Tactic or Technique: Impersonation: Brand

Brand impersonation is a phishing technique where attackers copy the look and feel of trusted companies to make their emails seem legitimate. They recreate logos, colors, templates, and writing styles to mimic well-known brands like Microsoft, Amazon, or PayPal and convince you to trust the message.
They often use lookalike domains to make the links seem real. That could be a small typo, a character swap, or a URL like secure-microsoft[.]com that looks legitimate at first glance. These tricks are meant to get past your defenses and make you more likely to click or respond.
The goal is usually to steal your credentials or convince you to take some kind of action. But over time, these attacks also make it harder to trust what you see in your inbox. Spotting them means looking closely—at the sender address, the way the message is written, and where the links actually go. The differences are subtle, but once you know what to look for, they stand out.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Punchbowl
14h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Amazon
1d ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Microsoft with embedded logo and credential theft language
3d ago
Aug 4th, 2026
Sublime Security
Brand Impersonation: Google (QR Code)
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: Okta
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: SiriusXM
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: Microsoft
4d ago
Aug 3rd, 2026
@amitchell516
Brand impersonation: Sharepoint
4d ago
Aug 3rd, 2026
Sublime Security
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Aug 3rd, 2026
Sublime Security
Service abuse: SendGrid impersonation via Sendgrid from new sender
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: LinkedIn
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Canada Revenue Agency
6d ago
Aug 1st, 2026
Sublime Security
Attachment: EML with Sharepoint link likely unrelated to sender
9d ago
Jul 29th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
9d ago
Jul 29th, 2026
Sublime Security
Brand Impersonation: ShareFile
9d ago
Jul 29th, 2026
Sublime Security
Link: QuickBooks image lure with suspicious link
9d ago
Jul 29th, 2026
Sublime Security
Brand impersonation: Microsoft Planner with suspicious link
10d ago
Jul 28th, 2026
Sublime Security