Phishing & impersonation
607 signals in this category. Every entry links to a full explanation, severity tier, and false-positive notes.
What most signals in this category mean
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
- Fake plan administrator or financial advisor claiming a COVID or hardship early withdrawal from a 401k is available and that the target can avoid the 10% IRS penalty by submitting a claim within 30 days — advance-fee or credential-harvest fraud; real 401k hardship withdrawals are initiated through authenticated plan administrator portals, never cold email with penalty-avoidance claims.threat
401k-early-withdrawal-penalty-phish - Fake ACA marketplace or health insurance administrator claiming coverage will be cancelled unless income or enrollment is verified via email link — credential-harvest attack; real ACA coverage changes are communicated through healthcare.gov or state marketplace portals, never cold email links demanding income verification to prevent cancellation.threat
aca-health-insurance-cancel-phish - Fake agentic-AI permission-grant harvest — approve/authorize/delegate + inbox/calendar/repo scope + off-platform OAuth link.threat
agent-permission-consent-phish - Fake AI API runaway-spend / overage alert (OpenAI/Anthropic/Claude API) to harvest API keys or cloud credentials from non-official senderthreat
agentic-ai-runaway-spend-phish - AI Deepfake Extortion Threatthreat
ai-deepfake-synthetic-media-extortion - AI-generated phishing detected (compound structural heuristic)threat
ai-generated-phishing - AI LinkedIn spear-phishing lurethreat
ai-linkedin-spear-phishing-lure - Voice Clone Gift Card BECthreat
ai-voice-clone-gift-card-bec - Fake airline or hotel loyalty program claiming frequent flyer miles or reward points are about to expire and requiring account re-verification via email link — credential-harvest attack targeting loyalty account access.threat
airline-miles-expiration-phish - AiTM session-hijack phishing lurethreat
aitm-session-cookie-phishing-lure - Apple ID / iCloud phishthreat
apple-id-icloud-phish - QR code built from Unicode block characters (no image file)threat
ascii-qr-code-phishing - Fake auto / vehicle loan balloon payment due-date lure — "Your vehicle loan balloon payment of $X,XXX is due on [date] — pay now or your vehicle will be repossessed / reported to credit bureaus." Real balloon payment notices come from the lender's official domain established at loan origination, with proper account identification. Cold inbound email + balloon payment + repossession threat + off-brand payment link is a strong phishing indicator. Detection: balloon payment + auto/vehicle loan language + repossession/due urgency + no In-Reply-To + no List-Unsubscribe. Source: GC1 R16; CFPB auto loan fraud advisory 2025.threat
auto-loan-balloon-phish - 2FA backup / recovery codes theft — attacker asks the user to submit / enter / reply with their 2FA backup codes (the one-time codes users save when setting up 2FA for use when they lose their authenticator). Legitimate services DISPLAY backup codes to the user for saving; they NEVER ask the user to type codes back into anything, making "enter your backup codes at the verification page" / "reply with your 8 codes" a near-perfect attacker fingerprint. Harvested backup codes let the attacker bypass 2FA INDEFINITELY, even after a password change. Real precedents: Coinbase 2020 backup-code breach, Google 2023 phishing wave, ongoing Microsoft / Apple / Coinbase / Binance impersonation. Distinct from fido-passkey-downgrade-lure (passkey → password fallback), fake-password-manager-master-breach-lure (vault key harvest), fake-mobile-carrier-sim-swap-approval-lure (SMS takeover)threat
backup-codes-solicitation-phishing - Fake Plaid-style bank account re-link — "linked bank account expired, reconnect now" credential-harvest lure; real bank account linking is done inside the authenticated app, not via cold email.threat
bank-account-reverification-phish - Fake bank claiming account has been temporarily suspended or locked due to suspicious activity and requiring credential verification within 24 hours to restore access — credential-harvest attack; real banks never request full login credential re-entry via cold email link outside their authenticated portal.threat
bank-account-suspension-phish - Fake bank notice claiming unusual activity was detected and requiring identity verification within 24 hours to prevent account suspension — credential-harvest phishing; real banks never request full credential re-entry via cold email link under a 24-hour suspend-or-verify deadline.threat
bank-account-verification-phish - Bank secure message portal phishingthreat
bank-secure-message-portal-phish - Fake bank alert claiming an outgoing wire transfer requires email-link verification before processing — real banks authenticate wire transfers exclusively through secure portals, never email CTAs.threat
bank-wire-transfer-verification-phish - BankID credential harvest lurethreat
bankid-credential-harvest-lure - BEC vendor account verification fraudthreat
bec-vendor-account-verification-fraud - BEC Voice-Callback Request — deepfake-voice followup precursorthreat
bec-voice-callback-request - Fake HR department or benefits administrator claiming the target missed open enrollment and must click an emergency re-enrollment link within 24–48 hours or health insurance will be terminated — credential-harvest attack; real open enrollment is managed through authenticated employer HR portals, never cold email emergency enrollment links.threat
benefits-open-enrollment-emergency-phish - Fake Bolagsverket (Swedish Companies Registration Office) brand spoof — urgency + off-domain link.threat
bolagsverket-brand-phish - Hospitality-partner Extranet credential phishing — targets hotel / B&B / vacation-rental staff with Booking.com / Agoda / Expedia / Hotels.com / Airbnb / VRBO Partner Portal impersonation. Urgency hook tailored to the industry: "pending guest message awaiting your reply," "rate parity breach," "reservation dispute," "verify your property," "listing suspension" + a credential-harvesting login link on a non-booking.com / non-partner-central host. Force-multiplier attack: harvested Extranet creds let the attacker log in as the hotel and message guests FROM the real aggregator infrastructure with fake "update your payment method" instructions — each compromised hotel compromises its guests too. Evidence: Sekoia + Secureworks + Akamai + Google Threat Intelligence + Trustwave + Proofpoint 2024-2026 Vampire Bat / Smart Bat campaign coverage; Reuters 2024 hotel-industry reportingthreat
booking-extranet-hospitality-partner-phishing - Fake brokerage margin call / maintenance requirement demanding immediate wire transfer or account liquidation — impersonating Fidelity / Schwab / TD Ameritrade / IBKR.threat
broker-margin-call-phish - Browser-extension PUBLISHER credential phishing — impersonates Chrome Web Store / Firefox Add-ons (AMO) / Edge Add-ons / Opera Add-ons with a developer-account-security / Manifest-V3-migration / extension-listing-suspended / mandatory-publisher-verification narrative + credential-harvesting link on a non-store host. Targets extension PUBLISHERS (distinct from iter-889 `browser-extension-install-lure` which targets consumers). Compromise = attacker pushes signed malicious update to every installed user of every extension the publisher maintains, auto-deployed without user action. Cyberhaven Dec 26 2024 breach is canonical precedent: attacker phished a CWS developer, pushed malicious update that harvested Facebook Business manager credentials from every install. Evidence: Cyberhaven disclosure; OrcaSecurity + Socket + Secureannex Jan 2026 supply-chain-extension report; Google Chrome Web Store 2025 transparency report on developer-compromise-driven malicious updatesthreat
browser-extension-publisher-credential-phishing - Fake browser login window embedded in email (BitB)threat
browser-in-browser-phishing - Calendar invite phishing — .ics from freemail with phishing languagethreat
calendar-invite-phishing - TOAD callback phishing — subscription auto-renew + tollfree number + no URL (BazarCall / Luna Moth pattern)threat
callback-phishing-subscription-lure - Fake NHTSA or dealer claiming a safety recall requires a parts deposit payment before scheduling the recall repair — advance-fee fraud; real NHTSA safety recalls are always free to vehicle owners with no consumer deposit required.threat
car-recall-parts-deposit-phish - Catch-All Phishing Domainthreat
catch-all-domain-phishing - CEO Whaling Freemail Spoofthreat
ceo-whaling-no-thread-bec - Fake UnitedHealth Group / Optum / Change Healthcare breach notification phishing — "your records may have been affected by the Feb 2024 Change Healthcare ransomware attack — enroll in free credit monitoring within 30 days" from non-official sender harvesting SSN, Medicare ID, insurance IDs, and banking details for identity fraudthreat
change-healthcare-breach-notification-phish - Fake charity auction claiming the target won an auction item and must pay a delivery or shipping fee before the prize package is sent — advance-fee fraud; real charity auctions communicate winnings through authenticated event platforms and never require unsolicited advance fee payments to receive won items.threat
charity-auction-prize-phish - Fake charity or nonprofit claiming a donation tax receipt requires SSN or EIN verification via email link for IRS acknowledgment — PII-harvest fraud; real 501(c)(3) donation receipts are simple written acknowledgments that never require the donor to submit SSN or EIN.threat
charity-donation-receipt-phish - Fake CISA Known Exploited Vulnerabilities (KEV) catalog mandatory patch directive from non-official sender targeting IT/security staff — impersonates CISA BOD 22-01 with "patch within X days or face non-compliance penalty / federal mandate" urgency to harvest credentials or deploy malwarethreat
cisa-kev-mandate-phish - Clone phishing / corrected attachment (danger)threat
clone-phishing - Cloud file-share expiry credential phishing — impersonates OneDrive, Dropbox, Box, Google Drive, or WeTransfer with a file-expiry urgency + sign-in CTA at a non-official host. Proofpoint 2025-2026; Abnormal Security Q1 2026; CISA 2026.threat
cloud-file-share-expiry-credential-phish - Fake cloud storage quota exceeded / upgrade lure — "your storage is 98% full, upgrade now"; real quota alerts come from within the authenticated app (Google Drive / OneDrive / Dropbox), not cold inbound email.threat
cloud-storage-quota-phish - Cloudflare dev-platform abuse — *.pages.dev / *.workers.dev / cloudflare-ipfs.com URL + credential-action lure (Tycoon 2FA / Mamba 2FA hosts)threat
cloudflare-pages-workers-credential-host - Fake CMS / Healthcare.gov Special Enrollment Period (SEP) notice from non-official sender targeting ACA/Obamacare applicants — "enrollment deadline / your coverage will lapse / qualify for subsidies" urgency harvesting SSN, income details, and insurance informationthreat
cms-marketplace-sep-phish - Conference / event-registration phishing — impersonates major security + tech conferences (RSA Conference, Black Hat, DEF CON, Gartner Security & Risk Summit, Microsoft Ignite, AWS re:Invent, Google Cloud Next, KubeCon, O'Reilly, SANS, Infosecurity Europe, Web Summit, Dreamforce, SXSW) with a "registration incomplete / final payment due / invoice pending" narrative + payment-card-or-credential-harvesting link on a non-organizer host. Two BEC shapes: (a) credit card harvesting, (b) invoice-redirect where the victim's company pays an attacker-controlled account. Targets senior IT / security professionals + executives. Shipped 8 days before RSA Conference 2026 (Apr 27-May 1) to hit the peak phishing window. Evidence: Cofense 2024-2025 RSAC + Black Hat impersonation reports; Proofpoint 2024 conference-phishing coverage; CISA event-impersonation-BEC alertsthreat
conference-event-registration-phishing - ConsentFix OAuth harvest — instructs victim to copy post-login URL from browser into form (bypasses passkeys/MFA)threat
consentfix-oauth-token-copy-paste - Fake contest or sweepstakes claiming the target won a physical prize (iPad, vacation) but must pay a delivery or customs fee before it ships — advance-fee fraud targeting physical prizes; distinct from lottery-sweepstakes-prize-phish (cash prizes); no legitimate contest requires winner to pay delivery costs.threat
contest-prize-delivery-fee-phish - Fake 401(k) open enrollment window closure requiring portal credential entry — real 401k enrollment goes through the plan administrator's authenticated portal (Fidelity / Vanguard / Empower), not cold email.threat
corporate-401k-enrollment-phish - Fake corporate finance or compliance department claiming the target's expense report contains a policy violation and requiring repayment of the disallowed amount via email link or face paycheck deduction — credential-harvest and payment-collection fraud; real expense violations are handled through authenticated expense management platforms, never cold email payment links.threat
corporate-expense-policy-violation-phish - Fake credit bureau or identity protection service claiming credit has been compromised and requiring SSN verification immediately to freeze the credit report — PII-harvest fraud; real credit freezes are placed directly through Equifax/Experian/TransUnion via authenticated portals or phone, never via unsolicited email SSN submission.threat
credit-breach-ssn-freeze-phish - Cross-context login session phish — "companion / connector / verifier" app asks you to sign in at your real IdP then forwards your session to the attacker (2026 post-passkey pivot)threat
cross-context-login-session-phish - Fake CrowdStrike Falcon sensor update / channel-file remediation / EDR incident alert from non-crowdstrike.com senderwarning
crowdstrike-falcon-impersonation - Crypto ETF approval investment phishing — impersonates BlackRock iShares, Fidelity, VanEck, or Grayscale with fake ETF account-opening, dividend-claim, or early-access narratives. Chainalysis 2026 ($780M ETF-fraud); Proofpoint Oct 2024–2026; FINRA Feb 2026.threat
crypto-etf-approval-investment-phish - Fake Coinbase/Binance/Kraken account suspension or KYC notice with credential-harvest login link — targets hot wallet/exchange credentials (distinct from hardware wallet seed phrase phishing).threat
crypto-exchange-credential-harvest-phish - Fake crypto exchange KYC re-verification requiring passport or government ID upload via a non-official domain — impersonating Coinbase / Binance / Kraken / Gemini.threat
crypto-exchange-kyc-reverification-phish - Fake Ledger / Trezor critical firmware security update requiring seed phrase entry or wallet connect — real hardware wallet updates NEVER require seed phrases and are done via the official desktop app only.threat
crypto-hardware-wallet-phish - Crypto Wallet-Connect Drainerthreat
crypto-wallet-connect-drainer - Crypto wallet phishing — seed phrase / recovery phrase extraction demandthreat
crypto-wallet-phishing - Fake wallet security notice claiming the target's seed phrase or recovery phrase has been compromised and requiring them to enter their 12-word or 24-word phrase to migrate to secure storage — no legitimate wallet vendor ever requests a seed phrase via email; entering a seed phrase anywhere other than the physical device results in complete wallet drain.threat
crypto-wallet-seed-phrase-phish - Crypto wallet seed phrase recovery scamthreat
crypto-wallet-seed-phrase-recovery-scam - Fake CSN (Swedish student loan authority) brand spoof — urgency + off-domain link.threat
csn-brand-phish - Data breach account notification phishingthreat
data-breach-account-notification-phish - Fake dark-web breach notification — "your credentials were found on the dark web, click to protect your account" credential-harvest lure; real breach monitoring services never cold-email with click-through CTAs.threat
data-breach-credential-exposure-phish - Fake debt collector or law firm issuing a final notice before legal action or lawsuit, demanding immediate payment to avoid wage garnishment — illegal collection tactics and advance-fee fraud; real debt collection is governed by FDCPA and requires postal written validation notices, not cold email payment links threatening immediate garnishment.threat
debt-collection-legal-threat-phish - Delivery phishing — fee/customs demand (never legitimate)threat
delivery-phishing-fee - DEX / MEV-bot approval phishing — email claims a DeFi aggregator (1inch, Jupiter, Paraswap, Uniswap, CoW Protocol) detected a pending MEV-bot attack on the recipient's wallet and urges emergency approval revocation at a drainer URL. Chainalysis 2026; Certik 2026 DeFi approval-scam surge.threat
dex-aggregator-mev-bot-approval-phish - Discord Nitro + Steam credential-harvest phish — email offers free Discord Nitro (1-3 months) in exchange for linking Steam / Epic Games / Riot / Battle.net at a non-official URL. Dominant gaming-inbox credential vector: Discord T&S blocks 12M phishing DMs/month; IT Pro 2024-2025 + Bitdefender + MakeUseOf + Aura documented the Nitro+Steam bundle flow. Distinct from fake-discord-nitro-gift-account-phish (gift-account theft, no Steam-link bundled flow)threat
discord-nitro-steam-link-credential-lure - Document-share phishing — fake OneDrive/SharePoint/Google Drive/Dropbox share + sign-in-to-view credential harvestthreat
doc-share-phishing - Fake domain registrar claiming a domain is expiring and must be renewed via payment link — domain slamming / registrar fraud; real renewal notices come from the actual registrar the domain was registered with.threat
domain-expiration-fraud-phish - Fake domain registrar claiming the target's domain expires today or within hours and will be released to the public or acquired by competitors unless renewed immediately — domain-slamming urgency attack; real registrars send expiry notices on a predictable calendar, not same-day-expiry cold emails with competitor-acquisition threats.threat
domain-expiry-renewal-urgency-phish - Fake domain registrar claiming the target's domain expires in 48 hours and they must click to renew now or lose it permanently — domain-slamming / registrar-transfer fraud or credential-harvest; real domain expiration notices come from the actual registrar where the domain is registered, not cold emails from unfamiliar domains threatening permanent loss.threat
domain-registrar-renewal-phish - Fake DORA / ICT incident mandatory notification lure — urgency + off-europa.eu link.threat
dora-incident-phish - German pension-phishing impersonating the Deutsche Rentenversicherung (DRV-Bund + 14 regional bodies). Targets ~57M German pensioners + contributors. German-language panic hook: "Rentenbescheid," "Rentenanpassung," "drohende Rentenkürzung," "Rentenauszahlung ist gefährdet," "Rentenkonto überprüfen," "Sozialversicherungsnummer bestätigen" + credential-harvesting link on a non-DRV host (legit DRV only uses deutsche-rentenversicherung.de / rentenversicherung.de / drv-bund.de). Age-demographic weapon: retirees receiving monthly pension payments click panic narratives faster than younger cohorts. Evidence: DRV-Bund official Phishing-Warnungen page; BSI CS-Warnungen 2026; Heise + Spiegel + Süddeutsche Zeitung Feb 2026 coverage; Verbraucherzentrale + Stiftung Warentest senior-fraud advisories. Closes the non-English regional-coverage set (Spanish LATAM + Japanese + Brazilian + German)threat
drv-rentenversicherung-german-pension-phishing - Fake Amazon, eBay, or Etsy claiming account suspended due to unusual activity and requiring credential re-entry via email link to restore access — credential-harvest attack targeting online marketplace accounts.threat
e-commerce-account-verification-phish - Email quota / storage phishingthreat
email-quota-storage-phish - Fake employer benefits open enrollment requiring credential entry via a non-official HR portal — impersonating Workday / ADP / BambooHR / Gusto.threat
employee-benefits-open-enrollment-phish - Fake recruiter or HR department claiming a job offer is contingent on a background check processing fee that must be paid before the offer letter can be released — advance-fee fraud targeting job seekers; real employment background checks are paid by the employer, never requiring candidate upfront fee payment via email link.threat
employment-background-check-fee-phish - Fake employer or brokerage claiming the Employee Stock Purchase Plan (ESPP) enrollment or purchase window is closing imminently and requiring contribution update or banking details via email link before the window closes — credential-harvest; real ESPP changes are managed through authenticated HR portals, never cold email banking-detail requests.threat
espp-window-closure-phish - EV charging network account-takeover phish — email impersonates Tesla, ChargePoint, EVgo, Blink, IONIQ or Electrify America with a billing-failure or account-suspended hook harvesting credentials + payment card. Pwn2Own Miami 2026; FTC 2026 EV-charging complaint data.threat
