Attack Type: Credential Phishing

Credential phishing attacks are designed to steal your login information by tricking you into entering it on fake login pages. These emails impersonate trusted services like Microsoft 365, Google Workspace, or banking sites, using urgent phrases like “verify your account,” “prevent suspension,” or “view shared document” to push you into clicking.
Once you click the link, it leads to a fake login page that looks convincing. If you enter your credentials, the attacker captures them immediately. Common examples include phishing emails pretending to be DocuSign requests, Dropbox links, or HR file shares—things that feel routine but create a false sense of urgency.
Attackers often use real platforms like Microsoft Forms, Google Forms, or compromised websites to host these fake login pages, making the links appear legitimate and harder for security tools to catch. The damage doesn’t stop at just stealing your login. Once attackers gain access, they can move through your organization, steal sensitive data, send internal phishing emails, or even launch a ransomware attack.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Open redirect: Quickbase
10m ago
Oct 6th, 2026
Sublime Security
Fake voicemail notification (untrusted sender)
1h ago
Oct 6th, 2026
Sublime Security
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suspicious URL pattern
4h ago
Oct 6th, 2026
Sublime Security
Attachment: PDF Link With Valueless Base64 Query Parameter
4h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: ConstructConnect
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with zipper-interleaved tracking token
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with prefixed base64 dash-record fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suffixed unsubscribe bucket
5h ago
Oct 6th, 2026
Sublime Security
Link: Malformed subdomain ending in hyphen
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Service abuse: Lovable-hosted redirect to external phishing page
6h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
6h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: Amazon
1d ago
Oct 5th, 2026
Sublime Security