{"success":true,"data":{"id":"cloud-storage-overage-lure","label":"Fake cloud-storage overage lure — \"your iCloud / Google Drive / OneDrive / Dropbox is 95% full, upgrade now\" from non-vendor sender, credential-harvest on the upgrade link (2024-2025 Q4 iCloud-heavy consumer campaigns)","description":"Fake \"your iCloud / Google Drive / Microsoft OneDrive / Dropbox / Box / pCloud / Mega / Photos Library is 95% full — upgrade now\" email from a non-vendor sender. High-volume consumer-targeting campaign documented continuously through 2024-2025 in Abnormal Security, Proofpoint, and BleepingComputer feeds; the iCloud variant spikes every Q4 as users' Photos libraries fill up. The \"upgrade\" link lands on a credential-harvest page replicating the targeted service's login screen. Fires when the body references a specific cloud-storage product (iCloud, Google Drive, OneDrive, Dropbox, Box, Mega, pCloud, Photos Library, Google Photos, Google One) OR generic \"cloud storage / cloud backup\" AND contains overage / capacity-urgency language (nearly full, almost full, 9X% full, storage limit / quota exceeded, running out of space, upgrade your storage, buy more storage) AND the sender is not a known cloud-storage vendor (apple.com, icloud.com, google.com, microsoft.com, onedrive.com, dropbox.com, box.com, mega.nz, pcloud.com, idrive.com, backblaze.com, sync.com, tresorit.com, nextcloud.com, owncloud.com). Auto-classified as danger via the `-lure` suffix.","tier":"danger","category":"other","isThin":false}}