ev-charging-account-takeover-credential-phish - Facebook / Instagram account phishthreat
facebook-instagram-account-phish - Fake FAFSA 2026-27 correction/verification notice from non-official sender targeting students and parents — impersonates studentaid.gov with "your FAFSA has errors — correction required / update your FAFSA" urgency harvesting FSA ID, SSN, and financial account informationthreat
fafsa-2026-27-correction-phish - Fake 1Password Teams / Bitwarden / Keeper Business team password manager subscription payment failed, team vault inaccessible, or employees locked out phishingthreat
fake-1password-bitwarden-teams-password-manager-billing-phish - Fake 1Password family/teams invitation phishing — impersonates 1Password with a family-invite or team-join lure directing to a fake portal harvesting master passwords + secret keys. Proofpoint / KrebsOnSecurity 2025-2026.threat
fake-1password-family-invite-credential-phish - Fake 401k, IRA, or retirement account early withdrawal or hardship distribution phishing — fraudulent email impersonating Fidelity, Vanguard, Charles Schwab, or another retirement account provider claiming the recipient is eligible for a penalty-free early withdrawal, hardship distribution, or COVID hardship relief from their 401k, IRA, or pension account — directing them to click a link to claim the funds, provide their Social Security number, date of birth, or bank account details to receive the distribution — a financial data theft attack exploiting the opportunity framing of accessible retirement savings to harvest identity and financial account informationthreat
fake-401k-retirement-early-withdrawal-phish - Fake Adobe Creative Cloud subscription payment failed or account suspended phishing — fraudulent email impersonating Adobe claiming the recipient's Creative Cloud subscription payment has failed, their Adobe account has been suspended due to unusual activity, or their subscription is expiring — directing them to sign in to their Adobe account, update billing information, or verify identity to restore access to Photoshop, Illustrator, Premiere Pro, After Effects, or Acrobat — a credential-harvesting and payment card theft attack targeting Adobe's 35M+ paid Creative Cloud subscribers; Adobe is consistently a top-20 most impersonated brand (APWG 2024)threat
fake-adobe-creative-cloud-subscription-account-phish - Fake Adobe Firefly / Leonardo.ai / Ideogram AI creative subscription suspended, generative credits depleted, image generation tokens unavailable, or Creative Cloud Firefly access blocked due to billing failure phishingthreat
fake-adobefirefly-leonardo-ai-creative-billing-phish - Fake ADP Workforce Now payroll platform subscription payment failed, payroll licenses suspended, payroll processing disabled, or ADP access no longer active phishingthreat
fake-adp-workforce-payroll-platform-billing-phish - Fake AI agentic billing dispute phishing — claims the victim's AI agent or autonomous assistant made unauthorized purchases (charging $hundreds) and creates 24-48h dispute urgency directing to a non-vendor credential-harvest page. FBI IC3 2026; Abnormal Security AI-agent-billing-fraud Q1 2026.threat
fake-agentic-ai-purchase-billing-dispute-phish - Fake AI API key expiry / rotation phishing — impersonates OpenAI, Anthropic, Google AI Studio, Mistral, Cohere, or Groq with a key-expiry or mandatory-rotation narrative + link to non-official API dashboard. Proofpoint Q1 2026 (+480%); Abnormal Security Mar 2026; SANS ISC Feb 2026.threat
fake-ai-api-key-expiry-rotation-phish - Fake AI tool subscription billing phishing — impersonates OpenAI/ChatGPT/Claude/Copilot/Gemini with fake charge notification + call-to-cancel phone number or dispute link; real AI billing emails come from official domains and never use callback phone tacticsthreat
fake-ai-chatbot-subscription-billing-phish - Fake AI training data opt-out / GDPR Article 17 phishing — impersonates a data-protection authority claiming the victim's data is used for AI training and must be deleted via a fraudulent "opt-out" form harvesting credentials or PII. EDPB 2026; Proofpoint GDPR-lure campaign Q1 2026.threat
fake-ai-training-data-optout-gdpr-phish - Fake Aircall / Dialpad / OpenPhone VoIP business phone subscription payment failed, business phone system offline, customer calls not received, or call routing and phone numbers suspended phishingthreat
fake-aircall-dialpad-voip-business-calling-billing-phish - Crypto airdrop-claim drainer lure — email announces token-airdrop eligibility (Backpack, Pyth, Jito, Wormhole, LayerZero ZRO, Monad MON, Arbitrum, Optimism, etc.) with a short claim window + connect-wallet CTA at an off-brand URL. Post-connection the drainer harvests approval signatures. Pre-connection recruitment variant; distinct from seed-phrase + EIP-712 permit signals. FBI IC3 PSA 2025-06-03 + FBI Mar 2026 FBI Token TRC-20 alert; $17B 2025 crypto fraud lossesthreat
fake-airdrop-claim-drainer-lure - Fake airline flight refund / EU261 compensation phishing — non-airline sender impersonates Delta, United, Southwest, Ryanair, or a flight compensation service claiming an approved refund or EU261 delay compensation that requires the recipient to submit bank account or credit card details within a short deadline to receive the paymentthreat
fake-airline-flight-refund-compensation-phish - Fake Airtable / Smartsheet database and spreadsheet subscription payment failed, team bases and automations inaccessible, or workspace and sheets suspended phishingthreat
fake-airtable-smartsheet-database-billing-phish - Fake Alexa / Google Home skill OAuth re-link lure — email claims an Alexa, Google Home, Home Assistant, or HomeKit skill requires account re-linking via OAuth at a non-official URL, harvesting credentials or granting malicious OAuth scope. Extension of the R2 oauth-device-code-phishing-lure into the voice-assistant ecosystem; Push Security 2025 consent-phishing trend. Distinct from R2 #1 (Microsoft devicelogin) and fake-smart-home-device-breach-lure (breach narrative)threat
fake-alexa-skill-account-link-oauth-lure - Fake Algolia / Elastic Cloud / Elasticsearch search platform subscription payment failed, search indexes and clusters suspended, or AI recommendations disabled phishing — fraudulent email impersonating Algolia, Elastic Cloud, or Elasticsearch claiming the subscription payment has failed, search indexes and query analytics are suspended, or Kibana dashboards and log ingestion are offline — Algolia: 11K+ paying customers ($0-1,000+/month); Elastic Cloud: 3K+ customers; search suspension makes product catalogs unsearchable and SaaS apps lose full-text search — immediate user-experience and revenue impactthreat
fake-algolia-elasticsearch-search-platform-billing-phish - Fake Alibaba, AliExpress, or Trade Assurance account suspended or payment held phishing — fraudulent email impersonating Alibaba, AliExpress, or Trade Assurance claiming the recipient's supplier account has been suspended, flagged, or that a payment or disbursement has been held pending a compliance review — directing them to click a link to verify their identity, provide bank account details, submit tax information, or confirm business information to restore account access or release held fundsthreat
fake-alibaba-aliexpress-trade-assurance-phish - Fake Amazon account suspension phish — Amazon account/Prime/order suspended + update payment/billing + click link to verify + account permanently closed in 24–48 hoursthreat
fake-amazon-account-suspension-phish - Fake Amazon order / account phishthreat
fake-amazon-order-account-phish - Fake Amazon order confirmation / unauthorized purchase phishthreat
fake-amazon-order-confirmation-phish - Fake Amazon unauthorized order or charge phishing — non-official sender impersonates Amazon falsely claiming an unauthorized order has been placed or an unexpected charge has appeared on the recipient's account, directing them to call a toll-free number or click a link to cancel, dispute, or refund the fraudulent transactionthreat
fake-amazon-order-unauthorized-charge-phish - Fake Amazon Prime membership renewal phishing — impersonates Amazon Prime annual renewal notices at $139–179, urges victim to "verify payment" or "cancel" via a link that harvests credentials or card details; Amazon is the #1 most impersonated brand globally (APWG Q4 2024); distinct from order-confirmation and account-suspension signalsthreat
fake-amazon-prime-membership-renewal-phish - Fake Amazon Seller Central or Amazon FBA account suspended or disbursement hold phishing — fraudulent email impersonating Amazon Seller Central, Amazon FBA, or Amazon Marketplace claiming the recipient's seller account has been suspended, flagged, or that disbursements have been withheld or placed on hold — directing them to click a link to appeal, verify their identity, provide bank account or routing number, submit tax information, or confirm business details to restore selling access and release held funds — a credential-harvesting and financial data theft attack targeting Amazon sellers whose business income depends on continuous marketplace access and timely disbursementsthreat
fake-amazon-seller-central-account-suspended-phish - Fake Ancestry / 23andMe / MyHeritage DNA genetic data account suspended, locked, or data breach phishing — fraudulent email impersonating Ancestry, 23andMe, or MyHeritage claiming the recipient's DNA account has been suspended for suspicious activity, their genetic data and family tree are inaccessible, or a data breach has exposed their DNA results — directing them to sign in, verify identity, or secure their account through a credential-harvesting portal; Ancestry 3M+ paid subscribers; 23andMe 14M+ customers (company filed for bankruptcy in 2024, heightening user anxiety about genetic data security); MyHeritage 4M+; DNA genetic data is uniquely sensitive — it is permanent, irreplaceable, identifies biological relatives, and contains medical predisposition information; 23andMe 2023 breach exposed 6.9M profiles creating a persistent threat perception in this user basethreat
fake-ancestry-23andme-dna-genetic-data-account-phish - Fake Apollo.io / ZoomInfo / Lusha B2B sales intelligence subscription payment failed, contact credits suspended, email sequences paused, or prospecting credits at risk phishingthreat
fake-apollo-zoominfo-b2b-sales-intelligence-billing-phish - Fake Apple Developer Program account suspended, certificates revoked, or App Store Connect access disabled phishing — fraudulent email impersonating Apple claiming the recipient's Apple Developer account has been suspended for a policy violation, their development certificates have been revoked, their App Store Connect access has been disabled, or their Developer Program membership payment has failed — directing them to sign in, update billing, or verify identity to restore developer access — a credential-harvesting attack targeting Apple's 34M+ registered developers and 5M+ active app publishers; when certificates are revoked, ALL apps stop working on every iOS/macOS device immediately — representing catastrophic revenue loss for indie developers and app businesses dependent on App Store incomethreat
fake-apple-developer-program-account-suspended-phish - Fake Apple ID account locked credential phishing — non-official sender impersonates Apple claiming the recipient's Apple ID, iCloud account, or Apple account has been locked, suspended, or disabled due to suspicious activity or an unauthorized sign-in attempt, directing them to verify credentials or click a link to restore access through a phishing portalthreat
fake-apple-id-account-locked-credential-phish - Fake Apple ID account locked / disabled phishthreat
fake-apple-id-account-locked-phish - Fake Apple ID / iCloud account suspended phishing — impersonates Apple security notices claiming the Apple ID was locked or suspended due to unusual activity, driving to a credential-harvest page; Apple is a top-5 most impersonated brand (APWG); FBI IC3 2023: Apple impersonation scams caused $300M+ in lossesthreat
fake-apple-id-icloud-account-suspended-phish - Fake Apple One subscription expired or payment failed with Apple Music, Apple TV+, Apple Arcade, iCloud+, and Apple Fitness+ all suspended phishingthreat
fake-apple-one-subscription-bundle-billing-phish - Fake Apple Pay / Google Pay / Samsung Pay digital wallet phishing — fraudulent email impersonating Apple Pay, Google Pay, Samsung Pay, or Apple Wallet claiming a transaction was declined, the digital wallet account has been suspended, unusual payment activity was detected, or a payment method has expired — directing the recipient to verify payment credentials, update billing information, or sign in to restore access — a credential and payment card harvesting attack targeting digital wallet users; Zimperium 2024: digital wallet phishing grew 340% YoY; Apple Pay has 500M+ users globallythreat
fake-apple-pay-google-pay-digital-wallet-phish - Fake Arbitrum BoLD / Optimism fault-proof L2 force-exit / force-inclusion drainer — "Sequencer censoring your withdrawal — submit force-exit before the 7-day challenge window expires" → fake L1 inbox harvests withdrawal-proof signatures + Permit2 approvals. Arbitrum BoLD + Optimism fault-proofs 2025-26 created legitimate force-exit primitives through the L1 delayed inbox over a 7-day challenge window, lending the lure narrative credibility. Real Arbitrum / Optimism force-exit + force-inclusion flows go through the protocol's native UI on arbiscan.io / bridge.arbitrum.io / app.optimism.io, never via inbound email link. Distinct from `base-superchain-l3-sequencer-fee-refund-claim-lure` (R8 C5, Base superchain L3 refund) — this signal is specifically the Arbitrum / Optimism / force-exit / 7-day-challenge-window framing. Bridge-drainer + crypto-permit2 cluster. Source: GC1 R9 multiagent council top-5 P0 (S4 crypto specialist).threat
fake-arbitrum-optimism-l2-force-exit-challenge-window-drainer - Fake Atlassian Jira / Confluence project management subscription payment failed, licenses no longer active, team wiki access suspended, or project management access disabled phishingthreat
fake-atlassian-jira-confluence-project-management-billing-phish - Fake Atlassian / Jira Software / Confluence subscription payment failed, projects locked, or wiki access suspended phishing — fraudulent email impersonating Atlassian claiming the recipient's Jira Software or Confluence subscription payment has failed, their Jira projects and sprint boards are locked, their Confluence wiki and team documentation are inaccessible, or an unauthorized charge was detected — distinct from workspace-share phishing; Atlassian: 200K+ enterprise customers with Jira (10M+ users) and Confluence (60M+ users); business-critical tool suspension ("your Jira projects will be locked in 48 hours") creates extreme team-level urgency threatening active sprints and release schedulesthreat
fake-atlassian-jira-confluence-subscription-billing-phish - Fake Audible / Kindle Unlimited / Scribd audiobook or ebook subscription membership payment failed, credits at risk, or account suspended phishing — fraudulent email impersonating Audible, Kindle Unlimited, or Scribd claiming the recipient's audiobook membership payment has failed, their pre-paid credits are at risk, their ebook access has been suspended, or an unauthorized charge was detected — directing them to update billing, restore membership, or verify payment through a credential-harvesting portal; Audible 40M+ subscribers ($14.95/month with pre-paid credit tokens — each credit worth $14.95 can be stolen as a redeemable asset); Kindle Unlimited 10M+ subscribers ($11.99/month, unlimited ebook access); Scribd 1M+; Audible credits are a uniquely tangible loss vector — users who know they have 2-3 unused credits feel they will lose immediate monetary value if their membership lapses, driving urgent actionthreat
fake-audible-kindle-unlimited-audiobook-subscription-phish - Fake Auth0 / Firebase Authentication developer platform subscription payment failed, authentication flows suspended, users cannot log in to your application, or tenant disabled phishingthreat
fake-auth0-firebase-auth-developer-platform-billing-phish - Fake auto insurance quote personal data harvest scam — fraudulent email poses as a car insurance comparison service claiming the recipient qualifies for lower rates, then requests Social Security number, driver's license number, and date of birth to "verify eligibility," harvesting the combination needed for full identity theftthreat
fake-auto-insurance-quote-personal-data-harvest-scam - Fake Automation Anywhere RPA platform subscription payment failed, bot licenses suspended, control room access disabled, or automation workflows no longer active phishingthreat
fake-automation-anywhere-rpa-platform-billing-phish - Fake AWS, Azure, or cloud platform billing failure or overage phishing — fraudulent email impersonating Amazon Web Services, Microsoft Azure, Google Cloud, or similar cloud provider claiming the recipient's payment has failed, account will be suspended, or has an unexpected usage charge — directing them to click a link to update payment details, confirm billing information, or verify their credit card to restore services — a high-value phishing attack targeting developers and businesses dependent on cloud infrastructurethreat
fake-aws-cloud-billing-overage-phish - Fake bank fraud alert credential phishing — non-official sender impersonates Chase, Bank of America, Wells Fargo, Citibank, or other major banks claiming unusual, suspicious, or fraudulent activity has been detected on the recipient's account and directing them to verify credentials (PIN, account number, routing number, password, SSN) through a phishing link or call, enabling full account takeoverthreat
fake-bank-account-fraud-alert-credential-phish - Fake urgent wire transfer authorization Business Email Compromise (BEC) — fraudulent email impersonates an executive or manager demanding an immediate wire transfer, bank transfer, or ACH payment while instructing the recipient to bypass normal approval channels, keep the request confidential, and not verify through usual procedures — a hallmark Business Email Compromise pattern that causes billions in annual corporate fraud lossesthreat
fake-bank-wire-transfer-authorization-bec - Fake beehiiv / ConvertKit / Ghost newsletter creator platform subscription payment failed, newsletter and paid subscriber access suspended, or email automation sequences halted phishing — fraudulent email impersonating beehiiv, ConvertKit, or Ghost claiming the subscription payment has failed, newsletters and email sends are suspended, paid subscriber access is no longer active, or membership subscriptions and automation sequences have been halted — beehiiv: 50K+ creators ($49-99/month Scale/Max); ConvertKit/Kit: 100K+ creators ($29-79/month Creator/Creator Pro); Ghost: 150K+ sites ($9-25/month Starter/Creator/Team/Business); distinct from Kajabi/Teachable course platform phishing — targets newsletter and email creators; newsletter platform suspension simultaneously halts all email sends, locks paid subscribers out of gated content, and breaks all automation sequences, ending recurring newsletter revenuethreat
fake-beehiiv-convertkit-newsletter-creator-billing-phish - Fake BetterHelp / Talkspace / Teladoc / Cerebral telehealth therapy subscription payment failed, membership cancelled, or unauthorized account access phishing — fraudulent email impersonating BetterHelp, Talkspace, Teladoc, or Cerebral claiming the recipient's online therapy or telehealth subscription payment has failed, their therapy access has been suspended, or unauthorized access was detected on their mental health account — directing them to update billing, renew the subscription, or verify identity through a credential-harvesting portal; BetterHelp 4M+ active subscribers ($95-425/month); Talkspace 2M+ users; Teladoc Health 60M+ members; Cerebral 150,000+ patients; mental health accounts contain sensitive protected health information (PHI) including diagnosis records, therapy notes, and prescription history; HIPAA-regulated PHI commands a premium on dark web markets; therapy is appointment-based and time-sensitive, creating urgency to restore access before the next scheduled sessionthreat
fake-betterhelp-talkspace-telehealth-therapy-subscription-phish - Fake Big 4 / McKinsey audit report PDF phishing — impersonates PwC, Deloitte, EY, KPMG, or McKinsey sending a "confidential audit findings" PDF from a non-official domain; PDF is a malware dropper or credential-harvest portal link. Proofpoint 2026; Cofense Big4-impersonation campaign Q1 2026.threat
fake-big4-audit-report-pdf-phish - Fake Booking.com / Hotels.com / Expedia credential phishing — non-OTA sender impersonates travel booking platforms with fake payout-on-hold, payment-declined, unusual-login, or refund-pending alerts designed to harvest host banking details or guest credit card informationthreat
