091d98fc79a263', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
'8c61b30c46de11fd376026587646066325cc31f9749381abe2280b1fc1b58fbc', // Compromised account - invoice notice and ICS calendar invite voicemail credential phishing campaigns
'8d0a6552bc32f3704106dcbdd393c73ceb29a4bbfd7f0ec207ea438c757b608e', // Compromised Vietnamese bank account - advance fee fraud gift and prize campaigns
'8d6d35f92d52490cfd8c2153a979604b95aabb430eef256486600075465e80b8', // Compromised Kenyan school account - thread hijacking with credential phishing link
'8f8ea31184fbfd5633983283a4946d44f74638d521ad3bba9d967f5a128c2ad1', // Compromised education account - fake photo share spam with image attachments and a Google Sites redirect landing page
'90349b130b8bf9d0a06f809c78b3e1926e0b02d4797bee3fd614eec5f9f9c9d8', // Compromised account - proposal review lures with PDF attachment impersonating the owning business
'9059acff3ee9f042e49bafad2fa905051fd0b4817e4434c4a44b463ebf422963', // Abused ESP subdomain - parcel delivery notification phishing redirecting to a compromised WordPress host
'91fe8f768fdef0efacb6325ad65b4d5922789d49dc2b253e7e352367ac8608fc', // Observed malicious sender - advance-fee investment fraud campaigns
'955ae08074c3cf8fff4143461c371ece9690921a27896d18b3c34f6afa65b48f', // Compromised government account - service solicitation BEC campaigns with mismatched display name
'9565c234e0c50c63f3a05123e98e324988744230ef3b14dcabafaa45e162bc25', // Compromised account - payroll and compensation statement lures with credential phishing PDF attachments relayed through SES
'97956c1c9b21e5499a9363040b419b349b91bf5d594cd343303c98f2ff7f59d2', // Compromised account - Brazilian invoice (NFe) lure with HTML payload hosted on Azure blob storage
'98efda257ce741da148c18cdf32a60bb37952c322a9df9d9f996591b0670f52d', // Attacker-registered domain - title order and wire fraud lures spoofing a Chase title team address
'9a431f19cd293db92b46516921b57a145933fb84bcd74b61d030a563acba7080', // Compromised account - company proposal lures with Zoho Writer published document payload
'9ac3bc28005ac615607c878c119118698b368217633d616082bd6b619bca8224', // Compromised university student account - advance fee fraud to undisclosed recipients with freemail reply-to
'9ad52736e4eb32a906e646cb4c16f38c318e44922666f59d1652b85d2a7a7680', // Compromised nonprofit account - ICS calendar invite credential phishing
'9af400fa39126d7ad6a34adbd1bc681fdeec84e9542def79e3e49bd170bfe328', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'9c49f7240d126b9769580d403a5e5cd759edaaa1c32ec92b0a076c2ac96a8235', // Compromised account - sales inquiry BEC with attacker-controlled reply-to domain
'9ce5faf38597804a6513b30ec3929fd4beacb240ed304cd4f07be163afe149df', // Compromised account - German language tyre system invoice lure delivering a compressed archive payload hosted on Dropbox
'9d20cf849102d8c4bfec9c15c2d79fa408502657a4455cacaa2bc725fec078ae', // Compromised account - tool giveaway lure with Google Cloud Storage redirect
'9d5c11b2b6dc2f8c0e7962302796a9862512530b938025c44e114a2a66586902', // Compromised account - company proposal lures with Zoho Writer published document payload
'9fda882aad59efabf9e2c45a9f1490e87deb323de5aedcf80b4bfbbf1c21f8b0', // Compromised account - fake eDocument task and Teams share credential phishing campaigns
