Tactic or Technique: Spoofing

Spoofing is when attackers falsify sender information to make a message look like it came from someone you trust by forging a real email address.
Messages like this often impersonate executives, IT support, or vendors and can lead to stolen credentials, wire fraud, or malware infections. When the source looks trustworthy, you're more likely to follow instructions, click a link, or open a file without hesitation.
Spoofing is especially effective when email authentication protocols like SPF, DKIM, and DMARC aren’t properly enforced. Without those protections, it becomes much easier for attackers to get past both technical filters and human judgment.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Extortion / sextortion in attachment from untrusted sender
22h ago
Aug 6th, 2026
Sublime Security
BEC: Tax document request
23h ago
Aug 6th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
VIP local_part impersonation from unsolicited sender
9d ago
Jul 29th, 2026
Sublime Security
Brand impersonation: Anthropic/Claude with newly registered domain
14d ago
Jul 24th, 2026
Sublime Security
Service abuse: Zohodesk reply-to mismatch with job scam indicators
16d ago
Jul 22nd, 2026
Sublime Security
Brand impersonation: Bids & Tenders
17d ago
Jul 21st, 2026
Sublime Security
Link: Suspicious wp-admin path from mismatched sender domain
21d ago
Jul 17th, 2026
Sublime Security
Link: Invalid reply-to with recipient details in subject, body, and encoded link
22d ago
Jul 16th, 2026
Sublime Security
VIP impersonation: Fake thread with VIPs missing email metadata
25d ago
Jul 13th, 2026
Sublime Security
Impersonation: Employee name in subject with suspicious sender
28d ago
Jul 10th, 2026
Sublime Security
Service abuse: Facebook mail notification callback scam
29d ago
Jul 9th, 2026
Sublime Security
VIP impersonation: VIP name within a delimited subject with fake previous threads
30d ago
Jul 8th, 2026
Sublime Security
VIP impersonation: Fabricated thread history with fake VIP recipients
30d ago
Jul 8th, 2026
Sublime Security
BEC: Financial fraud from newly registered sender domain
1mo ago
Jun 25th, 2026
Sublime Security
Body: Fake secure email portal with HTML obfuscation
1mo ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
1mo ago
Jun 17th, 2026
Sublime Security
Service abuse: PayPal manager account creation with callback scam indicators
2mo ago
Jun 2nd, 2026
Sublime Security
Brand impersonation: DocuSign
2mo ago
Jun 1st, 2026
Sublime Security
Headers: X-Source-Auth mismatch with mismatched reply-to domain
2mo ago
May 21st, 2026
Sublime Security