fake-booking-hotel-platform-credential-phish - Fake Braze / Iterable / Customer.io cross-channel marketing automation subscription payment failed, customer engagement campaigns suspended, push notifications not delivered, or lifecycle campaigns and triggered messages disabled phishingthreat
fake-braze-iterable-marketing-automation-billing-phish - Fake Brex / Mercury / Ramp corporate banking account suspended, corporate cards frozen, or business payments halted phishing — fraudulent email impersonating Brex, Mercury, or Ramp claiming suspicious activity was detected, the corporate banking account is suspended, or corporate cards and business payments are frozen — distinct from Wise/Revolut (personal fintech) phishing; Brex: 20K+ companies ($0-50+/month); Mercury: 100K+ startups (business checking); startup corporate account suspension means inability to pay employees, vendors, contractors, or run payroll — existential business threatthreat
fake-brex-mercury-corporate-banking-account-phish - Fake Buffer / Hootsuite / Sprout Social social media management subscription payment failed, scheduled posts cancelled, or social media accounts disconnected phishing — fraudulent email impersonating Buffer, Hootsuite, or Sprout Social claiming the subscription payment has failed, scheduled social media posts have been cancelled, connected accounts are disconnected, or social media publishing is suspended — Buffer: 75K+ paying customers ($6-120/month Essentials/Team/Agency); Hootsuite: 800K+ paying customers ($99-249/month Pro/Team/Business/Enterprise); Sprout Social: 34K+ ($249-499+/month); distinct from general social media platform phishing; social media management suspension simultaneously cancels all queued posts across every connected social channel, disconnects all OAuth-linked social accounts, and halts all analytics data collectionthreat
fake-buffer-hootsuite-social-media-management-billing-phish - Business Email Compromise (BEC) / CEO fraud — executive impersonation requesting urgent wire transfer or gift cardsthreat
fake-business-email-compromise-ceo-fraud - Fake Calendly / Acuity Scheduling subscription payment failed, booking links and scheduling suspended, or appointment calendar inactive phishing — fraudulent email impersonating Calendly or Acuity Scheduling claiming the subscription payment has failed, booking links are no longer active, or appointment scheduling and client calendar are suspended — Calendly: 10M+ users, 50K+ paying ($10-20/month Standard/Teams); Acuity Scheduling: 100K+ users ($20-61/month); all booking links go dark simultaneously — service businesses lose all new appointment acquisition and existing scheduled appointments become inaccessiblethreat
fake-calendly-acuity-scheduling-platform-billing-phish - Fake Calendly / scheduling tool meeting invitation phishing — impersonates Calendly, Cal.com, Doodle, or scheduling platforms with a "confirm your meeting" link that harvests Microsoft 365 or Google credentials; Cofense 2024: scheduling-tool phishing emerged as top-10 business email threat as remote work normalized calendar link flowsthreat
fake-calendly-scheduling-meeting-invitation-phish - Fake Calm or Headspace meditation app subscription suspended — Premium or Plus plan payment failed, sleep stories inaccessible, guided meditations blocked, mindfulness content no longer available due to billing failure phishingthreat
fake-calm-headspace-meditation-app-subscription-billing-phish - Fake Calm Premium / Headspace Plus mindfulness or meditation subscription payment failed, sleep sounds suspended, or meditation access revoked phishing — fraudulent email impersonating Calm or Headspace claiming the recipient's meditation subscription payment has failed, their sleep sounds and Daily Calm sessions are suspended, or their guided meditation access has been revoked — directing them to update billing, restore access, or sign in through a credential-harvesting portal; Calm: 4M+ paid subscribers ($69.99/year); Headspace: 2M+ paid subscribers ($12.99/month); sleep content urgency peaks at evening check times — "your sleep sounds are unavailable tonight" exploits pre-sleep anxiety; meditation app users in active wellness routines fear disrupting streaks and daily practicesthreat
fake-calm-headspace-mindfulness-meditation-subscription-phish - Fake Canva Pro / Canva Teams subscription billing or account suspended phishing — fraudulent email impersonating Canva claiming the recipient's Canva Pro or Canva Teams subscription payment has failed, their account has been suspended, or their subscription is expiring with designs and Brand Kit at risk — directing them to sign in, update billing, or verify account — distinct from the design-file-share lure; Canva has 135M+ registered users and 15M+ paying Pro/Teams subscribers making it a high-volume impersonation targetthreat
fake-canva-pro-subscription-billing-phish - Fake Carta / Pulley cap table and equity management subscription payment failed, cap table inaccessible, option exercises suspended, or stockholder data at risk phishingthreat
fake-carta-pulley-cap-table-equity-billing-phish - Fake Cash App / Zelle payment pending claim phishing — "you have a pending payment of $XXX — log in to claim" + or account verification required to release held funds + or overpayment refund scam + real Cash App/Zelle never email unsolicited pending claim notificationsthreat
fake-cashapp-zelle-payment-pending-claim-phish - Fake credit card cashback / reward points expiry phishthreat
fake-cashback-reward-redemption-phish - Fake Celonis / UiPath process mining and RPA subscription payment failed, platform licenses suspended, robots and automation workflows disabled, or execution management system access no longer active phishingthreat
fake-celonis-uipath-process-mining-rpa-billing-phish - Fake Ceridian Dayforce payroll and HCM platform subscription payment failed, payroll licenses suspended, workforce management disabled, or Dayforce access no longer active phishingthreat
fake-ceridian-dayforce-payroll-hcm-billing-phish - Fake Character.ai Plus subscription suspended — AI companion/roleplay platform payment failed, character chats and character memory no longer active, roleplay access revoked due to billing failure phishingthreat
fake-characterai-plus-subscription-billing-phish - Fake Chargebee / Recurly / Paddle subscription billing platform payment failed, subscription billing suspended, customer subscriptions cannot renew, or recurring billing and invoice generation disabled phishingthreat
fake-chargebee-recurly-subscription-billing-platform-phish - Fake charity / disaster relief donation phishing — Red Cross / UNICEF / Salvation Army impersonation soliciting urgent donations after disasters; FTC 2024: $24M+ in charity scam losses; spikes within 24h of every major disaster declarationthreat
fake-charity-disaster-relief-donation-phish - Fake ChatGPT / OpenAI / Gemini / Claude AI service subscription phishing — fraudulent email impersonating OpenAI, ChatGPT Plus, Google Gemini Advanced, Anthropic Claude, or Microsoft Copilot claiming the recipient's subscription payment failed, account has been suspended for a usage policy violation, or subscription is expiring — directing them to sign in to update billing, verify identity, or restore access through a spoofed account portal — a credential-harvesting and payment card theft attack targeting AI service users; Kaspersky 2025: AI brand impersonation grew 1,200% YoY; APWG Q1 2026: OpenAI is a top-10 most impersonated brandthreat
fake-chatgpt-openai-ai-service-subscription-phish - Fake Chewy Autoship / BarkBox / The Farmer's Dog pet food or pet supply subscription payment failed, autoship paused, or order cancelled phishing — fraudulent email impersonating Chewy, BarkBox, The Farmer's Dog, or Nom Nom claiming the recipient's pet food autoship payment has failed, their upcoming pet food delivery has been paused or cancelled, or an unauthorized order was placed — directing them to update billing, resume autoship, or verify their account through a credential-harvesting portal; Chewy 20M+ active customers ($10.3B annual revenue; autoship represents 75% of revenue and is specifically designed to be automatic — billing communications are expected and trusted); BarkBox 1M+ monthly subscribers ($35/month); The Farmer's Dog 500K+ subscribers ($100-300/month premium pet food); Nom Nom 250K+; pet owners are emotionally motivated to ensure uninterrupted pet food delivery, acting rapidly on any notification that their pet's food supply is at riskthreat
fake-chewy-petsmart-pet-autoship-subscription-phish - Fake child support enforcement arrears, wage garnishment, or license suspension phishing — fraudulent email impersonating a state child support enforcement agency or Title IV-D division claiming the recipient has past-due child support arrears, a pending license suspension, wage garnishment order, or bank levy — directing them to click a link to pay, provide bank account details, routing number, SSN, or case number to settle the delinquency and avoid legal actionthreat
fake-child-support-enforcement-payment-phish - Fake Chime / SoFi / Ally Bank / Marcus online-only digital bank account suspended, locked, or unauthorized transaction phishing — fraudulent email impersonating Chime, SoFi Bank, Ally Bank, or Marcus by Goldman Sachs claiming the recipient's digital banking account has been temporarily suspended, locked for suspicious activity, or that an unauthorized transaction was detected — directing them to sign in, verify identity, or secure their account through a credential-harvesting portal; Chime 22M+ account holders; SoFi 9M+ members; Ally Bank 11M+ customers; Marcus 10M+ customers; online-only banks rely exclusively on digital communication — users receive all alerts by email and are less suspicious of security notifications sent this waythreat
fake-chime-sofi-digital-bank-account-phish - Fake CircleCI / Buildkite / Travis CI CI/CD pipeline subscription payment failed, pipelines suspended, or deployments halted phishing — fraudulent email impersonating CircleCI, Buildkite, or Travis CI claiming the subscription payment has failed, CI/CD pipelines are suspended, builds are halted, or deployments are blocked — CircleCI: 30K+ paying organizations, 500K+ developers ($30-2,000+/month), used by Spotify, Segment, and thousands of tech companies; Buildkite: 2,000+ enterprise customers including GitHub, Shopify, and Stripe; Travis CI: legacy CI/CD widely used in open source; distinct from GitHub/GitLab devops platform billing — targets dedicated CI/CD pipeline tooling; suspended CI/CD pipelines block all code deployments to production, halting feature releases, hotfix deployments, and automated test execution simultaneouslythreat
fake-circleci-buildkite-cicd-pipeline-billing-phish - Fake Clari / Revenue Grid revenue forecasting platform subscription payment failed, deal inspection and forecast submissions suspended, pipeline intelligence disabled, or revenue intelligence at risk phishingthreat
fake-clari-revenue-grid-revenue-forecasting-platform-billing-phish - Fake Anthropic Claude Pro or Teams subscription billing failure or account suspension phishingthreat
fake-claude-pro-billing-phish - ClickFix / FakeCaptcha PowerShell paste scam — email disguises as Cloudflare/Google/reCAPTCHA verification and instructs the victim to press Win+R or open PowerShell/terminal and paste a clipboard-injected command, silently running mshta/PowerShell to install stealer malware (CISA-flagged Q4 2025 → 2026)threat
fake-clickfix-captcha-powershell-paste-scam - Fake cloud storage account deletion phish — Google Drive/Dropbox/OneDrive/iCloud storage full + account/files will be permanently deleted + click to upgrade / enter card detailsthreat
fake-cloud-storage-account-deletion-phish - Fake Cloudflare account suspended or DDoS protection disabled phishing — fraudulent email impersonating Cloudflare claiming the recipient's Cloudflare account has been suspended, flagged, or their DDoS protection has expired or been disabled — directing them to sign in, update billing, or verify their Cloudflare account to restore website protection — distinct from the ClickFix CAPTCHA lure; Cloudflare has 33M+ registered users and powers 20%+ of the global web; the catastrophic fear of a website losing DDoS protection and going offline drives instant, uncritical actionthreat
fake-cloudflare-account-security-ddos-phish - Fake Cloudflare / Fastly CDN and network services subscription payment failed, domain protection suspended, CDN services disabled, or SSL and DDoS protection access no longer active phishingthreat
fake-cloudflare-fastly-cdn-network-billing-phish - Fake Cloudflare Zero Trust / WARP+ admin re-authentication or policy suspension phishing — fraudulent email impersonating Cloudflare claiming the recipient's Zero Trust admin account requires re-authentication, their WARP+ team plan has expired, or their Zero Trust access policies are suspended — targeting IT administrators and DevOps engineers who use Cloudflare One to gate corporate application access; Zero Trust admin credentials give attackers full control over which users can access which apps behind the gatewaythreat
fake-cloudflare-zero-trust-warp-admin-phish - Fake Cloudinary / Bunny CDN / Fastly media delivery or CDN subscription payment failed, image delivery and video streaming suspended, or media assets offline phishing — fraudulent email impersonating Cloudinary, Bunny CDN, or Fastly claiming the subscription payment has failed, image and video delivery is suspended, or media assets and content delivery are no longer active — Cloudinary: 1M+ developers ($89-450/month Plus/Advanced); Bunny.net: 300K+ users; Fastly: 3K+ enterprise customers; CDN suspension breaks every image and video on the subscriber's website simultaneously — entire web properties become visually brokenthreat
fake-cloudinary-bunny-cdn-media-delivery-billing-phish - Fake Coinbase, Binance, or crypto exchange account phishing — fraudulent email impersonating Coinbase, Binance, Kraken, Gemini, or another cryptocurrency exchange claiming the recipient's account has been restricted, suspended, frozen, or compromised due to suspicious activity or an account review — directing them to click a link to verify their identity, provide KYC documentation, submit a government ID, or confirm account details to restore access — a credential-harvesting and identity theft attack targeting holders of potentially high-value cryptocurrency accountsthreat
fake-coinbase-crypto-exchange-account-phish - Fake Tesla / Rivian / Lucid / Ford BlueCruise / GM OnStar / Mercedes Me / BMW ConnectedDrive / Audi connect / Volvo Cars / Polestar / NissanConnect / HondaLink / Toyota Connect / Hyundai BlueLink / Kia Connect connected-car account-takeover lure — "your connected-car account accessed by unauthorized device, verify within 24 hours or vehicle features suspended" targeting 30M+ global connected-car accounts (4M+ Tesla, 1M+ Rivian, 50K+ Lucid, millions of legacy-OEM accounts); account controls infotainment + Supercharger billing + remote unlock + summon/drive-away + phone-as-key + cabin-camera; post-compromise = physical vehicle theft via remote unlock, Supercharger billing drain, dark-market sale $500-5K per account, cabin-camera + GPS-history exfil for stalking / burglary-timing (Vice + Ars Technica 2023-2024 documented remote-summon attacks on compromised Tesla accounts)threat
fake-connected-car-account-takeover-lure - Fake Contentful / Sanity / Storyblok headless CMS subscription payment failed, content delivery suspended, or CMS spaces and entries inaccessible phishing — fraudulent email impersonating Contentful, Sanity, or Storyblok claiming the subscription payment has failed, content delivery is suspended, or CMS spaces, datasets, and entries are no longer accessible — Contentful: 30% of Fortune 500 companies, 7K+ enterprise customers ($300-2,000+/month); Sanity: 1,000+ enterprise customers; headless CMS suspension takes down every website and app that reads content from the CMS simultaneously — the entire digital presence goes content-dark at oncethreat
fake-contentful-sanity-headless-cms-billing-phish - Fake Contentsquare / Heap digital experience analytics subscription payment failed, session recordings and heatmaps suspended, data capture tracking disabled, or product analytics access no longer active phishingthreat
fake-contentsquare-heap-digital-experience-analytics-billing-phish - Fake credit card account suspended or blocked phishing — fraudulent email impersonating Visa, Mastercard, American Express, Discover, or Citi claiming the recipient's credit card has been suspended, blocked, flagged, or cancelled due to suspicious activity or unauthorized charges — directing them to click a link to verify card details, update billing information, or confirm identity to restore card access — a credential-harvesting phishing attack targeting payment card informationthreat
fake-credit-card-account-suspended-phish - Fake credit card rewards / loyalty points expiring phishing — impersonates Chase Ultimate Rewards, Amex Membership Rewards, Citi ThankYou, Delta SkyMiles, or other reward programs claiming points will be forfeited unless redeemed via a link that harvests card credentials or account login; high conversion because victims fear genuinely losing their accumulated pointsthreat
fake-credit-card-rewards-points-expiring-phish - Fake Experian, Equifax, or credit bureau identity theft alert or credit monitoring phishing — fraudulent email impersonating Experian, Equifax, TransUnion, Credit Karma, or an identity protection service claiming the recipient's personal information was found on the dark web, their SSN was exposed in a data breach, or suspicious activity was detected on their credit report — directing them to click a link to verify their identity, provide their Social Security number, date of birth, or financial details to lock or freeze their credit — a high-value identity theft and financial data harvest attack exploiting fear of credit damage and data breach consequencesthreat
fake-credit-score-identity-theft-monitoring-phish - Fake GoFundMe / Kickstarter / Indiegogo / Fundly / YouCaring / DonorsChoose / SeedRS / Crowdcube / StartEngine / WeFunder campaign-CREATOR payout phishing — "your campaign payout is on hold / creator verification required, verify within N hours or funds return to donors" + credential-harvesting link to a non-vendor host impersonating the creator / organizer dashboard. Blast radius: payout redirection (medical GoFundMes can be tens of thousands; tech Kickstarter campaigns hundreds of thousands), campaign page defacement for follow-up solicitation to different endpoint, donor PII exposure via dashboard, Stripe Connect abuse on Kickstarter. Distinct from donor-side charity phish and from fake-patreon-substack-creator-payout-phish (subscription-based creators). Evidence: GoFundMe Trust & Safety advisories (COVID-19 2020, Turkey-Syria 2023, Hawaii wildfire 2023); Kickstarter 2022-2024 creator advisories around high-profile $1M+ tech campaigns; BBB + FTC crowdfunding takeover coveragethreat
fake-crowdfunding-creator-payout-phish - Fake CrowdStrike Falcon / SentinelOne endpoint security platform subscription payment failed, platform licenses suspended, endpoint protection and detection disabled, or agents no longer active phishingthreat
fake-crowdstrike-sentinelone-endpoint-security-billing-phish - Fake Crunchyroll / Paramount+ / Peacock / Discovery+ second-tier streaming subscription payment failed, streaming access suspended, or account cancelled phishing — fraudulent email impersonating Crunchyroll, Paramount+, Peacock, or Discovery+ claiming the recipient's streaming subscription payment has failed, their streaming access has been suspended, or an unauthorized charge was detected — directing them to update billing, reactivate the subscription, or verify payment through a credential-harvesting portal; Crunchyroll 13M+ premium subscribers (world's largest anime streaming platform); Paramount+ 71M+ subscribers; Peacock 34M+ paid subscribers; Discovery+ 24M+; second-tier streaming platforms are more vulnerable than Netflix/Hulu because users are less security-aware about them and more likely to forget billing dates, making billing failure emails feel unexpected but plausiblethreat
fake-crunchyroll-paramount-peacock-streaming-subscription-phish - Fake crypto exchange KYC identity verification phishing — Binance/Coinbase/Kraken impersonation demanding government ID upload or account will be frozen/suspended + AML compliance pretext + sender domain is always a lookalike, never the real exchange domainthreat
fake-crypto-exchange-kyc-identity-verification-phish - Fake crypto seed phrase / wallet recovery scamthreat
fake-crypto-seed-phrase-wallet-recovery-scam - Fake crypto wallet seed phrase phishing — fraudulent email impersonating MetaMask, Coinbase Wallet, Ledger, Trust Wallet, Phantom, or Trezor claiming the recipient's wallet has been suspended, compromised, or flagged — then directing them to enter, submit, or provide their seed phrase, secret recovery phrase, mnemonic, or private key to verify ownership and restore access — a devastating crypto theft attack that instantly drains all wallet assetsthreat