'a15404dc1be5940267fbd4fb7f673f4b0715eb0eb19bbfabfc8394f28a96b243', // Compromised account - fake HR policy violation notice harvesting credentials via SendGrid click-tracked link, personalized with recipient name and job title
'a206e5b140de73c7ef373197d929c99a26ec416c7fdeef66ef7b4593a11c9595', // Attacker-controlled throwaway account - executive impersonation BEC reply lures in a shared campaign
'a2bbaa6824197630b7b9fb12296405481f6d2224194559c1ee39a635f8603cfc', // Free-mail persona used in VIP-impersonation invoice/payment BEC with fabricated reply threads
'a3473438fe21318a0e950cf1c01309d84a8fb0bd287276e0dc90e33501d3e233', // Attacker-controlled domain - BuildingConnected impersonation credential phishing with visit tracking
'a4312827c4ed4900fa06d6f3058edc203fe85683b6de585d1fae5becd4700a6b', // Spoofed sender in prize scam campaign - gaming and tool giveaway lures hosted on Google Cloud Storage
'a4f740abf0fa1c0a6c26a9acdff1248e6cd147b392b5806028515ae3da389785', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
'a5e72048f261715f3e7ce6d2cc8916bd2a3e230e5dba3f6bfa3fbf8756ac7381', // Attacker-registered domain - fake family office investment solicitation BEC campaigns
'a7fc25e74dec71054e0d8da967f612612fe926aa2fd29618d1ad4e9316e93988', // Attacker-controlled domain behind a privacy registrar - empty-subject fax transmission log lures using an Xfinity tracking open redirect to an Engagis OpenID credential prompt
'a9f1555662a63f40e3e1260a33ef1f119aec0c79a052d58094732dbe82e56f7b', // Compromised account relaying through an attacker-controlled Google Group - hidden Google Sites credential harvester behind a decoy Acrobat link
'aa679ede4b58f308084c907834ee382b80f6d74aa0161c06ad873a5605e08241', // Compromised consumer ISP account - executive impersonation requesting mobile number for SMS pivot
'ab89b7242f2e0ebf76e8af17516aa8273c9002480e94a10dd29cb94252a2d5e6', // Compromised account - lender branded secure message credential phishing distributed via SendGrid
'add7445fa0b8209b0da2e500b8c50231fc4c0f8c029a38659dd2e5ee58ff85c7', // Compromised account - empty-subject fax transmission log lures using an Xfinity tracking open redirect to an Engagis OpenID credential prompt
'ae42584dfd37653be7e42203ca5b6ad5508a639726ab5cbb65ba58085e54c6b4', // Attacker-controlled typosquat domain - numeric-hex reference code reconnaissance
'b044f948af172622b44fec0affad51861ff32c5f6ba5bcda261293e35a6b5d3b', // Observed malicious sender - advance-fee investment fraud campaigns
'b1636bd79df0c1cecfb3213ffc0f921d23c73435cabcc2ff03c759c14c896170', // Attacker-registered domain - completed document notification credential phishing via marketing automation tracking links
'b1a62e7738fae564eb985703a8b73efa43e50dd6f9d97e32c5ea38332f1496cd', // Compromised account - project and proposal inquiry BEC lures sent without payload links
'b3a315352bd909eee0c773071df508ef0487f0180df22017c6e5e5eb40d77301', // Compromised Japanese company account - parcel delivery credential phishing
'b4751533eefe4d0cc630fd5dce52e043a1ff6617238b2ebe3b7290899bbe241f', // Observed malicious sender - Kroger brand impersonation credential phishing campaigns
'b4a1ad4e015be4e6dac4e9ebedb23615e2db8287afe0198f3a1ecde7ed5722ec', // Compromised account - SF Express shipment notice lures with recipient address in the subject and payload staged on a CDN asset host
'b6878960db617a69fed9fe072dce897e8f76c2bf9cf2f93171e442f74ccc8f25', // Compromised account - repeated BEC first contact with single-character subject
