Tactic or Technique: Impersonation: Brand

Brand impersonation is a phishing technique where attackers copy the look and feel of trusted companies to make their emails seem legitimate. They recreate logos, colors, templates, and writing styles to mimic well-known brands like Microsoft, Amazon, or PayPal and convince you to trust the message.
They often use lookalike domains to make the links seem real. That could be a small typo, a character swap, or a URL like secure-microsoft[.]com that looks legitimate at first glance. These tricks are meant to get past your defenses and make you more likely to click or respond.
The goal is usually to steal your credentials or convince you to take some kind of action. But over time, these attacks also make it harder to trust what you see in your inbox. Spotting them means looking closely—at the sender address, the way the message is written, and where the links actually go. The differences are subtle, but once you know what to look for, they stand out.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Body: PayApp transaction reference pattern
3d ago
Mar 27th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
4d ago
Mar 26th, 2026
Sublime Security
Callback phishing via Microsoft comment
4d ago
Mar 26th, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Mar 26th, 2026
Sublime Security
Brand impersonation: USPS
5d ago
Mar 25th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
7d ago
Mar 23rd, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
7d ago
Mar 23rd, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
10d ago
Mar 20th, 2026
Sublime Security
Brand Impersonation: Procore
10d ago
Mar 20th, 2026
Sublime Security
Brand impersonation: DocSend
12d ago
Mar 18th, 2026
Sublime Security
Brand impersonation: Wix
14d ago
Mar 16th, 2026
Sublime Security
Brand impersonation: FedEx
14d ago
Mar 16th, 2026
Sublime Security
Link: Microsoft device code authentication with suspicious indicators
18d ago
Mar 12th, 2026
Sublime Security
Brand impersonation: Booking.com
18d ago
Mar 12th, 2026
Sublime Security
Brand impersonation: SendGrid
18d ago
Mar 12th, 2026
Sublime Security
Brand impersonation: McAfee
19d ago
Mar 11th, 2026
Sublime Security
Brand impersonation: GitHub with callback scam indicators
19d ago
Mar 11th, 2026
Sublime Security
Impersonation: Legal firm with copyright infringement notice
20d ago
Mar 10th, 2026
Sublime Security
Service abuse: File sharing impersonation with external SharePoint links
21d ago
Mar 9th, 2026
Sublime Security
Credential phishing: Blue button styled link with file-sharing template artifacts
21d ago
Mar 9th, 2026
Sublime Security