fake-crypto-wallet-seed-phrase-phish - Fake cryptocurrency exchange account security phishing — non-official sender impersonates Coinbase, Binance, Kraken, or Gemini claiming the recipient's account has been locked, suspended, or flagged for suspicious activity, then harvests login credentials or government ID documents through a phishing portal, enabling irreversible theft of all held cryptocurrencythreat
fake-cryptocurrency-exchange-account-security-phish - Fake Cursor / Replit / Windsurf AI code editor subscription payment failed, coding environment and workspace suspended, or AI coding features disabled phishing — fraudulent email impersonating Cursor, Replit, or Windsurf claiming the subscription payment has failed, the AI code editor and workspace are suspended, or AI coding features and repls are no longer active — Cursor: 1M+ paying users ($20/month Pro, $40/month Business); Replit: 4M+ users ($20/month Core, $25-40/month Teams); distinct from GitHub Copilot phishing; AI coding tool suspension disables the entire development workflow — editors switch to read-only mode, AI completions stop, and cloud execution environments go offlinethreat
fake-cursor-replit-ai-coding-tool-billing-phish - Fake dark-web credential monitoring phishing — claims the victim's passwords were found on the dark web or RaidForums, creates urgency to "upgrade" or "remove" data, and harvests credentials or payment info at a non-legitimate monitoring-service domain. ITRC 2026; Proofpoint identity-theft-lure campaign 2026.threat
fake-dark-web-monitoring-credential-phish - Fake data breach identity protection phish — your credentials/SSN found on dark web + click to see breach report + pay for identity theft protection / dark web monitoring subscriptionthreat
fake-data-breach-identity-protection-phish - Fake Databricks Lakehouse Platform subscription payment failed, workspace suspended, clusters paused, Unity Catalog access disabled, or MLflow experiments unavailable phishingthreat
fake-databricks-lakehouse-platform-billing-phish - Fake Datadog / New Relic observability and APM platform subscription payment failed, licenses suspended, monitoring and dashboards disabled, or APM access no longer active phishingthreat
fake-datadog-newrelic-observability-apm-billing-phish - Fake Tinder / Bumble / Hinge / Match.com premium subscription payment failed or account suspended phishing — fraudulent email impersonating Tinder, Bumble, Hinge, or Match.com claiming the recipient's Tinder Gold, Bumble Premium, Hinge Preferred, or Match.com membership payment has failed, their account has been downgraded or suspended, or their premium features are no longer available — directing them to sign in and update billing to restore their subscription — distinct from romance scam phishing (which involves fake relationships); this targets the platform billing UX; Tinder 75M+ monthly active users; Bumble 42M+; Hinge 23M+; Match.com 9M+ paid subscribers; IC3 2024: dating platform impersonation phishing growing rapidly targeting the 18-35 demographic with high premium-feature adoptionthreat
fake-dating-app-subscription-billing-phish - Fake DAZN or ESPN+ sports streaming subscription suspended — annual or monthly plan payment failed, live sports access revoked, sports streaming content no longer available due to billing failure phishingthreat
fake-dazn-espnplus-sports-streaming-subscription-billing-phish - Fake dbt Cloud / Hightouch data transformation and reverse ETL subscription payment failed, dbt models and dbt runs suspended, audience syncs disabled, or reverse ETL syncs no longer active phishingthreat
fake-dbt-hightouch-data-transformation-reverse-etl-billing-phish - Fake Deel / Rippling / Gusto global payroll and HR platform subscription payment failed, payroll suspended, or employee management platform offline phishing — fraudulent email impersonating Deel, Rippling, or Gusto claiming the subscription payment has failed, global payroll and contractor payments are suspended, or employee management and HR workflows are no longer active — Deel: 35K+ companies ($49/contractor/month, $599+/EOR/month); Rippling: 17K+ companies ($8/user/month+); Gusto: 300K+ businesses ($40+$6/person/month); payroll suspension means employees cannot be paid — the single most catastrophic SaaS-linked business emergency with immediate legal, contractual, and reputational consequencesthreat
fake-deel-rippling-global-payroll-platform-billing-phish - Fake Descript / Riverside / Buzzsprout podcast and video creation tool subscription payment failed, video projects suspended, or podcast recordings halted phishingthreat
fake-descript-riverside-podcast-video-creation-billing-phish - Fake DigitalOcean / Linode / Vultr VPS or cloud hosting account suspended, droplets and servers offline, or managed databases at risk phishing — fraudulent email impersonating DigitalOcean, Linode (Akamai Cloud), or Vultr claiming the account is suspended, droplets and cloud servers are offline, or managed databases and Kubernetes clusters are at risk — DigitalOcean: 600K+ paid customers ($12-960+/month); Linode: 900K+ users; Vultr: 1.5M+ users; self-managed VPS suspension means production servers, websites, APIs, and databases all go offline simultaneously — distinct from AWS/Azure (covered) and Vercel/Netlify (covered)threat
fake-digitalocean-linode-vps-hosting-billing-phish - Fake diploma / degree mill scam — earn accredited degree based on life experience + no coursework/exams required + buy fake degree online + ships in 7 days + employers accept + discreet packagingthreat
fake-diploma-degree-mill-credential-scam - Fake Discord Nitro gift or account compromised phishing — fraudulent email impersonating Discord claiming the recipient has been selected for a free Nitro subscription gift, their account has been compromised, or their account has been suspended — directing them to click a link to claim the Nitro gift, verify their account token, or appeal the suspension — a credential-harvesting phishing attack heavily targeting gamers, teenagers, and young adults in Discord's massive user basethreat
fake-discord-nitro-gift-account-phish - Fake DistroKid / TuneCore / CD Baby music distribution subscription expired or distribution fee unpaid with music removed from Spotify, Apple Music, and all streaming platforms and royalty payments stopped phishingthreat
fake-distrokid-tunecore-music-distribution-billing-phish - Fake DMCA / AI-generated legal threat phishing — impersonates copyright enforcement with DMCA/cease-and-desist urgency + dispute CTA at a non-official link, harvesting credentials. FBI IC3 2025 (+480% AI-generated legal notices); Abnormal Security Apr 2026.threat
fake-dmca-ai-legal-threat-phish - Fake DMV or vehicle registration renewal phishing — fraudulent email impersonating a state Department of Motor Vehicles, DMV renewal service, or motor vehicle division claiming the recipient's vehicle registration has expired, is past due, or has an unpaid fine outstanding — directing them to click a link or visit a portal to pay the registration fee online immediately to avoid penalties, suspension, or cancellation — a smishing and phishing scam that spikes around registration renewal periodsthreat
fake-dmv-vehicle-registration-renewal-phish - Fake Docker Hub / GHCR / ECR secret-leak credential breach lure — email claims Docker Hub, GHCR, GitLab Container Registry, Quay.io, Amazon ECR, ACR, or Google Artifact Registry detected hard-coded secrets in the recipient's container images, demands immediate credential rotation at a fake security console. Flare Sep 2025: 10,000+ Docker Hub images exposing AWS/DB/API keys; THN Dec 2025 IAM-crypto-mining chain. Distinct from fake-docker-hub-desktop-subscription-billing-phish (billing, not secret-leak)threat
fake-docker-hub-credential-breach-lure - Fake Docker Hub / Docker Desktop subscription suspended, image pull rate exceeded, private repositories inaccessible, or CI/CD pipeline disabled due to billing failure phishingthreat
fake-docker-hub-desktop-subscription-billing-phish - Fake DocuSign / eSign document signature phishing — "document awaiting your signature" from non-official domain + click link leads to credential harvesting login + may ask for Microsoft/Google/corporate credentials + real eSign platforms never request credentials via cold emailthreat
fake-docusign-esign-document-signature-phish - Fake DraftKings / FanDuel / BetMGM sports betting sportsbook account suspended, funds withheld, or identity verification required phishing — fraudulent email impersonating DraftKings, FanDuel, BetMGM, or Caesars Sportsbook claiming the recipient's sportsbook account has been suspended for suspicious activity, their funds or winnings have been placed on hold pending identity verification, or unauthorized access was detected — directing them to sign in, verify age/identity, or submit KYC documents through a credential-harvesting portal; DraftKings 6.6M+ MAU; FanDuel 8M+ MAU; BetMGM 5M+; accounts hold real cash balances plus SSN and bank routing details required for KYC/AML compliance; sports betting now legal in 35+ US states with explosive growth creating a large, rapidly expanding target poolthreat
fake-draftkings-fanduel-sports-betting-account-phish - Fake Drata / Vanta compliance automation subscription payment failed, SOC 2 audit evidence collection suspended, or compliance monitoring and security controls no longer active phishingthreat
fake-drata-vanta-compliance-automation-billing-phish - Fake Dropbox Business / Box Enterprise cloud storage subscription payment failed, team folders inaccessible, or organization content suspended phishingthreat
fake-dropbox-business-box-cloud-storage-billing-phish - Fake EU Digital Services Act Article 16 / 22 trusted-flagger takedown-notice impersonation lure — "DSA Article 16 trusted flagger takedown notice has been issued for illegal content on your account; you have 24 hours to appeal via the Digital Services Coordinator portal" spoofing the DSC (Digital Services Coordinator). Targets content creators, brand-protection teams, and platform-trust-and-safety admins. The DSA Art. 16 / 22 / 23 takedown machinery is now live across VLOPs / VLOSEs (very large online platforms / search engines), giving attackers a real regulatory pretext. Lookalike DSC portals harvest platform-admin credentials, content metadata, and creator-account access. Real DSC takedown notices come through formal platform-trust-and-safety channels, never via inbound email link from an unfamiliar domain. Source: GC1 R8 multiagent council (S3 EU-reg specialist).threat
fake-dsa-trusted-flagger-takedown-notice-impersonation-lure - Fake Duolingo Super / MasterClass / Udemy / Skillshare online learning subscription payment failed, course access suspended, or streak at risk phishing — fraudulent email impersonating Duolingo, MasterClass, Udemy, or Skillshare claiming the recipient's learning subscription payment has failed, their course access has been suspended, or their Duolingo streak is at risk — directing them to update billing, restore membership, or verify payment through a credential-harvesting portal; Duolingo 74M+ MAU with 20M+ Super subscribers ($6.99/month; streak mechanic creates unique anxiety — "your streak is at risk" is more emotionally urgent than standard access loss); MasterClass 10M+ subscribers ($180/year); Udemy 62M+ learners with 12M+ paid subscription users; Skillshare 12M+ members; online learning platforms offer course certificates as career credentials — "your completion certificates are at risk" amplifies attack urgency beyond simple access lossthreat
fake-duolingo-masterclass-edtech-subscription-phish - Fake eBay seller account suspended or payment hold phishing — fraudulent email impersonating eBay claiming the recipient's seller account has been suspended, flagged, or placed on a payment hold due to a policy violation, high dispute rate, or chargeback activity — directing them to click a link to verify their identity, provide bank account or routing number, submit tax information, or appeal the suspension to restore their selling privileges and release their funds — a credential-harvesting and financial data theft attack targeting eBay sellers whose business income depends on marketplace accessthreat
fake-ebay-seller-account-payment-hold-phish - Fake ElevenLabs voice AI subscription suspended — Creator, Pro, or Scale plan payment failed, character quota revoked, voice cloning access blocked, or text-to-speech API suspended due to billing failure phishingthreat
fake-elevenlabs-voice-ai-subscription-billing-phish - Fake job offer / employment phish — unsolicited job offer + pay background check fee / training deposit + provide SSN or bank details upfrontthreat
fake-employment-background-check-phish - Fake Microsoft Entra B2B external guest invite phishing — abuses the legitimate invites@microsoft.com cross-tenant invitation mechanism to grant attackers cross-tenant access to the victim's Microsoft identity. CISA AA24-038A; Unit 42 2025-2026 (340+ M365 orgs compromised).threat
fake-entra-b2b-external-guest-invite-phish - Fake e-signature harvestthreat
fake-esignature-credential-harvest - Fake ESOP / RSU / stock-option expiry phishing — impersonates Carta, Morgan Stanley At Work, Fidelity NetBenefits, E*Trade, or Computershare with equity-award-expiry urgency + brokerage-credential harvest. SEC/FINRA 2025-2026; Abnormal Security Mar 2026.threat
fake-esop-rsu-stock-option-expiry-phish - Fake EU AI Act compliance enforcement phishing — impersonates EU AI Office or AI compliance auditor with EU Regulation 2024/1689 enforcement urgency (mandatory registration, €30M fine threat) and a non-europa.eu registration link. FBI IC3 2026; ENISA 2026 AI-compliance-lure advisory.threat
fake-eu-ai-act-compliance-enforcement-phish - Fake Expensify / Ramp / Navan expense management subscription payment failed, expense reports cannot be submitted, employee reimbursements on hold, or corporate cards and spend management suspended phishingthreat
fake-expensify-ramp-expense-management-billing-phish - Fake FedEx / UPS / USPS delivery fee / customs hold phishthreat
fake-fedex-ups-usps-delivery-fee-phish - Fake FEMA or government disaster relief advance fee phishing — fraudulent email impersonating FEMA, the Federal Emergency Management Agency, SBA disaster loan programs, or generic emergency aid agencies claiming the recipient's disaster relief application has been approved or they are eligible for emergency grant funds — directing them to click a link, verify their identity, provide bank routing details, or pay a processing fee to release the funds — a disaster-opportunism fraud that peaks after major hurricanes, wildfires, and floodsthreat
fake-fema-government-disaster-relief-advance-fee-phish - Fake Figma / Canva design file share credential phishing — impersonates Figma, Canva, Adobe XD, or Sketch with a fake "someone shared a design with you" notification requiring Google or Microsoft sign-in on a non-official domain; designers receive legitimate file-share invitations constantly and have been conditioned to click without verifying the sender domain; Proofpoint 2024: Figma impersonation phishing up 300%; Cofense 2024: design-tool lures are the fastest-growing new phishing category in tech industriesthreat
fake-figma-canva-design-file-share-phish - Fake Figma organization / Professional subscription payment failed, design files and team workspace suspended, or FigJam boards at risk phishing — fraudulent email impersonating Figma claiming the organization or Professional subscription payment has failed, design files and team workspace are suspended, component libraries and prototypes are no longer active, or FigJam boards are at risk — Figma: 4M+ paying users ($15/editor/month Starter, $45-75/editor/month Professional/Organization/Enterprise); #1 design tool used by Google, Microsoft, Airbnb, and 90%+ of design teams globally; distinct from fake Figma file-share credential phishing — this targets billing suspension with company-wide design workflow consequences; Figma Organization plan suspension locks all editors out of the entire design workspace, component library, and collaboration infrastructure simultaneouslythreat
fake-figma-organization-subscription-billing-phish - Fake FINRA, SEC, or securities regulator investment fraud recovery phishing — fraudulent email impersonating FINRA, the SEC, CFTC, or another financial regulator claiming the recipient has been identified as an investment fraud victim eligible for a recovery award, settlement, or restitution — directing them to click a link to claim funds, verify their SSN, brokerage account details, or bank routing number to receive their compensationthreat
fake-finra-sec-investment-fraud-recovery-phish - Fake Fiverr / Upwork freelance platform seller account suspended or earnings withheld phishing — fraudulent email impersonating Fiverr, Upwork, or Toptal claiming the recipient's seller account has been suspended for a policy violation, their earnings or pending withdrawals have been withheld, or their active gigs or contracts have been paused — directing them to sign in, verify identity, or appeal to restore access and release earnings; Fiverr: 4M+ active sellers; Upwork: 18M+ registered freelancers; gig workers whose primary income flows through these platforms act immediately on suspension notices; FTC 2024: freelance platform impersonation fraud surged 130% as gig economy adoption grewthreat
fake-fiverr-upwork-freelance-platform-account-phish - Fake Fivetran / Airbyte data pipeline and ETL subscription payment failed, data connectors and sync jobs suspended, warehouse sync disabled, or data pipeline syncs no longer active phishingthreat
fake-fivetran-airbyte-data-pipeline-etl-billing-phish - Fake Fly.io platform credit card failed / app suspended phishing — impersonates Fly.io with payment-failed or app-suspended urgency + update-payment CTA at a non-fly.io host. Proofpoint / Abnormal Security 2025-2026.threat
fake-fly-io-credit-card-failed-billing-phish - Fake Gainsight / ChurnZero customer success platform subscription payment failed, customer health scores and renewal playbooks suspended, churn risk alerts disabled, or NPS surveys at risk phishingthreat
fake-gainsight-churnzero-customer-success-platform-billing-phish - Fake gaming platform free currency reward phishing — unsolicited free V-Bucks/Robux/Game Pass/Steam credit offer + must log in to claim + credential harvesting from Fortnite/Roblox/Xbox/Steam users + legitimate platforms never grant free currency via unsolicited emailthreat
fake-gaming-platform-free-currency-reward-phish - Fake Ghost Pro / Beehiiv / ConvertKit creator newsletter subscription payment failed, subscriber access suspended, or paid memberships and publications at risk phishing — fraudulent email impersonating Ghost, Beehiiv, or ConvertKit claiming the newsletter subscription payment has failed, subscriber access and paid memberships are suspended, or scheduled publications are no longer sending — Ghost Pro: 300K+ paid blogs ($9-199/month); Beehiiv: 50K+ newsletters ($42-84/month Scale/Max); newsletter audience loss urgency — a suspended creator platform severs the relationship between the creator and every subscriber simultaneouslythreat
fake-ghost-substack-creator-newsletter-billing-phish - Fake gig-platform driver / dasher / shopper account deactivation phishing — non-official sender impersonates Uber, Lyft, DoorDash, Instacart, Grubhub, or Shipt threatening permanent deactivation of the recipient's driver or shopper account unless identity documents are verified or the account is re-activated through a fraudulent portal within a tight deadlinethreat
fake-gig-platform-driver-account-deactivation-phish - Fake GitHub Copilot / JetBrains All Products Pack developer tool subscription payment failed, license expired, or IDE switching to read-only mode phishing — fraudulent email impersonating GitHub or JetBrains claiming the recipient's Copilot Business subscription payment has failed, their JetBrains license has expired, or their IDEs (IntelliJ IDEA, PyCharm, WebStorm) will switch to read-only mode — directing them to sign in, renew, or update billing through a credential-harvesting portal; GitHub Copilot: 1.3M+ paid subscribers ($10-19/month; Business $19/seat); JetBrains: millions of paying subscribers ($249/year All Products Pack); developer tool phishing uniquely threatens professional output — "your IDE switches to read-only at midnight" creates extreme urgency; Copilot Business seat management makes team leads prime targetsthreat
