Attack Type: Credential Phishing

Credential phishing attacks are designed to steal your login information by tricking you into entering it on fake login pages. These emails impersonate trusted services like Microsoft 365, Google Workspace, or banking sites, using urgent phrases like “verify your account,” “prevent suspension,” or “view shared document” to push you into clicking.
Once you click the link, it leads to a fake login page that looks convincing. If you enter your credentials, the attacker captures them immediately. Common examples include phishing emails pretending to be DocuSign requests, Dropbox links, or HR file shares—things that feel routine but create a false sense of urgency.
Attackers often use real platforms like Microsoft Forms, Google Forms, or compromised websites to host these fake login pages, making the links appear legitimate and harder for security tools to catch. The damage doesn’t stop at just stealing your login. Once attackers gain access, they can move through your organization, steal sensitive data, send internal phishing emails, or even launch a ransomware attack.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS voicemail lure with suspicious link
1h ago
Sep 16th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
2h ago
Sep 16th, 2026
Sublime Security
Suspicious message with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Suspicious attachment with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Brand impersonation: Social Security Administration
6h ago
Sep 16th, 2026
Sublime Security
Link: Possible Intuit link abuse
22h ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Wix
1d ago
Sep 15th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
1d ago
Sep 15th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
Link: Abused Trac-link URL
2d ago
Sep 14th, 2026
Sublime Security
Attachment: Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Attachment: ICS calendar invite with Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Sep 14th, 2026
Sublime Security
Link: Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
2d ago
Sep 14th, 2026
Sublime Security
Brand impersonation: Netflix
5d ago
Sep 11th, 2026
min0k
Brand impersonation: Survey request with credential theft indicators
5d ago
Sep 11th, 2026
Sublime Security
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
5d ago
Sep 11th, 2026
Sublime Security