Tactic or Technique: Impersonation: Brand

Brand impersonation is a phishing technique where attackers copy the look and feel of trusted companies to make their emails seem legitimate. They recreate logos, colors, templates, and writing styles to mimic well-known brands like Microsoft, Amazon, or PayPal and convince you to trust the message.
They often use lookalike domains to make the links seem real. That could be a small typo, a character swap, or a URL like secure-microsoft[.]com that looks legitimate at first glance. These tricks are meant to get past your defenses and make you more likely to click or respond.
The goal is usually to steal your credentials or convince you to take some kind of action. But over time, these attacks also make it harder to trust what you see in your inbox. Spotting them means looking closely—at the sender address, the way the message is written, and where the links actually go. The differences are subtle, but once you know what to look for, they stand out.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Adobe (QR code)
2d ago
Apr 20th, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
2d ago
Apr 20th, 2026
Sublime Security
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
5d ago
Apr 17th, 2026
Sublime Security
Brand impersonation: DocuSign
5d ago
Apr 17th, 2026
Sublime Security
Brand impersonation: Wells Fargo
7d ago
Apr 15th, 2026
Sublime Security
Service abuse: Meetup.com redirect with brand impersonation
7d ago
Apr 15th, 2026
Sublime Security
Attachment: PDF With SAI Global ISO9001 Logo
7d ago
Apr 15th, 2026
Sublime Security
Brand impersonation: Amazon with suspicious attachment
8d ago
Apr 14th, 2026
Sublime Security
Brand impersonation: USPS
9d ago
Apr 13th, 2026
Sublime Security
Callback phishing via Microsoft comment
9d ago
Apr 13th, 2026
Sublime Security
Brand impersonation: McAfee
13d ago
Apr 9th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
13d ago
Apr 9th, 2026
Sublime Security
Callback phishing via Apple ID display name abuse
14d ago
Apr 8th, 2026
Sublime Security
Body: PayApp transaction reference pattern
15d ago
Apr 7th, 2026
Sublime Security
Brand impersonation: Zoom via lookalike domain
15d ago
Apr 7th, 2026
Sublime Security
Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
16d ago
Apr 6th, 2026
Sublime Security
Brand impersonation: Toronto-Dominion Bank
19d ago
Apr 3rd, 2026
Sublime Security
Impersonation: Social Security Administration (SSA)
21d ago
Apr 1st, 2026
Sublime Security
Brand impersonation: Zoom with deceptive link display
21d ago
Apr 1st, 2026
Sublime Security
Brand impersonation: Bank of America
22d ago
Mar 31st, 2026
Sublime Security