fake-github-copilot-jetbrains-developer-tool-subscription-phish - Fake GitHub Enterprise / GitLab Premium / Bitbucket DevOps subscription payment failed, repositories and CI/CD pipelines suspended, or organization access revoked phishing — fraudulent email impersonating GitHub Enterprise, GitLab, or Bitbucket claiming the subscription payment has failed, repositories and pull requests are going offline, or Actions CI/CD pipelines are suspended — distinct from GitHub Copilot developer tool phishing; GitHub Enterprise: 100K+ organizations ($21/seat/month); GitLab: 30M+ users, Premium $29/seat/month; repository suspension means the entire development team simultaneously loses code access, PR review workflows, and automated build pipelinesthreat
fake-github-enterprise-gitlab-devops-subscription-billing-phish - Fake GitHub / GitLab developer account security phishing — impersonates GitHub, GitLab, Bitbucket, or npm claiming unauthorized access, account compromise, or suspended account — driving to a credential-harvest page that captures developer credentials giving access to SSH keys, API tokens, private repos, and CI/CD secrets; Proofpoint 2024: GitHub is the most impersonated developer platform brand; phishing surged 250% after 2023 credential-stuffing campaigns targeting OSS maintainersthreat
fake-github-gitlab-developer-account-security-phish - Fake GitHub / GitLab repository hosting subscription payment failed, organization repositories suspended, enterprise licenses disabled, or repository access no longer active phishingthreat
fake-github-gitlab-repository-hosting-billing-phish - Fake Gong / Chorus revenue intelligence subscription payment failed, call recordings and deal intelligence suspended, or conversation intelligence and pipeline analytics inaccessible phishingthreat
fake-gong-chorus-revenue-intelligence-billing-phish - Fake Google account / Gmail security alert phishing — impersonates Google security notices claiming Google account or Gmail has been locked, suspended, or flagged for unusual activity, driving to a credential-harvest page; Google is the #2 most impersonated brand in consumer credential phishing (APWG Q4 2024); compromised Google credentials unlock Gmail, Drive, Google Pay, and all OAuth-linked servicesthreat
fake-google-account-security-alert-phish - Fake Google account suspicious activity phishing — non-official sender impersonates Google claiming the recipient's Google account or Gmail account has been compromised, locked, suspended, or accessed from an unrecognized device due to suspicious or unauthorized activity, directing them to verify credentials or click a link to secure and restore access through a phishing portalthreat
fake-google-account-suspicious-activity-phish - Fake Google Ads / Google Merchant Center billing suspension phishing — impersonates Google claiming a Google Ads, Google Merchant Center, or Google Shopping account has been suspended due to payment failure or policy violation, driving to a credential- or payment-card-harvest page; SMBs lose thousands per day when Google Ads access is cut; APWG Q4 2024: business platform impersonation phishing surged 38%; Google is consistently in the top-3 most impersonated brandsthreat
fake-google-ads-billing-account-suspended-phish - Fake Google AdSense publisher payment hold or account suspended phishing — fraudulent email impersonating Google AdSense claiming the recipient's AdSense payment has been placed on hold, their publisher account has been suspended for invalid click activity or a policy violation, or publisher identity verification is required to release pending earnings — directing them to sign in to their AdSense account, submit tax forms, or verify identity through a credential-harvesting portal — targeting website publishers and bloggers whose passive income depends on AdSense earnings; legitimate AdSense payment holds and publisher verifications are common events, making fake versions highly believablethreat
fake-google-adsense-publisher-payment-hold-phish - Fake Google One subscription expired or Google One AI Premium payment failed with 2TB storage full, Google Photos backup stopped, and Gemini Advanced suspended phishingthreat
fake-google-one-storage-subscription-billing-phish - Fake Google Play Console developer account suspended, apps removed from Play Store, or in-app purchases disabled phishing — fraudulent email impersonating Google Play Console claiming the developer account has been suspended for a policy violation, Android apps have been removed from the Play Store, or in-app purchases are no longer processing — directing them to sign in and appeal through a credential-harvesting portal; distinct from Apple Developer Program phishing (already covered); Google Play: 3.5M+ Android apps, 2.5M+ developers; app removal cuts off all Play Store revenue and removes the app from every Android device simultaneously — peak urgency for indie developersthreat
fake-google-play-console-developer-account-phish - Fake Google Workspace or Google Admin account suspended or billing failed phishing — fraudulent email impersonating Google Workspace, Google Admin, or GSuite claiming the recipient's workspace account has been suspended, their domain restricted, or their billing has failed — directing them to click a link to verify admin credentials, update payment details, or confirm organization information through a fraudulent portal — a credential-harvesting and financial data theft attack targeting Google Workspace administrators who control organization-wide email, documents, and Google Cloud servicesthreat
fake-google-workspace-admin-account-suspended-phish - Fake government digital ID enrollment phishing — impersonates BankID, GOV.UK One Login, myGovID, FranceConnect, MitID, DigiD, or SPID with mandatory-enrollment urgency + portal-CTA at a non-government host. CISA/ENISA 2025-2026.threat
fake-government-digital-id-enrollment-phish - Fake government tax refund phishthreat
fake-government-tax-refund-scam - Fake Grammarly Premium / SEMrush Pro / Ahrefs professional writing or SEO tool subscription payment failed, account suspended, or keyword data at risk phishing — fraudulent email impersonating Grammarly, SEMrush, Ahrefs, or Moz claiming the recipient's professional tool subscription payment has failed, their account has been suspended, their premium writing features or keyword research data are no longer accessible, or an unauthorized charge was detected — directing them to update billing, restore access, or sign in through a credential-harvesting portal; Grammarly 30M+ daily active users with 1M+ Premium/Business subscribers ($12-15/month); SEMrush 10M+ registered users with 1M+ paying subscribers ($119-449/month); Ahrefs 500K+ subscribers ($99-999/month); Moz 500K+ subscribers; professional tool account compromise gives attackers access to writing documents, SEO strategy data, competitor intelligence, and linked Google/Microsoft credentialsthreat
fake-grammarly-semrush-professional-tool-subscription-phish - Fake Greenhouse / Lever ATS subscription payment failed, job postings suspended, applicant pipeline inaccessible, or hiring pipeline halted phishingthreat
fake-greenhouse-lever-applicant-tracking-billing-phish - Fake Grok / xAI subscription suspended or xAI API access revoked or Grok AI features disabled due to billing failure phishingthreat
fake-grok-xai-subscription-billing-phish - Fake Gusto / BambooHR / Paychex US small business HR and payroll platform subscription payment failed, payroll will not be processed, or employee records and direct deposit suspended phishing — fraudulent email impersonating Gusto, BambooHR, or Paychex claiming the subscription payment has failed, payroll will not be processed and employees will not be paid, direct deposit is suspended, or employee records and HR workflows are no longer active — Gusto: 300K+ small businesses ($6-80/month + $4-12/employee), covers payroll + benefits + HR; BambooHR: 30K+ companies; Paychex: millions of SMB customers; distinct from Deel/Rippling global payroll phishing — targets US domestic SMB HR/payroll; payroll suspension is the highest-urgency billing failure hook possible — employees do not receive paychecks, creating immediate legal employment liabilitythreat
fake-gusto-bamboohr-us-hr-payroll-billing-phish - Fake HCP Terraform / HashiCorp Vault subscription payment failed, infrastructure automation and remote state suspended, or secrets management and dynamic credentials offline phishing — fraudulent email impersonating HashiCorp Terraform Cloud or HCP Vault claiming the subscription payment has failed, infrastructure workspace runs and remote state management are suspended, or Vault dynamic secrets and application credentials are no longer active — HCP Terraform Plus: $20/user/month; HCP Vault: $0.03-0.07/hr; infrastructure automation suspension blocks all deployment pipelines; Vault suspension takes all application secrets offline simultaneouslythreat
fake-hashicorp-terraform-cloud-infrastructure-billing-phish - Fake HashiCorp Vault / Terraform Cloud infrastructure and secrets management subscription payment failed, licenses no longer active, workspace access suspended, or infrastructure access disabled phishingthreat
fake-hashicorp-vault-terraform-cloud-infra-billing-phish - Fake health insurance open enrollment or COBRA continuation phishing — fraudulent email impersonating an employer benefits portal, COBRA administrator, or ACA marketplace claiming the recipient's open enrollment period is ending, their COBRA coverage is expiring, or their health coverage will lapse — directing them to click a link to enroll, verify identity, provide SSN, or update payment information to continue coverage — a credential-harvesting and personal information fraud targeting employees during enrollment periodsthreat
fake-health-insurance-open-enrollment-cobra-phish - Fake health insurance enrollment / PII harvest scam — $0 premium ACA/Obamacare plan + government subsidy + you qualify + provide SSN/Medicare ID to enroll + urgent deadline + identity theft setupthreat
fake-health-insurance-plan-pii-harvest-scam - Fake Heap / PostHog product analytics subscription payment failed, event tracking suspended, session replay disabled, feature flags deactivated, or A/B tests disabled phishingthreat
fake-heap-posthog-product-analytics-billing-phish - Fake HelloFresh / Blue Apron / Green Chef / Factor meal kit subscription payment failed, delivery paused, or subscription cancelled phishing — fraudulent email impersonating HelloFresh, Blue Apron, Green Chef, or Factor claiming the recipient's meal kit subscription payment has failed, their upcoming delivery has been paused, or their subscription has been cancelled — directing them to update billing, reactivate the subscription, or verify payment through a credential-harvesting portal; HelloFresh 7M+ active customers (world's largest meal kit company); Factor 1M+; EveryPlate 1M+; Green Chef 500K+; meal kit subscriptions bill weekly and customers regularly manage pauses/restarts — billing failure lures are frequent and expected; a missed meal kit delivery creates immediate household planning urgency (no dinner for the week), pressuring rapid action without sender verificationthreat
fake-hellofresh-blue-apron-meal-kit-subscription-phish - Fake helpdesk — IT impersonation + credential reset/verification demandthreat
fake-helpdesk-credential-harvest - Fake Heroku / Railway / Render / Fly.io app deployment platform subscription payment failed, dynos or deployments suspended, or apps offline phishing — fraudulent email impersonating Heroku, Railway, Render, or Fly.io claiming the subscription payment has failed, dynos are suspended, app deployments are no longer active, or web services are offline — Heroku: 13M+ registered developers, millions of deployed apps ($5-500+/month); Railway: 500K+ active users ($5-20/month), widely adopted by indie developers and startups; Render: 500K+ users; distinct from Vercel/Netlify frontend platform phishing — targets backend/full-stack deployment; a single dyno suspension takes production applications offline, exposing live users to 503 errors and breaking API endpoints, webhooks, and cron jobs simultaneouslythreat
fake-heroku-railway-app-deployment-platform-billing-phish - Fake Hertz / Enterprise / Avis car rental account suspended, unauthorized charge dispute, or rental damage charge phishing — fraudulent email impersonating Hertz, Enterprise Rent-A-Car, Avis, National, or Budget claiming an unauthorized charge was detected on the recipient's rental loyalty account, their account has been suspended, or a damage charge requires dispute — directing them to sign in, verify identity, or confirm payment details through a phishing portal; Hertz Gold Plus Rewards 32M+ members; Enterprise Emerald Club 17M+; Hertz's 2025 data breach (Cleo file transfer compromise, 9.5M+ customers) provides attackers a plausible breach notification pretext; variable car rental charges (damage assessments, late fees, fuel charges) make unauthorized-charge lures highly believablethreat
fake-hertz-enterprise-car-rental-account-phish - Fake HeyGen or Synthesia AI avatar video subscription suspended — Creator or Business plan payment failed, AI video generation credits revoked, talking avatar access blocked due to billing failure phishingthreat
fake-heygen-synthesia-ai-avatar-video-subscription-billing-phish - Fake hitman / contract-kill extortion scam — claims the sender was paid to kill or harm the recipient but offers to "call off" the contract for $2,000–$5,000 in Bitcoin; completely fabricated but causes extreme distress; FBI IC3 2022: 84,000+ extortion/blackmail complaints totalling $107M; consistently top-3 FBI extortion typethreat
fake-hitman-contract-kill-extortion-scam - Fake hospital / medical debt collection payment phishing — non-healthcare sender impersonates a medical billing department or debt collection agency claiming an overdue hospital, doctor, or patient balance that will be sent to collections and damage the victim's credit score unless paid immediately via a fraudulent portalthreat
fake-hospital-medical-debt-collection-payment-phish - Fake Booking.com guest payment re-verification phishing — abuses hacked hotel Booking.com accounts to send payment-reverification requests from the legitimate booking.com domain, directing to a fraudulent card-entry page with reservation-cancellation urgency. NCA / Booking.com advisory 2025-2026; Abnormal Security hospitality-phish Q1 2026.threat
fake-hotel-booking-guest-payment-reverification-phish - Fake Hotjar / FullStory session recording and heatmap subscription payment failed, session recordings and heatmaps suspended, or replays and UX analytics inaccessible phishingthreat
fake-hotjar-fullstory-session-recording-billing-phish - Fake HR / payroll W-2 or 1099 tax form credential phishing — fraudulent email impersonating an HR department, payroll provider, or accounting system claiming an employee's W-2, 1099, or year-end tax form is available or that direct deposit details need updating — directing them to click a link and log in with credentials, provide SSN, or verify bank routing numbers to access their tax documents — a spear-phishing attack that harvests employee login credentials, SSNs, and banking detailsthreat
fake-hr-w2-employee-tax-form-credential-phish - Fake HubSpot CRM and marketing automation portal suspended, contact database disabled, or Marketing Hub access revoked due to subscription payment failure phishingthreat
fake-hubspot-crm-marketing-automation-billing-phish - Fake HubSpot / Salesforce / Zoho CRM account suspended or data export phishing — fraudulent email impersonating HubSpot, Salesforce, Zoho CRM, or Pipedrive claiming the recipient's CRM account has been suspended, their Salesforce license is expiring with data at risk, a data export is ready requiring sign-in, or unusual access was detected — directing them to sign in to verify, restore access, or download their data — a credential-harvesting attack giving attackers access to ALL customer contact records, deal pipelines, and sales communications; HubSpot: 216,000+ customers; Salesforce: 150,000+ customers; CRM access enables follow-on BEC attacks and contact database theftthreat
fake-hubspot-salesforce-crm-account-phish - Fake HubSpot / Salesforce / Zendesk CRM subscription payment failed, sales pipeline suspended, or marketing automation disabled phishing — fraudulent email impersonating HubSpot, Salesforce, or Zendesk claiming the subscription payment has failed, the CRM and sales pipeline are suspended, or marketing automation and email sequences are disabled — distinct from account-suspended/data-export phishing; HubSpot: 216K+ customers ($45-3,200/month Marketing Hub); Salesforce: 150K+ customers ($25-500/user/month); CRM suspension during quarter-close means sales team loses visibility into every active deal simultaneouslythreat
fake-hubspot-salesforce-crm-subscription-billing-phish - Fake iCloud storage full or Apple ID locked credential phishing — fraudulent email impersonating Apple or iCloud claiming the recipient's iCloud storage is full, backups have stopped, their Apple ID has been locked, or their account will be disabled — directing them to click a link to verify their Apple ID credentials, update billing, or upgrade their storage plan — a credential-harvesting phishing attack targeting the hundreds of millions of Apple device owners worldwidethreat
fake-icloud-storage-account-locked-credential-phish - Fake Indeed / Glassdoor / ZipRecruiter job board account suspended, locked, or unauthorized access phishing — fraudulent email impersonating Indeed, Glassdoor, or ZipRecruiter claiming the recipient's job board account has been suspended for suspicious activity, their profile and resume are no longer visible to employers, or unauthorized access was detected — directing them to sign in, verify identity, or complete employment verification through a credential-harvesting portal; Indeed 350M+ registered users (world's #1 job site); Glassdoor 60M+ monthly users; ZipRecruiter 12M+ active job seekers; job board accounts contain uploaded resumes with SSN, home address, employment history, and salary information; employment anxiety makes users act immediately on account-suspension threats during any job searchthreat
fake-indeed-glassdoor-job-board-account-phish - Fake Instagram / Facebook copyright strike account phishing — DMCA/copyright infringement notice threatening account deletion unless credentials submitted to "appeal" + sender is never @instagram.com or @facebookmail.com + real Meta copyright actions happen in-app with no credential re-entrythreat
fake-instagram-facebook-copyright-strike-account-phish - Fake Intercom / Drift customer messaging workspace suspended, live chat offline, chatbot disabled, or support inbox inaccessible due to subscription payment failure phishingthreat
fake-intercom-drift-customer-messaging-billing-phish - Fake Intercom / Freshdesk / Help Scout customer support platform subscription payment failed, support inbox and live chat suspended, or helpdesk tickets inaccessible phishing — fraudulent email impersonating Intercom, Freshdesk, or Help Scout claiming the subscription payment has failed, customer messaging and support inbox are suspended, or helpdesk tickets and conversations are no longer active — Intercom: 25K+ paying customers ($74-374/month Essential/Advanced/Expert); Freshdesk: 50K+ customers ($18-95/agent/month); customer support suspension means every inbound customer request goes unanswered — the support inbox fills but agents cannot access or respond, creating visible customer-facing SLA failuresthreat
fake-intercom-freshdesk-customer-support-platform-billing-phish - Fake vendor impersonating a known supplier with an attached invoice due immediately and a claim that banking details have changed — BEC payment-diversion fraud; real vendor banking-detail changes are authenticated out-of-band, never via cold email with "process payment to the following account."threat
fake-invoice-vendor-payment-phish - Fake IRS audit notice phishingthreat
fake-irs-audit-notice-phish - Fake IRS statutory notice of deficiency claiming failure to respond within 30 days will trigger automatic tax assessment and instructing the target to call immediately to dispute — IRS impersonation fraud; the real IRS sends deficiency notices by certified postal mail, never by email.threat
fake-irs-cp3219-deficiency-phish - Fake IRS tax refund deposit phishing — non-official sender falsely claims the recipient has an approved, pending, or expiring federal tax refund and requests bank account number, routing number, or direct deposit details to "process" the deposit, or links to a credential-harvesting portal impersonating the IRS or U.S. Treasurythreat
fake-irs-tax-refund-deposit-phish - Fake IRS tax refund or overdue tax notice phishing — fraudulent email impersonating the IRS or Internal Revenue Service claiming a tax refund is available, a tax overpayment has been detected, or outstanding back taxes are owed — directing the recipient to click a link to verify identity and claim a refund, provide bank routing and SSN details for direct deposit, or call an IRS officer immediately to avoid levy or arrest warrantthreat
