Tactic or Technique: Free email provider

Attackers often use free email services like Gmail, Hotmail, and Yahoo to send phishing messages that are harder to detect. These platforms are widely trusted and have high deliverability, which makes it easier for malicious emails to land in your inbox.
It only takes a few minutes for an attacker to create a throwaway account. From there, they can spoof a display name to look like a coworker, vendor, or partner. Since free email addresses are often used in real conversations, the message may not seem out of place.
This tactic works because it blends in. A message might look clean, use a familiar name, and avoid anything that would trigger a filter. If you’re not paying close attention, it’s easy to miss the signs and respond without realizing the sender isn’t who they claim to be.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Romance scam
23h ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/becfraud-romance-scam-0243cdaa
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
8d ago
Jan 15th, 2026
Sublime Security
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-suspicious-sender-or-recipient-pattern-2ac0d329
Attachment: Callback phishing solicitation via image file
11d ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Callback phishing via e-signature service
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Callback phishing: Social Security Administration fraud
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-social-security-administration-fraud-a9049d52
Callback phishing via Zoho service abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoho-service-abuse-61e351ec
Message traversed multiple onmicrosoft.com tenants
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Domain impersonation: Freemail reply-to local lookalike with financial request
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/domain-impersonation-freemail-reply-to-local-lookalike-with-financial-request-43026a40
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/fake-message-thread-untrusted-sender-with-a-mismatched-freemail-reply-to-address-ca64e819
Brand impersonation: Norton
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-norton-32bd9efd
Link: Apple App Store malicious ad manager themed apps from free email provider
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-apple-app-store-malicious-ad-manager-themed-apps-from-free-email-provider-9ce402c6
Credential phishing: Engaging language and other indicators (untrusted sender)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-engaging-language-and-other-indicators-untrusted-sender-c2bc8ca2
Link: Invoice or receipt from freemail sender with customer service number
11d ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/link-invoice-or-receipt-from-freemail-sender-with-customer-service-number-3825232d
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/spam-default-microsoft-exchange-online-sender-domain-onmicrosoftcom-3f2a64ce
Spam: URL shortener with short body content and emojis
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/spam-url-shortener-with-short-body-content-and-emojis-b7797e4c
Callback phishing via Intuit service abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-intuit-service-abuse-f2fe1294
ClickFunnels link infrastructure abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Reconnaissance: Email address harvesting attempt
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/reconnaissance-email-address-harvesting-attempt-bb31efbc
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
Google services using g.co shortlinks
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/google-services-using-gco-shortlinks-09ff8a73