'b7415f1380d0a89b124bce7de8b1eee96dc452f9c95252192176cd427020b060', // Observed malicious sender - contract agreement BEC campaigns using freemail reply-to mismatch
'b77161f16370afbd32afd8e613be5ffb1a9d9e99e1b8d3e547cf6379ab55c6ca', // Observed malicious sender - spoofed sender in fake forwarded thread membership invoice fraud campaigns
'bb87499a229e0f70ebd20d8d3be83d426c898c01ee3a4b8706abc5d78d9146df', // Compromised account - ICS calendar invite credential phishing
'bb8e9bf6bd2e4c3749b5b778222c6c52097de3a98f0a56ea358b6e31081d2b17', // Compromised Amazon SES tenant - credential phishing sent from click-tracking subdomain with decoy Alignable and Intuit links
'bd39e620e9fd143d50ee834ba38bff60d80bf4dc36681c5d3e02757dedecfdcf', // Compromised account - product pricing and event space inquiry BEC lures
'be44430a667b7776e351cf54a66f85716de0731dcb1245b7c5bca081e4cd80a5', // Observed malicious sender
'be6f44a266193db11f641f64f34eb011a636fde8696dc95f82d4d3c3090a1b75', // Compromised account - mail delivery failure notification credential phishing
'be75194b73d1bb258beb4ab257211d4ba6be240a485d60b2f4346b4d3171d5e4', // Attacker-controlled domain registered days before use - BEC first contact with an alphanumeric reference code subject
'beca37c439dbac64c07a144e36c1c057cb9b2a0d105b464f88e0a023298599cf', // Compromised account - brand impersonation with reply pivot to a lookalike domain
'bf5d4be8d2cee2476e9a226bd955f41819e4b01976f9bbd91b58bc82f057d4f6', // Observed malicious sender
'c178b0a38ad2fdbdb40b7851d0fa4ed962b1252b1b7e7d6c04c4f2d6260f560f', // Compromised government account - Microsoft 365 subscription expiry credential phishing
'c35764206e9ae5372498a5c7562e52632a0ddadecd1973d71b9d448624ae3b16', // Compromised account - urgent notification lure via cloud-protect.net redirect
'c36ea820ad081f649f670a3d98b079c6897554749fe85af4afc11f6a5badd2d7', // Compromised government mailbox - price inquiry and project proposal reply-chain BEC pretexting with no sender signature
'c5dfb0030991c22aad632fb5d57e7eac57f6379ff3165fcf5d170a6d730c4538', // Compromised account - ICS calendar invite fake document share
'c75f2d07928e315171113031a6a1a54bed3a6a6cd53b293a8e9015222de1fb32', // Compromised account - supplier purchase inquiry fraud with typosquat reply-to domain
'caed0ffc5a2f2858ef33956eeaf3f1309467e352506dbc200bed299a3ce71420', // Observed malicious sender - advance-fee investment fraud campaigns
'cafb217669aba8cea858f44e7c4672644015a9d76e4c8de4a53fcc98e3f66881', // Compromised account - company proposal lures with Zoho Writer published document payload
'cbb683f2108bf5c91e5da136b20d94e299bd8a027311afd10f17575f0a166f19', // Attacker-controlled domain - homoglyph brand impersonation with open redirect chain
'cc154336dc3d3f9af8226bb0e5fe764a822d5d8063601d0572ae0368395c71c2', // Compromised account - Cyrillic homoglyph voicemail notification credential phishing with a punycode obfuscated redirect chain
'ccbb818f79e89f26de61674b90618330fcaca8d6630fc44b3c51a161ed06bdfb', // Compromised account - quote request vendor fraud BEC lures with a TLD swap typosquat reply-to domain targeting construction county government and healthcare recipients
'cd020f36af6c65e3953816094eee6b2e57f888d01cf00de9017ff4d3c63f8e07', // Attacker-controlled domain - Advance-fee investment solicitation using a forged reply chain
'ce3ba673d30f2a4aa04809e8e709c1ec04e21b2d3474e5c57b61653c2646b9be', // Compromised account - fake document share and edit invitation credential phishing with HTML whitespace stuffing