fake-irs-tax-refund-overdue-phish - Fake ISO 42001 / NIST AI RMF compliance consultant phishing — impersonates an AI-governance auditor offering gap analysis, compliance certification, or AI risk framework assessment with a booking CTA at a non-official domain. ENISA 2026; SANS ISC Q1 2026 AI-compliance-consultant-spam surge.threat
fake-iso42001-nist-ai-audit-consultant-phish - Fake Jasper / Copy.ai / Writesonic AI writing tool subscription payment failed, AI content generation suspended, brand voice templates inaccessible, or AI copywriting and marketing content disabled phishingthreat
fake-jasper-copyai-ai-writing-tool-billing-phish - Fake Kajabi / Teachable / Thinkific / Podia creator course platform subscription payment failed, online courses and student access suspended, or community and digital products at risk phishing — fraudulent email impersonating Kajabi, Teachable, Thinkific, or Podia claiming the subscription payment has failed, online courses and student access are suspended, course revenue and enrollments are no longer active, or the course platform will be shut down — Kajabi: 75K+ creators ($149-399/month Basic/Growth/Pro); Teachable: 100K+ creators ($59-499/month Basic/Pro/Business); Thinkific: 50K+ creators ($49-499/month Basic/Start/Grow/Expand); course platform suspension cuts off all student access simultaneously — creators lose both new enrollments and access to existing paying students, creating SLA violations and refund demandsthreat
fake-kajabi-teachable-creator-course-platform-billing-phish - Fake Klarna / Afterpay / Affirm Buy Now Pay Later account suspended, installment payment failed, or unauthorized purchase phishing — fraudulent email impersonating Klarna, Afterpay, Affirm, or Sezzle claiming the recipient's BNPL account has been suspended due to an overdue payment, their installment plan is on hold with orders at risk of cancellation, or an unauthorized purchase was detected — directing them to sign in, pay their overdue balance, update payment information, or dispute the purchase through a credential-harvesting portal; Klarna 85M+ active consumers globally ($20B in annual transactions); Afterpay 20M+ active customers ($20B+ GMV); Affirm 18M+ active consumers; BNPL creates a unique urgency vector: active orders in progress may be cancelled if payment fails — a shopper who just purchased electronics or clothing feels immediate loss pressure beyond simple account access; BNPL accounts hold bank account details (often ACH-linked for installments), credit/debit cards, purchase history, and SSN for credit checksthreat
fake-klarna-afterpay-affirm-bnpl-account-phish - Fake Klaviyo / Attentive e-commerce email and SMS marketing subscription payment failed, email flows suspended, abandoned cart emails no longer sending, or SMS campaigns paused phishingthreat
fake-klaviyo-attentive-ecommerce-email-sms-marketing-billing-phish - Fake Lattice / Culture Amp performance management subscription payment failed, performance review cycle suspended, OKRs and employee surveys inaccessible, or employee data at risk phishingthreat
fake-lattice-culture-amp-performance-management-billing-phish - Fake LaunchDarkly / Split.io feature flag management subscription payment failed, feature flags and kill switches suspended, feature rollouts disabled, or A/B tests no longer active phishingthreat
fake-launchdarkly-split-feature-flag-management-billing-phish - Fake Lemonade / Trupanion / ASPCA pet insurance or renters insurance payment failed, policy lapsed, or coverage suspended phishing — fraudulent email impersonating Lemonade, Trupanion, ASPCA Pet Insurance, or Healthy Paws claiming the recipient's pet insurance or renters insurance payment has failed, their policy has lapsed, their pet is no longer covered, or a pending claim has been placed on hold pending account verification — directing them to update billing, reinstate coverage, or verify identity through a credential-harvesting portal; Lemonade 2M+ policyholders (covers both renters and pet insurance; $9-25/month); Trupanion 1M+ enrolled pets ($65-100/month premium); ASPCA Pet Insurance 700K+; Nationwide Pet 1M+; pet insurance phishing creates medical-urgency-for-pets: "your Trupanion coverage has lapsed and your upcoming vet visit will not be reimbursed" threatens pet health costs the owner is expecting to be covered, particularly powerful for owners managing chronic pet conditions with regular treatment schedulesthreat
fake-lemonade-trupanion-insurtech-insurance-billing-phish - Fake Linear / Basecamp project management subscription payment failed, workspace and issues suspended, or projects and team messaging inaccessible phishing — fraudulent email impersonating Linear or Basecamp claiming the subscription payment has failed, the workspace is suspended, issues and projects are no longer accessible, or team messaging and to-do lists are inaccessible — Linear: 150K+ users ($8-16/user/month), the dominant project management tool for high-growth startups (used by Vercel, Notion, Loom, OpenAI, Mercury); Basecamp: 100K+ teams ($99/month flat), the go-to for remote-first and agency teams; distinct from Monday/Asana/ClickUp billing phishing — targets developer-centric and startup-focused PM tools; Linear workspace suspension blocks issue tracking, sprint planning, and engineering roadmap visibility simultaneously for all team membersthreat
fake-linear-basecamp-project-management-billing-phish - Fake Linear / Notion productivity workspace subscription payment failed, workspace members suspended, team pages disabled, or workspace access no longer active phishingthreat
fake-linear-notion-productivity-workspace-billing-phish - Fake Linear team workspace billing suspension phishing — impersonates Linear with a workspace-suspended or subscription-cancelled urgency + billing-update CTA at a non-linear.app host. Proofpoint 2025-2026.threat
fake-linear-team-workspace-billing-phish - Fake LinkedIn connection request, pending connections, or account restricted phishing — impersonates LinkedIn from a non-LinkedIn domain with fake "X sent you a connection request", "N pending connections", or "your account has been restricted" emails driving to a fake LinkedIn login page; Check Point 2024: LinkedIn is the most impersonated brand globally (52% of all brand phishing); Vade Secure 2024: LinkedIn impersonation grew 232% YoY; targets sales and networking professionals conditioned to click connection notifications instantlythreat
fake-linkedin-connection-request-credential-phish - Fake LinkedIn job offer credential phishing — non-LinkedIn sender impersonates LinkedIn job alerts/InMail to harvest LinkedIn credentials, Social Security Number, bank account details, or government ID under guise of job application/onboardingthreat
fake-linkedin-job-offer-credential-phish - Fake LinkedIn Premium subscription payment failed or account suspended phishing — fraudulent email impersonating LinkedIn claiming the recipient's LinkedIn Premium Career, Sales Navigator, Recruiter Lite, or LinkedIn Learning subscription payment has failed, their account has been suspended, or their Premium benefits have been restricted — directing them to sign in, update billing information, or restore their Premium subscription through a credential-harvesting portal — distinct from LinkedIn account compromise phishing; LinkedIn has 900M+ users with 39M+ Premium subscribers paying $39.99–$119.99/month; suspending Premium access removes InMail credits, profile insights, advanced candidate search, and LinkedIn Learning — high urgency for job seekers and sales professionalsthreat
fake-linkedin-premium-subscription-billing-phish - Fake LinkedIn recruiter credential-harvest lure — "Senior Executive at Goldman Sachs sent you a LinkedIn InMail about a $250K role, sign in to view" targeting LinkedIn 1B+ user base; post-2024-2026 tech-layoff job-market anxiety amplifies conversion; LinkedIn credentials harvest enables connections export, Sales Navigator data exfil, DM harvest, fake-offer hijack to victim's networkthreat
fake-linkedin-recruiter-credential-lure - Fake Looker / Metabase BI and analytics platform subscription payment failed, Looks and dashboards suspended, LookML models inaccessible, dashboards and questions disabled, or scheduled reports no longer running phishingthreat
fake-looker-metabase-bi-analytics-platform-billing-phish - Fake loyalty or reward points expiring phishing — fraudulent email impersonating an airline frequent flyer program, hotel loyalty program, credit card rewards account, or generic rewards platform claiming the recipient's miles, points, or rewards are expiring soon or have been forfeited — directing them to click a link, log in, or verify account details to claim, redeem, or save their points before they are cancelled — a credential-harvesting phishing attack exploiting urgency around loyalty program balancesthreat
fake-loyalty-reward-points-expiring-phish - Fake Lucidchart / Lucidspark diagramming and whiteboard subscription payment failed, team diagrams inaccessible, or shared boards and content suspended phishingthreat
fake-lucidchart-lucidspark-diagramming-billing-phish - Fake Mailchimp / ConvertKit / Klaviyo email marketing account suspended phishing — fraudulent email impersonating Mailchimp, ConvertKit, Klaviyo, or Constant Contact claiming the recipient's account has been suspended for spam complaints or a policy violation, their sending has been paused, or their payment failed — directing them to sign in, appeal the suspension, or verify their account to restore email marketing access — a credential-harvesting attack targeting businesses whose revenue depends on email marketing; Mailchimp has 14M+ active users; a sending suspension means immediate loss of campaigns, cart abandonment emails, and customer communicationsthreat
fake-mailchimp-email-marketing-account-suspended-phish - Fake Mailchimp email marketing account suspended, audience disabled, campaign sending halted, or subscriber list inaccessible due to billing failure phishingthreat
fake-mailchimp-email-marketing-audience-billing-phish - Fake major US bank account suspended phishing — non-official sender impersonates Chase, Wells Fargo, Bank of America, Citibank, Capital One, or another major bank falsely claiming the recipient's account has been suspended, locked, frozen, or restricted due to suspicious or unauthorized activity, and directing them to click a link to verify their identity or restore access through a credential-harvesting portalthreat
fake-major-us-bank-account-suspended-phish - Fake Marriott Bonvoy / Hilton Honors / IHG One Rewards hotel loyalty account suspended, unauthorized booking, or points drained phishing — fraudulent email impersonating Marriott Bonvoy, Hilton Honors, IHG One Rewards, or World of Hyatt claiming an unauthorized hotel reservation was made on the recipient's loyalty account, the account has been suspended for suspicious activity, or loyalty points have been redeemed without authorization — directing them to sign in, verify identity, or dispute the booking through a credential-harvesting portal; Marriott Bonvoy 200M+ members; Hilton Honors 180M+; IHG One Rewards 110M+; World of Hyatt 42M+; loyalty accounts store payment cards, passport data, and corporate billing codes; 2022 Marriott breach exposed 5.2M accounts; hotel points are actively monetized on dark web markets at $3-15 per accountthreat
fake-marriott-bonvoy-hilton-honors-hotel-loyalty-account-phish - Fake Matter smart-home firmware credential harvest — impersonates Nest, Philips Hue, Aqara, SmartThings, or Amazon Echo with a "mandatory Matter/Thread firmware update requires account re-authentication" hook harvesting cloud credentials. Bitdefender Mar 2026; Malwarebytes Jan 2026; CISA 2026.threat
fake-matter-smart-home-firmware-credential-harvest - Fake Medallia / Qualtrics CX and experience management platform subscription payment failed, platform licenses suspended, surveys and feedback programs disabled, or experience management access no longer active phishingthreat
fake-medallia-qualtrics-cx-experience-management-billing-phish - Fake medical AI diagnosis report phishing — impersonates Epic MyChart AI, Amazon Health, or Babylon Health claiming an "AI-detected abnormality" to harvest patient portal credentials or payment details. Cofense Mar 2026; HHS OCR advisory Mar 2026; Abnormal Security Q1 2026.threat
fake-medical-ai-diagnosis-report-phish - Fake medical alert device free Medicare harvest scam — free medical alert/fall detection/diabetic supplies/brace "covered by Medicare" + must provide Medicare ID number or date of birth + targets seniors for identity theft and fraudulent insurance billingthreat
fake-medical-alert-device-free-medicare-harvest-scam - Fake Medicare or Medicaid benefit suspension, card expiry, or enrollment phishing — fraudulent email impersonating CMS, Medicare, or a Medicaid agency claiming the recipient's Medicare card has expired, their Medicaid benefit is suspended, or their coverage will be terminated — directing them to click a link to verify their Medicare beneficiary number, SSN, date of birth, or bank account to renew coverage or receive a replacement cardthreat
fake-medicare-medicaid-benefits-phish - Fake Meta or Facebook Ads account suspended phishing — fraudulent email impersonating Meta Business, Facebook Ads Manager, or Meta Business Suite claiming the recipient's ad account has been suspended, restricted, or flagged for a policy violation — directing them to click a link to appeal, verify their identity, or provide business and payment information to reactivate — a high-damage attack targeting businesses and marketers whose revenue depends on active Facebook advertisingthreat
fake-meta-facebook-ads-account-suspended-phish - MFA fatigue / push-bombing phish — attacker spams the victim with MFA approval prompts and emails them claiming the pending Microsoft/Okta/Duo push must be approved to stop the codes, taking over the account when the victim caves (Uber 2022, heavy M365/Okta campaigns 2024-26)threat
fake-mfa-fatigue-push-bombing-phish - Fake Microsoft 365 / Office 365 license expiry billing phishing — non-Microsoft sender claims the recipient's Microsoft 365 or Office 365 subscription has expired or will expire imminently and that access to email, OneDrive, Teams, Word, or Excel will be lost unless payment details are updated or verified immediatelythreat
fake-microsoft-365-license-expiry-billing-phish - Fake Microsoft 365 / Office 365 account expiry or compromise phishing — fraudulent email impersonating Microsoft 365, Office 365, SharePoint, or OneDrive claiming the recipient's account is expiring, suspended, compromised, or that their storage quota is exceeded — directing them to click a link to sign in, verify credentials, update account details, or re-authenticate to prevent deactivation — a credential-harvesting phishing attack targeting enterprise Microsoft 365 accountsthreat
fake-microsoft-365-oauth-consent-phish - Fake Microsoft 365 / Office 365 / Teams account suspended phishing — impersonates Microsoft security notices claiming account is suspended, password expired, or unusual sign-in detected, driving to a credential-harvest page; Microsoft is the #1 most impersonated brand in business email phishing (APWG 2024); FBI IC3 2023: Microsoft-impersonation BEC caused $2.9B in lossesthreat
fake-microsoft-365-office-account-phish - Fake Microsoft 365 / Office 365 password expiry or account locked credential phishing — non-official sender impersonates Microsoft claiming the recipient's Microsoft 365, Office 365, or Outlook account password is expiring, expired, or the account is locked or sign-in has been blocked, directing them to click a link to reset their password or verify credentials through a credential-harvesting portalthreat
fake-microsoft-365-password-expiry-credential-phish - Fake Microsoft 365 / Office 365 quarantine digest message-release phishing — fraudulent email impersonating Microsoft 365, Office 365, Exchange Online, or Microsoft Defender for Office 365 claiming the recipient has N quarantined messages requiring release, their email delivery is on hold, or messages have been blocked — directing them to click "release messages" or sign in to review quarantined email — a credential-harvesting attack exploiting the genuine Microsoft 365 quarantine digest workflow that employees receive daily; Cofense 2024: quarantine-release phishing is a top-3 enterprise credential harvest vector; M365 has 300M+ monthly active usersthreat
fake-microsoft-365-quarantine-message-release-phish - Fake Microsoft account unusual sign-in / suspension phishthreat
fake-microsoft-account-unusual-signin-phish - Fake Microsoft / Google account phishthreat
fake-microsoft-google-account-phish - Fake Midjourney / Runway ML AI image and video generation subscription suspended, fast GPU hours depleted, Gen-3 video credits expired, or image generation access blocked due to billing failure phishingthreat
fake-midjourney-runway-ai-image-video-billing-phish - Fake Miro / Figma design and collaboration tool subscription payment failed, workspace licenses no longer active, team access suspended, or design file access disabled phishingthreat
fake-miro-figma-design-tool-collaboration-billing-phish - Fake Miro / Mural / Lucidchart visual collaboration or whiteboard subscription payment failed, boards and team workspace suspended, or diagrams inaccessible phishing — fraudulent email impersonating Miro, Mural, or Lucidchart claiming the subscription payment has failed, visual boards and collaborative whiteboards are suspended, or diagrams and team facilitation sessions are no longer active — Miro: 60M+ users, 200K+ paying ($10-20/member/month Team/Business); Mural: 35M+ users, enterprise-focused ($17.99-24.99/member/month); Lucidchart: 30M+ users ($7.95-20/user/month); visual workspace suspension locks all team members out of shared boards simultaneously — in-progress design sprints, architecture diagrams, and retrospective sessions go darkthreat
fake-miro-mural-visual-collaboration-billing-phish - Fake Mixpanel / Amplitude / Segment product analytics subscription payment failed, event tracking suspended, or customer data platform disabled phishing — fraudulent email impersonating Mixpanel, Amplitude, or Segment claiming the subscription payment has failed, event tracking and funnel analytics are no longer active, or the customer data pipeline to analytics destinations is suspended — directing them to update billing or restore analytics access through a credential-harvesting portal; Mixpanel: 30K+ paying customers ($20-833/month Growth/Enterprise); Amplitude: 2,000+ enterprise customers ($61-2,000+/month); losing analytics means product teams are unable to track user behavior, measure feature adoption, or validate A/B experiment results during active product releasesthreat
fake-mixpanel-amplitude-analytics-platform-billing-phish - Fake mobile carrier SIM swap / account takeover phishing — non-carrier sender impersonates AT&T, Verizon, or T-Mobile claiming an unauthorized SIM swap or port-out is in progress and demands account PIN or Social Security Number to "cancel" the transferthreat
fake-mobile-carrier-sim-swap-account-takeover-phish - Fake Monday.com / Asana / ClickUp project management subscription payment failed, workspace suspended, or team boards inaccessible phishing — fraudulent email impersonating Monday.com, Asana, or ClickUp claiming the subscription payment has failed, team workspace is suspended, or boards and projects are no longer accessible — distinct from workspace-share phishing; Monday.com: 225K+ customers ($9-19/seat/month); Asana: 126K+ paying organizations ($13.49/seat/month); ClickUp: 800K+ teams; workspace suspension affects every team member simultaneously, creating organizational pressure that reaches billing admin through escalationthreat
fake-monday-asana-clickup-project-management-billing-phish - Fake bounce/NDR with phishing link from non-system senderthreat
fake-ndr-phishing - Fake Netflix / Hulu / Disney+ / Spotify streaming service payment-failed phishing — fake billing-failure notice from a streaming brand urges victim to update payment details via a link harvesting card or streaming credentials; Netflix is the #3 most impersonated brand (APWG Q4 2024); FTC 2024: subscription service impersonation is a top-10 phishing lurethreat
fake-netflix-streaming-service-payment-failed-phish - Fake NFT whitelist / mint wallet-drain phishing — fraudulent email claims the recipient's wallet has been whitelisted or allowlisted for an exclusive NFT mint, presale drop, or free NFT claim, then directs them to connect MetaMask, Trust Wallet, or Phantom to a malicious portal that drains all crypto and NFTs via a malicious smart contract; some variants request the seed phrase directlythreat
