Tactic or Technique: Spoofing

Spoofing is when attackers falsify sender information to make a message look like it came from someone you trust by forging a real email address.
Messages like this often impersonate executives, IT support, or vendors and can lead to stolen credentials, wire fraud, or malware infections. When the source looks trustworthy, you're more likely to follow instructions, click a link, or open a file without hesitation.
Spoofing is especially effective when email authentication protocols like SPF, DKIM, and DMARC aren’t properly enforced. Without those protections, it becomes much easier for attackers to get past both technical filters and human judgment.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Service abuse: Google callback scam
4h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: ConstructConnect
5h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: Google Authenticator
4d ago
Oct 2nd, 2026
Sublime Security
Attachment: ICS invite meeting lure
8d ago
Sep 28th, 2026
Sublime Security
Body: Embedded email headers indicative of thread hijacking/abuse
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Navan
13d ago
Sep 23rd, 2026
Sublime Security
Extortion / sextortion (untrusted sender)
13d ago
Sep 23rd, 2026
Sublime Security
VIP local_part impersonation from unsolicited sender
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: State Farm
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
14d ago
Sep 22nd, 2026
Sublime Security
Brand impersonation: Sedgwick Claims
18d ago
Sep 18th, 2026
Sublime Security
Brand impersonation: MyChart
19d ago
Sep 17th, 2026
Sublime Security
Sender: Suspicious CC suffix in sender display name
20d ago
Sep 16th, 2026
Sublime Security
BEC/Fraud: Contract or order lure with mismatched reply-to
20d ago
Sep 16th, 2026
Sublime Security
Link: Delimited encoded path parameters (~V~ scheme)
1mo ago
Aug 31st, 2026
Sublime Security
Service abuse: Kagoya.net-hosted domains sending English business lures
1mo ago
Aug 27th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
1mo ago
Aug 25th, 2026
Sublime Security
Service abuse: Facebook mail notification callback scam
1mo ago
Aug 25th, 2026
Sublime Security