'd0c976c4f72edb8094a4258e4c1bbb3b21ba17c30e0e95f7e32e5e8457c43335', // Observed malicious sender - Robinhood and Interactive Brokers lookalike domain credential phishing via account security alerts
'd16ec6c5e981e96ac5d3de0089ed6419eef9ad23a712fe3fd9e8bec97e62b063', // Compromised account - Banco do Brasil pending procedure notification credential phishing
'd42970a5e7e999074b5f3055823dcb66840d3a8787fb38958a7e1d650eb093c8', // Compromised university account - advance fee fraud first contact lure with an external consultancy reply contact pivot
'd8aab2b15d8bbfd7e2fac6310ad0369eec56540cd67ed90313045cacda7f3c80', // Compromised account - mail delivery failure notification credential phishing
'd931f0c6ddded184ac8e0a6dcdb356fc0d4f64fe2c852f587db149d942c2e5e3', // Compromised account - Dropbox Paper credential phishing to undisclosed recipients
'da53b2817a57c3914b74d12c9bfd9a88299a52b595401bc495c3ac85cfbb5521', // Compromised education account - callback phishing fake invoice and order confirmation lures blind copied to Microsoft 365 group addresses
'db92038c5432edd7ce1df22ae4ffc173eff2ab6f6dc9f77e435b6437d6a788db', // Observed malicious sender - advance-fee project funding fraud from newly registered domain
'dc01b1e4b74adb29a9e2ff4f29a34076f61c87cf04f620cef525d5070818687c', // Observed malicious sender - advance-fee investment fraud campaigns
'dcf926c300e21c985ff97951bb747662f4d89b68ebd2ec2346792ea69534cafc', // Attacker-registered domain - realtor-targeted program eligibility confirmation lures
'de7deda77de750c100c517564cbf2ffbec72001d31203ed7eb5c45635945ea5f', // Attacker-controlled Amazon SES infrastructure - mail delivery report quarantine release credential phishing with per-recipient display name spoofing
'dff78965cc2c55b284990806f57a9ac6c4da7e50271a5a1473fb7b6bd557ff4e', // Attacker-registered domain - purchase order and RFQ review BEC lures behind an unscannable Cloudflare link
'e06aa193933815324af2fee9d3c250dab080a681b9658253ce2b0af0466cbbd1', // Observed malicious sender - advance-fee investment fraud campaigns
'e0b7349e426e4ad21dc9512fdd04e821c66f92a00fa81a79536f2ef36adbc562', // Compromised government account - technical support lure with Constant Contact landing page
'e0da1bd70a04552d8104ae6d11b2eeb477b6dc8ecbd257d5dcde3bec0127044e', // Observed malicious sender - bid solicitation and RFQ vendor impersonation campaigns using typosquatted reply-to domain
'e2ac59798b67d702ccb16fb33a126c17fa5b437d43eedce5e5574d9961609085', // Compromised government mailbox - null subject BEC pretexting under a fabricated display name with a freemail reply-to pivot
'e39218d8dd92ed4eabe4417733d40cfafe7de1fcce268bef9f33f624c9a90152', // Compromised account - recruiter corporate bill invoice fraud with generated PDF attachments
'e496f21a9a64bb06d1c3c9f3ce6df5a4fec04e513e51c9d05d6637e48036e9e8', // Observed malicious sender - advance-fee investment fraud campaigns
'e52716b8b92a14d06f4cd11f94237660a087229eb19ef96e76ee312334ba2210', // Compromised account - fake email quarantine and pending message approval credential phishing with compromised WordPress payload
'e58acee1778ebb1f0a3fd8aecaf8707976b7cf6edd44dddcc8638a772864084d', // Compromised account - QuickBooks payment confirmation impersonation with typosquat payload reached via open redirect