fake-nft-whitelist-mint-wallet-drain-phish - Fake Noom / Weight Watchers WW / Jenny Craig health coaching subscription payment failed, program access suspended, or coaching access revoked phishing — fraudulent email impersonating Noom, WW (Weight Watchers), Jenny Craig, or Optavia claiming the recipient's health program subscription payment has failed, their personalized meal plan and coach access are suspended, or their tracked progress is at risk — directing them to update billing, continue their program, or protect their progress through a credential-harvesting portal; Noom 4M+ subscribers ($60-199/program); WW/Weight Watchers 4.5M+ subscribers ($25-55/month); creates health-journey-interruption urgency — users mid-program fear losing momentum, coaching relationship, and months of tracked data; accounts contain detailed health data including weight history, food logs, biometric goals, and health coach communication recordsthreat
fake-noom-weightwatchers-health-coaching-subscription-phish - Fake Notion / Airtable / Monday.com workspace share credential phishing — impersonates Notion, Airtable, Monday.com, or Asana with a fake "someone shared a page/base/board with you" notification requiring Google or Microsoft 365 sign-in on a non-official domain; Cofense 2024: productivity-tool impersonation is a top-5 credential-phishing vector in SaaS-heavy organizations; workspace access gives attackers full company knowledge base, project plans, and connected app tokensthreat
fake-notion-airtable-workspace-share-phish - Fake Notion / Coda workspace subscription payment failed, workspace and team pages inaccessible, or team wikis and databases suspended phishingthreat
fake-notion-coda-workspace-subscription-billing-phish - Fake New York Times / Wall Street Journal / Washington Post digital news subscription payment failed, access suspended, or account locked phishing — fraudulent email impersonating NYT, WSJ, Washington Post, The Athletic, or The Economist claiming the recipient's digital subscription payment has failed, their article access has been suspended, or an unauthorized charge was detected — directing them to update billing, restore access, or sign in through a credential-harvesting portal; New York Times 10M+ digital subscribers ($17-25/month All Access); Wall Street Journal 3.6M+ digital subscribers ($38.99/month); Washington Post 3M+; The Athletic 3M+ ($12.99/month); The Economist 1.5M+ digital; news subscription phishing peaks during major news cycles when professional readers are most dependent on access — business professionals, lawyers, and journalists who lose WSJ access during earnings season face professional consequences that override normal verification behaviorthreat
fake-nytimes-wsj-digital-news-subscription-account-phish - OAuth illicit consent grant phish — email masquerades as a Google Docs / Microsoft 365 / DocuSign / Dropbox share and asks the victim to authorize a third-party OAuth app that silently grants attacker persistent mailbox read/send access (Microsoft Digital Defense Report 2025 identified this as the fastest-growing enterprise phishing vector)threat
fake-oauth-illicit-consent-grant-phish - Fake Okta / Azure AD / OneLogin SSO identity provider credential phishing — fraudulent email impersonating Okta, Azure Active Directory, Microsoft Entra ID, or OneLogin claiming the recipient's SSO account has been suspended, session has expired requiring re-authentication, or MFA authenticator needs to be re-enrolled — directing them to sign in through a spoofed identity provider portal to harvest their SSO credentials — the "master key" attack that unlocks every enterprise application at once; Okta serves 18,000+ enterprise customers; APWG 2024: IdP phishing grew 340% YoY; a single Okta credential gives attackers access to email, Slack, GitHub, Salesforce, Jira, and every other SSO-connected app simultaneouslythreat
fake-okta-sso-identity-provider-credential-phish - Fake OpenAI API / Anthropic Claude API subscription payment failed, API keys suspended, AI features no longer active, GPT-4 access revoked, or production apps will lose AI access phishingthreat
fake-openai-anthropic-ai-api-billing-phish - Fake NFT bid / offer notification phish — email impersonates OpenSea, Blur, or Magic Eden with a fake "you received a bid" or "your listing sold" hook, directing to a drainer dApp for ERC-20 approval or seed-phrase entry. Chainalysis 2026; Certik Q1 2026.threat
fake-opensea-blur-nft-bid-notification-phish - Fake Outreach.io / SalesLoft sales engagement platform subscription payment failed, sales sequences and cadences suspended, meeting booking disabled, or sequence enrollment paused phishingthreat
fake-outreach-salesloft-sales-engagement-platform-billing-phish - Fake P2P payment account alert phishthreat
fake-p2p-payment-account-alert-phish - Fake package delivery / customs fee phishing — non-carrier sender impersonates USPS, FedEx, UPS, DHL, or Amazon claiming a package is on hold or pending customs clearance and requires immediate payment of a small customs, handling, or rescheduling fee ($1–$5) to release delivery; the payment portal harvests full credit card details for large unauthorized chargesthreat
fake-package-delivery-redelivery-customs-fee-phish - Fake package delivery redelivery fee phishing — non-official sender impersonates UPS, FedEx, USPS, DHL, or another carrier falsely claiming the recipient's package could not be delivered, is on hold at customs, or requires a fee payment to reschedule delivery, directing them to a phishing site to pay a small "customs fee" or "redelivery fee" that harvests payment card detailsthreat
fake-package-delivery-redelivery-fee-phish - Fake PagerDuty / Opsgenie incident management and on-call scheduling subscription payment failed, licenses no longer active, on-call schedules disabled, or incident management access suspended phishingthreat
fake-pagerduty-opsgenie-incident-management-billing-phish - Fake Palo Alto Networks / Fortinet network security platform subscription payment failed, licenses suspended, firewall and endpoint protection disabled, or FortiCare support suspended phishingthreat
fake-paloalto-fortinet-network-security-billing-phish - Fake PandaDoc / Proposify proposal and contract management subscription payment failed, pending proposals and contracts suspended, document templates inaccessible, or electronic signatures at risk phishingthreat
fake-pandadoc-proposify-proposal-contract-platform-billing-phish - Fake parking violation / parking fine payment phishing — non-government sender impersonates a municipal parking authority or enforcement department claiming an unpaid parking citation that will incur late fees, vehicle boot/impound, or license plate/registration suspension unless paid immediately via a fraudulent portalthreat
fake-parking-violation-fine-payment-phish - Fake passkey account recovery override phishing — claims a passkey was removed/revoked and the user must re-enroll via a credential-harvesting recovery URL, exploiting passkey transition confusion. FIDO Alliance Q1 2026; Proofpoint Feb 2026; Krebs Mar 2026.threat
fake-passkey-account-recovery-override-phish - Fake password manager vault breach or account compromised phishing — fraudulent email impersonating LastPass, 1Password, Bitwarden, Dashlane, or Keeper claiming the recipient's password vault has been compromised, their account has been suspended for unusual activity, or their vault encryption requires immediate action — directing them to sign in, export their vault, or re-encrypt their stored passwords through a fraudulent portal — a catastrophic credential-harvesting attack; the master password unlocks ALL passwords stored across every site and service the victim uses; LastPass has 33M+ users (their 2022 breach still drives impersonation campaigns); 1Password 8M+; Bitwarden 8M+; Dashlane 15M+; FBI IC3 2024: credential manager phishing growing rapidly as password manager adoption risesthreat
fake-password-manager-vault-breach-phish - Fake Patreon / Substack / Ko-fi creator payout on hold or account suspended phishing — fraudulent email impersonating Patreon, Substack, Ko-fi, or Gumroad claiming the creator's payout has been placed on hold, earnings have been withheld, or account has been suspended — directing them to verify banking details or sign in to release earnings — targets independent creators whose primary income flows through these platforms; Patreon: 250K+ active creators; Substack: 35M+ paid subscriptions; APWG 2024: creator economy platform impersonation grew 195% YoYthreat
fake-patreon-substack-creator-payout-phish - Fake Paylocity / Paycom mid-market payroll platform subscription payment failed, payroll licenses suspended, payroll processing disabled, or HCM access no longer active phishingthreat
fake-paylocity-paycom-midmarket-payroll-billing-phish - Fake PayPal account limited or suspended phishing — fraudulent email impersonating PayPal claiming the recipient's account has been limited, suspended, or restricted due to unusual activity or unauthorized access, and directing them to click a link to verify their identity, update billing information, or restore access — a credential-harvesting phishing attack that captures PayPal login credentials and payment card detailsthreat
fake-paypal-account-limited-suspended-phish - Fake PayPal payment dispute / account limitation phishthreat
fake-paypal-payment-dispute-phish - Fake PayPal / Venmo / Zelle payment pending phishing — non-official sender impersonates PayPal, Venmo, Zelle, or Cash App falsely claiming the recipient has a pending payment, money transfer, or funds on hold and directing them to log in, verify their account, or click a link to claim or release the funds through a credential-harvesting portalthreat
fake-paypal-venmo-zelle-payment-pending-phish - Payroll direct-deposit account-change BEC — attacker impersonates an employee emailing HR or payroll to redirect the next paycheck to a mule account; FBI IC3 2024: $55M in payroll diversion BEC losses, average loss $8,000+threat
fake-payroll-direct-deposit-account-change-bec - Fake Peloton / Planet Fitness / ClassPass fitness membership payment failed, equipment access suspended, or membership cancelled phishing — fraudulent email impersonating Peloton, Planet Fitness, ClassPass, or OrangeTheory claiming the recipient's fitness membership payment has failed, their gym access has been suspended, or their Peloton equipment is no longer operable without an active membership — directing them to update billing, reactivate the membership, or verify payment through a credential-harvesting portal; Peloton 3M+ All-Access Membership subscribers ($44.99/month; equipment valued at $1,000-4,000 becomes non-functional without an active subscription creating extreme urgency); Planet Fitness 18M+ members (largest US gym chain); ClassPass 30M+ registered users; OrangeTheory 1.5M+ members; connected fitness equipment tied to subscription creates unique sunk-cost urgency not present in other subscription categoriesthreat
fake-peloton-planet-fitness-classpass-fitness-subscription-phish - Fake Pendo / WalkMe / Appcues product adoption subscription payment failed, in-app guidance and product analytics suspended, digital adoption platform offline, or user onboarding flows disabled phishingthreat
fake-pendo-walkme-product-adoption-billing-phish - Fake Perplexity AI Pro billing suspension phishing — impersonates Perplexity with Pro-subscription-expired or payment-failed urgency + renew CTA at a non-perplexity.ai host. Cofense 2025-2026.threat
fake-perplexity-ai-pro-billing-phish - Fake Perplexity Pro subscription suspended — AI-powered search platform payment failed, Pro searches and unlimited search capacity no longer active, Perplexity Spaces and Pages access revoked due to billing failure phishingthreat
fake-perplexity-pro-subscription-billing-phish - Fake pharmacy prescription phishingthreat
fake-pharmacy-prescription-phish - Fake Pika or Kling AI consumer video generation subscription suspended — Pro or Standard plan payment failed, video generation credits revoked, AI video creation access blocked due to billing failure phishingthreat
fake-pika-kling-ai-video-generation-subscription-billing-phish - Fake Plex Pass / Emby Premiere home media server subscription payment failed, server access disabled, or shared libraries suspended phishing — fraudulent email impersonating Plex or Emby claiming the recipient's Plex Pass subscription payment has failed, their media server remote access is disabled, or their shared libraries are suspended — directing them to update billing or restore server access through a credential-harvesting portal; Plex: 25M+ registered users with 5M+ Plex Pass subscribers ($6.99/month or $149.99 lifetime); Emby Premiere: 1M+ users; home media server users share libraries with family members, creating pressure to restore access quickly so others are not affectedthreat
fake-plex-pass-emby-media-server-subscription-phish - Fake Poshmark / Mercari / Depop / Vinted resale marketplace seller account suspended or payout withheld phishing — fraudulent email impersonating Poshmark, Mercari, Depop, or Vinted claiming the recipient's seller account has been suspended for unusual activity or a policy violation, their payout or earnings have been withheld pending identity verification, or their active listings have been removed — directing them to sign in, verify identity, or link a bank account to restore access and release earnings — a credential-harvesting and financial data theft attack targeting resale sellers who depend on platform payouts; Poshmark 80M+ users; Mercari 20M+ US monthly users; Depop 35M+ registered users; Vinted 50M+ EU users; FTC 2024: resale platform impersonation fraud grew 145% as secondhand marketplace adoption surgedthreat
fake-poshmark-mercari-resale-marketplace-account-phish - Fake Postman / RapidAPI developer API platform subscription payment failed, API collections and workspace suspended, or API monitors and mock servers offline phishing — fraudulent email impersonating Postman, RapidAPI, or Insomnia claiming the subscription payment has failed, API collections and team workspaces are no longer accessible, or automated API monitors and mock servers are offline — Postman: 30M+ registered users, 500K+ paying ($19-49/user/month Team/Enterprise); RapidAPI: 4M+ developers; Postman workspace suspension locks the entire API development team out of shared collections and environments simultaneously — all API testing, monitoring, and documentation workflows stopthreat
fake-postman-api-platform-subscription-billing-phish - Fake telehealth DEA-hold / prescription billing phish — email impersonating Hims, Hers, Roman, Nuo, Sesame, or Done claiming a DEA compliance hold or failed billing for a controlled-substance prescription; harvests payment card or portal credentials. NABP 2026; DEA controlled-substance phishing wave.threat
fake-prescription-telehealth-dea-billing-phish - Fake prize, sweepstakes, lottery winner, or gift card winner phishing — fraudulent email claiming the recipient has won a prize, cash award, gift card, jackpot, or sweepstakes — directing them to click a link to claim their winnings, provide personal information, pay a release fee, or verify their identity to receive the prizethreat
fake-prize-sweepstakes-lottery-winner-phish - Fake Productboard / Aha! product roadmap subscription payment failed, product roadmap and feedback portal suspended, or feature prioritization and strategic initiatives inaccessible phishingthreat
fake-productboard-aha-product-roadmap-billing-phish - Fake Proton Mail / Proton Drive / Proton VPN Plus subscription suspended or encrypted email access blocked or VPN connections disabled due to billing failure phishingthreat
fake-proton-mail-drive-vpn-subscription-billing-phish - Fake QR code phishing — scan to verify account — bank/Microsoft/PayPal QR code to scan to verify identity + enter credentials at secure portal + QR leads to phishing page harvesting passwords + quishing bypasses email URL scannersthreat
fake-qr-code-phishing-scan-to-verify-account - QR code phishing ("quishing") — email instructs victim to scan a QR code with phone camera to "verify identity" or "access a document", bypassing link scanners because the URL is in an image; APWG H2 2023: 587% surge; Cofense 2024: 17% of credential-phishing emails use QR codesthreat
fake-qr-code-quishing-phish - Fake QuickBooks / accounting software payment failed phishing — impersonates QuickBooks Online (Intuit), FreshBooks, Xero, or Wave claiming subscription payment failed and financial data will be deleted/locked within 24 hours; powerful loss-aversion hook for SMB owners relying on these tools for payroll, invoicing, and tax records; IC3 2024: SMB credential phishing up 40%; Proofpoint 2024: QuickBooks is the most impersonated accounting software brandthreat
fake-quickbooks-intuit-accounting-payment-failed-phish - Fake Rapid7 / Wiz cloud security and CSPM platform subscription payment failed, licenses suspended, InsightVM vulnerability scanning disabled, or cloud security posture management access no longer active phishingthreat
fake-rapid7-wiz-cloud-security-cspm-billing-phish - Fake real estate wire fraud — updated wire transfer instructions for closing + routing/account number changed + wire down payment today before deadlinethreat
fake-real-estate-wire-fraud-closing-scam - Fake Retool / Bubble / Webflow no-code and internal tool builder subscription payment failed, internal tools and admin panels offline, or no-code app suspended phishing — fraudulent email impersonating Retool, Bubble, or Webflow claiming the subscription payment has failed, internal tools and custom applications are offline, or the no-code app and workflows are no longer accessible — Retool: 7K+ companies ($10-50/user/month); Bubble.io: 3M+ users ($32-249/month); entire operations teams lose custom-built admin panels and workflow tools the moment subscription lapsesthreat
fake-retool-bubble-nocode-platform-billing-phish - Fake Ring Protect Plan / Nest Aware / SimpliSafe home security subscription billing phishing — fraudulent email impersonating Ring, Google Nest, or SimpliSafe claiming the recipient's home security subscription payment has failed, their Ring Protect Plan has expired, or their professional monitoring will be disabled — directing them to sign in, update billing, or verify payment to restore home security monitoring — a credential-harvesting and payment card theft attack exploiting homeowners' fear of their security cameras and alarms going dark; Ring has 10M+ Protect subscribers; Nest Aware 5M+; SimpliSafe 4M+ users; FTC 2025: smart home security subscription impersonation grew 210% YoYthreat
fake-ring-nest-smart-home-security-subscription-phish - Fake Robinhood / Schwab / E*TRADE brokerage investment account phishing — impersonates Robinhood, Charles Schwab, E*TRADE, Webull, or Fidelity claiming suspicious trading activity, unauthorized access, or account restriction — driving to a credential-harvest page enabling full account takeover; IC3 2024: investment account takeover fraud grew 64%, average loss $73,000; Proofpoint 2024: brokerage impersonation surged as retail investing went mainstream with 100M+ new accountsthreat
fake-robinhood-brokerage-investment-account-phish - Fake Rover / TaskRabbit / Handy pet sitting, dog walking, or home services account suspended, payment held, or booking cancelled phishing — fraudulent email impersonating Rover, TaskRabbit, or Handy claiming the recipient's account has been suspended for suspicious activity, their Tasker payment has been placed on hold, or an upcoming pet sitting or cleaning booking has been cancelled — directing them to sign in, verify identity, or resolve a payment issue through a credential-harvesting portal; Rover 2M+ pet sitter/walker profiles serving 5M+ pet owners (upcoming pet sitting booking cancellation creates immediate anxiety about who will care for the pet); TaskRabbit 2M+ Taskers with held payment urgency; Handy 3M+ customers with recurring cleaning subscriptions; these platforms hold home address, scheduled service appointments, stored payment cards, and sometimes house lock/alarm codes for cleaning bookings — premium attack targetsthreat
fake-rover-taskrabbit-home-services-account-phish - Fake SaaS trial expiry credential harvestthreat
fake-saas-trial-expiry-harvest - Fake Salesforce CRM org suspended, Sales Cloud licenses no longer active, users locked out, or subscription payment failed phishing — impersonates Salesforce to harvest credentials granting full CRM and pipeline accessthreat
fake-salesforce-crm-sales-cloud-billing-phish - Fake SAP SuccessFactors enterprise HCM subscription payment failed, licenses suspended, talent management and workflows disabled, or SuccessFactors instance access no longer active phishingthreat
fake-sap-successfactors-hcm-enterprise-billing-phish - Fake Seismic / Highspot sales enablement platform subscription payment failed, sales content library and sales playbooks suspended, content engagement analytics disabled, or sales enablement workflows at risk phishingthreat
