Tactic or Technique: Free email provider

Attackers often use free email services like Gmail, Hotmail, and Yahoo to send phishing messages that are harder to detect. These platforms are widely trusted and have high deliverability, which makes it easier for malicious emails to land in your inbox.
It only takes a few minutes for an attacker to create a throwaway account. From there, they can spoof a display name to look like a coworker, vendor, or partner. Since free email addresses are often used in real conversations, the message may not seem out of place.
This tactic works because it blends in. A message might look clean, use a familiar name, and avoid anything that would trigger a filter. If you’re not paying close attention, it’s easy to miss the signs and respond without realizing the sender isn’t who they claim to be.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Credential phishing: Engaging language and other indicators (untrusted sender)
5d ago
Oct 1st, 2026
Sublime Security
Credential phishing language and suspicious indicators (unknown sender)
7d ago
Sep 29th, 2026
Sublime Security
ClickFunnels link infrastructure abuse
7d ago
Sep 29th, 2026
Sublime Security
Callback phishing via e-signature service
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via image file
8d ago
Sep 28th, 2026
@vector_sec
Callback phishing solicitation in message body
8d ago
Sep 28th, 2026
Sublime Security
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Personalized fake order/invoice file naming pattern
8d ago
Sep 28th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
8d ago
Sep 28th, 2026
Sublime Security
Employee impersonation: Payroll fraud
8d ago
Sep 28th, 2026
Sublime Security
Mass campaign: Cross Site Scripting (XSS) attempt
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
8d ago
Sep 28th, 2026
Sublime Security
Suspicious request for financial information
13d ago
Sep 23rd, 2026
Sublime Security
BEC/Fraud: Penpal scam
13d ago
Sep 23rd, 2026
Sublime Security
Constant Contact link infrastructure abuse
13d ago
Sep 23rd, 2026
Sublime Security
COVID-19 themed fraud with sender and reply-to mismatch or compensation award
13d ago
Sep 23rd, 2026
Sublime Security
Honorific greeting BEC attempt with sender and reply-to mismatch
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: KnowBe4
13d ago
Sep 23rd, 2026
Sublime Security
Callback phishing via Google Group abuse
13d ago
Sep 23rd, 2026
Sublime Security