'e829d4a1070b56abae6b5c0e81f76dc41feacd256c9e97f719e8478872ca5d55', // Compromised account - invoice fraud with ACH payment urgency and recipient company display name spoofing
'eaef6d29428f22885109b201072d03826b5579b4b84658ab69e637659feabcc6', // Newly registered burner domain - executive impersonation requesting mobile number for SMS pivot
'eaf8cfe2d96cdb4f17819f77aad91fd9555fb82be5124b112a70d252f92219c6', // Compromised Japanese company account - vendor invoice BEC with fabricated internal exec forward in .msg attachment and lookalike vendor domain
'ec3d8dc44fa1143a7b438cf06cfb39d57ab26947f089bb03d723e11a515dddf7', // Compromised consumer account - executive impersonation BEC first contact requesting phone number
'ec9c01b0c4fbe5de2fb5065ab31cfb80304179a889a513f8bae112cc5d544331', // Compromised account - remittance notification document share credential phishing campaigns
'eceeea014ecc4f86431c8e49e16d74fcb1bdb2003f05a0e4166da37512f11847', // Compromised consumer ISP account - BEC first contact probe with display name impersonating a vendor executive
'eda233116ef0046c1ab0b64ce9e8654b808efafb0cb602de669a0722cc012de7', // Compromised account - per-recipient templated RFP solicitation BEC
'ee4873fd02b2832cc47f937d09368e26b08589967552c22551efc3d45856384d', // Attacker-controlled throwaway account - Meta business page verification credential phishing with Unicode-obfuscated subject and display name and numbered Netlify payload subdomains
'ef25dfa33c53628cf72f4902874212da1bd60bf38224a1781a059ccd168ad664', // Compromised student account - BEC first contact with mismatched reply-to
'f206926f3b476970e4132e3d9dd32170a5e991d5fba5883389f1d4a18c39aa40', // Attacker-controlled domain - request for quotation lure with excessive URL rewrite encoder chain
'f2231cb4a71ce384c1dd949af538dd25761776366a0f0b76ed4c889aa6488c4d', // Compromised SendGrid subdomain - fake eDocx pending task credential phishing
'f23450c74fbd8e5379835a6961f3cb92f0222573f6839469384717b4f1ed46f2', // Attacker-controlled lookalike domain - procurement sourcing BEC lures impersonating an unrelated metals supplier
'f33c82ad311018d7a88bf14b94be5cfa42afdbe529edc8086b0c11e1159648df', // Privacy mail burner account - executive impersonation requesting mobile number for SMS pivot
'f5ee438bbfbde02b493f726c06351325bfc31085e3056aaba768db9211893bc0', // Compromised account - fake webmail password security notice with recipient email in URL fragment
'f7134c981f996cacd56e1e541ba5179cd35292078496e981aec26fea016a3e14', // Compromised account - USAA claim adjuster impersonation with PDF attachment
'f88ea669b8f785c1afc0c04e15b412a1e7199c542b69fae9fc83a3260b9181f2', // Attacker-controlled domain behind a privacy registrar - fake EE rewards points expiry credential phishing delivered through SendGrid
'f92b12adb9911b249d6b774bbea0fe7e2481192e2ed99583c8a391be59802e1a', // Compromised marketing automation account - Adobe branded secure document credential phishing
'fa85690cd62ab68ed9168a43567f2868fa120aa73565a082a87443877d0c25e6', // Attacker-controlled domain - multi-lure credential phishing and BEC with homoglyph brand and university display name spoofing
'fcf380341ec080be2082bbf4c3a21fcd5dc2d79f5b50d7bc868c83f96ca6631d', // Attacker-registered domain - executive impersonation BEC reply lures
'fde63093f069fd00d5d5b0a8aff58e2e55646f0de7dadcd5b78c0511c16bf6cd' // Compromised account - credential phishing with recipient address in subject line and URL fragment
)
Playground
Test against your own EMLs or sample data.