Tactic or Technique: Free email provider

Attackers often use free email services like Gmail, Hotmail, and Yahoo to send phishing messages that are harder to detect. These platforms are widely trusted and have high deliverability, which makes it easier for malicious emails to land in your inbox.
It only takes a few minutes for an attacker to create a throwaway account. From there, they can spoof a display name to look like a coworker, vendor, or partner. Since free email addresses are often used in real conversations, the message may not seem out of place.
This tactic works because it blends in. A message might look clean, use a familiar name, and avoid anything that would trigger a filter. If you’re not paying close attention, it’s easy to miss the signs and respond without realizing the sender isn’t who they claim to be.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
VIP Impersonation via Google Group relay with suspicious indicators
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
Spam: Sexually explicit Google group invitation
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/spam-sexually-explicit-google-group-invitation-4e0bec29
ClickFunnels link infrastructure abuse
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Spam: SMTP & Proxy Communications in Email Body
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/spam-smtp-and-proxy-communications-in-email-body-2bdc6a3b
Link: Apple TestFlight from free email provider
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/link-apple-testflight-from-free-email-provider-9b447f1f
Link: Apple App Store malicious ad manager themed apps from free email provider
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/link-apple-app-store-malicious-ad-manager-themed-apps-from-free-email-provider-9ce402c6
Callback phishing solicitation in message body
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-solicitation-in-message-body-10a3a446
Callback phishing via e-signature service
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Constant Contact link infrastructure abuse
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/constant-contact-link-infrastructure-abuse-8c5e8e4c
Scam: Piano giveaway
1mo ago
Oct 8th, 2025
Sublime Security
/feeds/core/detection-rules/scam-piano-giveaway-1a91a203
Suspicious request for financial information
1mo ago
Oct 6th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d
Spam: Sexually explicit Looker Studio report
1mo ago
Oct 2nd, 2025
Sublime Security
/feeds/core/detection-rules/spam-sexually-explicit-looker-studio-report-f1e649cd
Attachment: Callback phishing solicitation via image file
1mo ago
Sep 25th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Link: PDF and financial display text to free file host
1mo ago
Sep 24th, 2025
Sublime Security
/feeds/core/detection-rules/link-pdf-and-financial-display-text-to-free-file-host-b010740b
Brand impersonation: Hulu
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-hulu-6833de58
Credential phishing: Engaging language and other indicators (untrusted sender)
2mo ago
Sep 11th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-engaging-language-and-other-indicators-untrusted-sender-c2bc8ca2
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
2mo ago
Sep 10th, 2025
Sublime Security
/feeds/core/detection-rules/request-for-quote-or-purchase-rfqorrfp-with-suspicious-sender-or-recipient-pattern-2ac0d329
Canva infrastructure abuse
2mo ago
Sep 5th, 2025
Sublime Security
/feeds/core/detection-rules/canva-infrastructure-abuse-b69fdb5c
BEC/Fraud: Student loan callback phishing
2mo ago
Sep 5th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-student-loan-callback-phishing-a71f82c3