Attack Type: Credential Phishing

Credential phishing attacks are designed to steal your login information by tricking you into entering it on fake login pages. These emails impersonate trusted services like Microsoft 365, Google Workspace, or banking sites, using urgent phrases like “verify your account,” “prevent suspension,” or “view shared document” to push you into clicking.
Once you click the link, it leads to a fake login page that looks convincing. If you enter your credentials, the attacker captures them immediately. Common examples include phishing emails pretending to be DocuSign requests, Dropbox links, or HR file shares—things that feel routine but create a false sense of urgency.
Attackers often use real platforms like Microsoft Forms, Google Forms, or compromised websites to host these fake login pages, making the links appear legitimate and harder for security tools to catch. The damage doesn’t stop at just stealing your login. Once attackers gain access, they can move through your organization, steal sensitive data, send internal phishing emails, or even launch a ransomware attack.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Impersonation: SAM/SBA federal registration
21m ago
Aug 27th, 2026
Sublime Security
Brand impersonation: Robinhood
21m ago
Aug 27th, 2026
Sublime Security
Attachment: ICS invite meeting lure
1h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: McAfee
2h ago
Aug 27th, 2026
Sublime Security
Link: Microsoft protected message with suspicious recipient patterns
2h ago
Aug 27th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
2h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
4h ago
Aug 27th, 2026
Sublime Security
Body: CSS clamp() font obfuscation with suspicious URL
20h ago
Aug 26th, 2026
Sublime Security
Attachment: PDF Grant Payment lure with embedded link
21h ago
Aug 26th, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
1d ago
Aug 26th, 2026
Sublime Security
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
Link: Self-sender with sender org in subject and credential theft indicator
2d ago
Aug 25th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Automobile assistance associations
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Sedgwick Claims
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: UPS
2d ago
Aug 25th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: AARP
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
2d ago
Aug 25th, 2026
Sublime Security
Link: Google Cloud Storage link with redirect.html in URL
3d ago
Aug 24th, 2026
Sublime Security