fake-seismic-highspot-sales-enablement-platform-billing-phish - Fake Sentry / Datadog / PagerDuty observability or incident-alerting subscription payment failed, error monitoring disabled, or on-call alerts suspended phishing — fraudulent email impersonating Sentry, Datadog, or PagerDuty claiming the subscription payment has failed, error monitoring and performance tracking are disabled, or incident alerts and on-call routing are suspended — directing them to update billing or restore monitoring through a credential-harvesting portal; Sentry: 90K+ organizations ($26-80/month Team/Business); Datadog: 25K+ customers ($15-23/host/month); PagerDuty: 25K+ customers; disabled monitoring means engineering teams are "flying blind" during production incidents — zero-visibility urgencythreat
fake-sentry-datadog-observability-subscription-billing-phish - Fake Sephora Beauty Insider / Ulta Beauty Rewards loyalty account suspended, points at risk, or Rouge/Platinum status expiring phishing — fraudulent email impersonating Sephora or Ulta Beauty claiming the recipient's Beauty Insider or Ulta Rewards account has been suspended for suspicious activity, their accumulated points are at risk of being forfeited, their Rouge or Platinum status is at risk, or an unauthorized purchase was made — directing them to sign in, verify identity, or secure their account through a credential-harvesting portal; Sephora Beauty Insider 35M+ members (Rouge tier requires $1,000+ annual spend — members who qualify have spent significantly and are highly motivated to protect that status); Ulta Beauty Rewards 42M+ active members (largest beauty loyalty program in the US; Platinum at $500+/year, Diamond at $1,200+/year spend — tier status represents hundreds of dollars of accumulated purchasing effort); beauty loyalty accounts contain purchase history, stored payment methods, home address, and skin-type/beauty preferences — premium profile for identity theft and targeted fraudthreat
fake-sephora-ulta-beauty-insider-loyalty-account-phish - Fake ServiceNow ITSM and workflow automation platform subscription payment failed, instance licenses suspended, workflows and automations disabled, or Now Platform access no longer active phishingthreat
fake-servicenow-itsm-platform-subscription-billing-phish - Fake shipping carrier delivery phishthreat
fake-shipping-carrier-delivery-phish - Fake Shopify / BigCommerce / WooCommerce ecommerce platform subscription payment failed, online store offline, or merchant account suspended phishing — fraudulent email impersonating Shopify, BigCommerce, or WooCommerce claiming the subscription payment has failed, the online store and checkout are offline, or the merchant account is suspended — directing them to update billing or restore the store through a credential-harvesting portal; Shopify: 2M+ merchants ($29-299/month); BigCommerce: 60K+ merchants; store going offline means zero sales revenue in real time — the most direct revenue-loss phishing hook of any billing signalthreat
fake-shopify-bigcommerce-ecommerce-platform-billing-phish - Fake Shopify / BigCommerce e-commerce store subscription payment failed, store suspended, storefront offline, or checkout disabled phishingthreat
fake-shopify-bigcommerce-ecommerce-store-billing-phish - Fake Shopify or Etsy seller account suspended phishing — fraudulent email impersonating Shopify, Etsy, or a generic merchant platform claiming the recipient's seller account has been suspended, restricted, placed on hold, or flagged for a policy violation — directing them to click a link to appeal, verify their identity, or provide bank routing numbers and tax information to reactivate their store — a credential-harvesting fraud targeting online sellers dependent on marketplace incomethreat
fake-shopify-etsy-seller-account-suspended-phish - Fake Slack / Teams / Discord workspace credential phishing — impersonates Slack, Microsoft Teams, or Discord with a fake workspace invitation or account deactivation warning requiring sign-in from a non-official domain; Cofense 2024: Slack phishing is the #1 workplace collaboration tool phishing vector; workspace access gives attackers full team communications, file history, and connected app tokens for deep BEC attacksthreat
fake-slack-workspace-credential-phish - Fake SNAP, EBT, or food benefit skimming replacement phishing — fraudulent email claiming the recipient's EBT card has been skimmed, their SNAP food benefits stolen, or that unauthorized transactions were detected — directing them to click a link to claim a benefit replacement, provide their EBT card number, PIN, case number, SSN, or household information to restore stolen food assistance benefitsthreat
fake-snap-ebt-benefit-stolen-replacement-phish - Fake Snowflake Data Cloud subscription payment failed, compute credits suspended, virtual warehouses paused, or data lake access disabled phishingthreat
fake-snowflake-data-cloud-warehouse-billing-phish - Fake Snowflake / Databricks / Fivetran data warehouse or data engineering subscription payment failed, queries and pipelines suspended, or BI dashboards offline phishing — fraudulent email impersonating Snowflake, Databricks, or Fivetran claiming the account is suspended, data warehouse queries and engineering pipelines are offline, or data connectors stopped syncing — Snowflake: 9K+ customers; Databricks: 10K+ customers; data platform suspension blinds analytics and data science teams mid-sprint, freezes BI dashboards feeding executive decisions, and halts data pipelines feeding downstream applicationsthreat
fake-snowflake-databricks-data-warehouse-billing-phish - Fake social media account suspension phish — Facebook/Instagram/Twitter account disabled + verify identity or account permanently deletedthreat
fake-social-media-account-suspension-phish - Fake social media sextortion intimate image threat scam — scammer claims to have obtained intimate/nude/explicit photos or compromising video and threatens to send them to contacts/family/employer unless paid in Bitcoin/cryptocurrency/gift cardsthreat
fake-social-media-sextortion-intimate-image-threat-scam - Fake social media verified badge / blue checkmark phishing — attacker impersonates Instagram, Facebook, TikTok, or X (Twitter) claiming the recipient's account has been approved for a verified blue badge, then demands account password and payment method to "complete the verification," harvesting credentials for full account takeoverthreat
fake-social-media-verified-badge-account-phish - Fake Solana airdrop / Jito priority-fee bundle-tip front-run drainer lure — "Solana airdrop claim window expires soon; pay 0.01 SOL Jito priority fee bundle and approve setAuthority on your SPL token account before snipers front-run your claim" targeting Jupiter / Drift / Kamino / Solana-ecosystem airdrop hunters. The signed setAuthority transfers ownership of the user's SPL token account to the attacker, draining the entire token balance on the next attacker-initiated transfer. Real Solana ecosystem airdrops never demand a Jito-priority-tip wire and never demand a setAuthority signature on the user's SPL token accounts. Distinct from `fake-eip-7702-account-abstraction-delegation-lure` (Ethereum EIP-7702), `fake-eigenlayer-symbiotic-restaking-slash-recovery-lure` (LRT slash drainer), and `base-superchain-l3-sequencer-fee-refund-claim-lure` (Base / OP bridge). Airdrop-drainer cluster. Source: GC1 R8 multiagent council (S4 crypto specialist).threat
fake-solana-jito-priority-fee-airdrop-snipe-drainer - Fake Splunk / Elastic SIEM and security analytics platform subscription payment failed, enterprise licenses suspended, security analytics and SIEM access disabled, or Elastic Cloud access no longer active phishingthreat
fake-splunk-elastic-siem-security-analytics-billing-phish - Fake Spotify, Netflix, Disney+, or streaming service payment failure phishing — fraudulent email impersonating a major streaming platform claiming the recipient's payment has failed, their subscription has been cancelled, or their account has been suspended — directing them to click a link to update their payment method, confirm billing details, or verify their credit card to restore access — a credential and payment card harvesting attack exploiting universal streaming service adoptionthreat
fake-spotify-netflix-streaming-billing-phish - Fake Sprinklr / Brandwatch enterprise social media management and social listening subscription payment failed, platform licenses suspended, social listening queries disabled, or mentions monitoring no longer active phishingthreat
fake-sprinklr-brandwatch-enterprise-social-listening-billing-phish - Fake SSDI, SSI, or Social Security disability benefit approval phishing — fraudulent email impersonating the Social Security Administration or a disability benefits program claiming the recipient has been approved for SSDI, SSI, or supplemental security income and must verify their identity, provide their Social Security number, date of birth, or bank account details to activate payments or claim fundsthreat
fake-ssdi-disability-benefit-approval-phish - Fake Starbucks Rewards / Dunkin Rewards / Chipotle Rewards / McDonald's MyMcDonald's Rewards restaurant loyalty account suspended, Stars at risk, or points expiring phishing — fraudulent email impersonating Starbucks, Dunkin, Chipotle, or McDonald's claiming the recipient's loyalty rewards account has been suspended for suspicious activity, their earned Stars or points are at risk of expiring, or an unauthorized redemption was detected — directing them to sign in, verify identity, or protect their points through a credential-harvesting portal; Starbucks Rewards 34M+ active members (largest US restaurant loyalty program; Gold Status and Stars have real monetary value — each Star earned represents paid purchases, and free drink rewards are emotionally tied to daily routine); Dunkin Rewards 12M+; Chipotle Rewards 30M+; McDonald's MyMcDonald's 15M+; restaurant loyalty accounts are checked daily by habitual users, making account-suspension alerts feel immediately credible and urgentthreat
fake-starbucks-dunkin-chipotle-restaurant-loyalty-account-phish - Fake state unclaimed property / treasury fund phishing — claims recipient has unclaimed funds held by the state treasury or a dormant bank account, demands a fee to "release" or "claim" the money; NAUPA: 10M+ fraudulent unclaimed-property claims annually; FTC top consumer scam warning; the genuine search (MissingMoney.com, state treasurer sites) is always freethreat
fake-state-unclaimed-property-treasury-phish - Fake Steam, PlayStation, or Xbox gaming account phishing — fraudulent email impersonating a gaming platform such as Steam, PlayStation Network, Xbox Live, or Nintendo claiming the recipient's account has been compromised, banned, suspended, or will be permanently disabled — directing them to click a link to verify credentials, appeal a ban, confirm account information, or secure the account — a credential-harvesting attack targeting gamers' valuable accounts with in-game items, purchase history, and linked payment methodsthreat
fake-steam-gaming-account-phish - Fake government stimulus check, relief fund, or economic impact payment phishing — fraudulent email impersonating the IRS, Treasury Department, or a federal agency claiming the recipient has an approved stimulus check, unclaimed government relief fund, CARES Act payment, or economic impact payment ready to collect — directing them to click a link to claim funds, provide their SSN, bank account, routing number, or personal information to deposit the paymentthreat
fake-stimulus-government-payment-phish - Fake Strava / Zwift / AllTrails+ fitness training app subscription payment failed, segment data at risk, or training access suspended phishing — fraudulent email impersonating Strava, Zwift, or AllTrails claiming the recipient's subscription payment has failed, their segment leaderboard access is suspended, their training data and performance history are at risk, or their cycling routes are unavailable — directing them to update billing or restore access through a credential-harvesting portal; Strava: 80M+ users, 10M+ paid subscribers ($11.99/month); Zwift: 1M+ subscribers ($14.99/month); AllTrails: 4M+ paid subscribers ($35.99/year); athlete identity investment in training data makes "your segment history and performance records are at risk" a powerful urgency triggerthreat
fake-strava-zwift-fitness-training-app-subscription-phish - Fake streaming subscription billing failure phishing — non-official sender impersonates Netflix, Spotify, Disney+, Hulu, or HBO Max falsely claiming the recipient's payment failed, billing issue occurred, or subscription was suspended, then directing them to update payment details or click a link through a credential- or card-harvesting portalthreat
fake-streaming-subscription-billing-failure-phish - Fake Stripe / Square merchant account suspended, payment processing disabled, or payouts frozen phishing — fraudulent email impersonating Stripe or Square claiming the merchant account has been suspended for suspicious activity, payment processing is disabled, or payouts and bank deposits are on hold pending identity verification — distinct from PayPal/Venmo personal payment pending phishing; Stripe: 4M+ active businesses ($0 + 2.9%+30¢/transaction); Square: 4M+ sellers; merchant account suspension means zero revenue from any card transaction — the most immediate revenue-zero business emergencythreat
fake-stripe-connect-merchant-account-payouts-phish - Fake Stripe payment processing account suspended, payouts disabled, or payment method billing failure phishing — impersonates Stripe claiming payment processing is halted and the business cannot accept paymentsthreat
fake-stripe-payment-processing-account-billing-phish - Fake Stripe, Square, or merchant payment processor phishing — fraudulent email impersonating Stripe, Square, or a payment processing platform claiming the recipient's merchant account has been restricted, suspended, or flagged for chargebacks or high-risk activity — directing them to verify their identity, provide business tax information, submit their SSN or EIN, confirm bank routing details, or click a link to resolve the restriction — a high-value phishing attack targeting business owners who depend on payment processing to accept customer paymentsthreat
fake-stripe-square-payment-processor-phish - Fake student loan forgiveness / cancellation phishing — non-official sender impersonates the Department of Education, Federal Student Aid, or a loan servicer claiming the recipient's student loans have been approved for forgiveness, discharge, or cancellation under a government program, then harvests FSA login credentials, Social Security numbers, or charges enrollment fees to "process" the applicationthreat
fake-student-loan-forgiveness-phish - Fake subscription payment failure phishthreat
fake-subscription-payment-failure-phish - Fake Suno / Udio AI music generation subscription suspended — Pro, Premier, or Standard plan payment failed, song generation credits revoked, track downloads blocked, or AI music access disabled due to billing failure phishingthreat
fake-suno-udio-ai-music-subscription-billing-phish - Fake paid survey / credential harvest scam — you have been selected for a paid survey + earn $500/$750 + provide credit card / SSN to verify age or pay membership feethreat
fake-survey-paid-participation-credential-harvest - Fake Tableau / Power BI business intelligence platform subscription payment failed, Tableau licenses suspended, Power BI workspace disabled, or BI dashboards and reports no longer active phishingthreat
fake-tableau-powerbi-bi-platform-billing-phish - Fake Talkdesk / Genesys Cloud contact center as a service subscription payment failed, agent licenses suspended, contact center access disabled, or cloud contact center agents no longer active phishingthreat
fake-talkdesk-genesys-cloud-contact-center-billing-phish - Fake tax preparer or refund advance SSN harvest scam — fraudulent email impersonating TurboTax, H&R Block, Jackson Hewitt, or a tax preparation service claiming the recipient can file their taxes and receive a maximum refund advance deposited in 24 hours — directing them to provide their Social Security number, W-2, 1099, and bank routing details to claim the advance — a personal information and identity theft fraud targeting taxpayers during filing seasonthreat
fake-tax-preparer-refund-advance-ssn-harvest-scam - Fake IRS/HMRC tax refund or stimulus payment phish — refund pending/approved + click link to claim + enter bank account / SSN / card details to receive itthreat
fake-tax-refund-stimulus-payment-phish - Fake Tealium / mParticle customer data platform subscription payment failed, data collection tags and audience segments suspended, event streams disabled, or customer data platform workflows at risk phishingthreat
fake-tealium-mparticle-customer-data-platform-billing-phish - Fake Tenable / Qualys vulnerability management platform subscription payment failed, licenses suspended, vulnerability scanning disabled, or Nessus and asset management access no longer active phishingthreat
fake-tenable-qualys-vulnerability-management-billing-phish - Fake Ticketmaster / event ticket platform account suspended phishing — impersonates Ticketmaster, StubHub, SeatGeek, Eventbrite, AXS, or Live Nation claiming account compromised, suspended, or breached, driving to credential-harvest page; spiked 280% H2 2024 following the ShinyHunters Ticketmaster breach affecting 560M customers; victims lose both login credentials and access to upcoming event ticketsthreat
fake-ticketmaster-event-ticket-platform-phish - Fake Tidal HiFi / Deezer Premium / Qobuz Studio hi-res music streaming subscription payment failed, lossless audio suspended, or streaming access revoked phishing — fraudulent email impersonating Tidal, Deezer, or Qobuz claiming the recipient's HiFi subscription payment has failed, their lossless or hi-res FLAC audio streaming is suspended, their Dolby Atmos tracks are inaccessible, or an unauthorized charge was detected; Tidal: 3-4M+ subscribers (many paying $19.99/month HiFi Plus); Deezer: 16M+ paid subscribers ($10.99/month Premium); Qobuz: 250K+ audiophile subscribers ($14.99/month Studio); audiophile identity investment makes "your lossless streaming access is revoked" a personal-quality-of-life attack beyond generic streaming suspensionthreat
fake-tidal-deezer-hifi-music-streaming-subscription-phish - Fake TikTok, YouTube, or creator account suspended phishing — fraudulent email impersonating TikTok, YouTube, Twitch, or another content creator platform claiming the recipient's account has been suspended, banned, or terminated for a policy violation, copyright strike, or monetization issue — directing them to click a link to appeal the suspension, verify their identity, confirm tax information, or restore access through a fraudulent portal — a credential-harvesting and financial data theft attack targeting content creators with monetized accounts and established audiencesthreat
fake-tiktok-youtube-creator-account-suspended-phish - Fake Toggl Track / Harvest / Clockify time tracking and invoicing subscription payment failed, time entries inaccessible, or invoicing suspended phishing — fraudulent email impersonating Toggl Track, Harvest, or Clockify claiming the subscription payment has failed, time entries and reports are inaccessible, client invoicing is suspended, or workspace will be shut down — Toggl Track: 80K+ paying teams ($10-20/seat/month), freelancers and agencies tracking billable hours; Harvest: 70K+ paying customers ($12-14/seat/month), integrates time tracking with invoicing and payroll; Clockify: 5M+ users with paid workspace plans; time tracking suspension directly blocks client invoicing — freelancers and agencies cannot generate invoices for billable hours until access is restored, creating immediate revenue blockagethreat
fake-toggl-harvest-time-tracking-billing-phish - Fake toll road unpaid fee phishing — non-government sender impersonates E-ZPass, SunPass, FasTrak, Illinois Tollway, or other US toll operators claiming a small unpaid toll balance will trigger late fees, vehicle registration holds, or DMV license plate flags unless paid immediately via a fraudulent portalthreat
fake-toll-road-unpaid-fee-phish - Fake TSA PreCheck / Global Entry renewal phishing — non-government sender impersonates TSA, CBP, or the Trusted Traveler Program claiming membership has expired or been suspended and demands a $78–$100 renewal fee plus passport number and date of birth on a fraudulent portalthreat
fake-tsa-precheck-global-entry-renewal-phish - Fake TurboTax / H&R Block / TaxAct tax filing software account locked, suspended, or tax return access on hold phishing — fraudulent email impersonating TurboTax, H&R Block, TaxAct, or FreeTaxUSA claiming the recipient's tax software account has been locked for suspicious activity, their in-progress tax return is no longer accessible, their prior-year tax documents are at risk, or their filing fee payment has failed — directing them to sign in, verify identity, pay an outstanding fee, or secure their account through a credential-harvesting portal; TurboTax 40M+ users ($39-89/filing); H&R Block 23M+ online users; TaxAct 7M+; FreeTaxUSA 7M+; during tax season (Jan-April) users have in-progress tax returns containing SSN, W-2 data, 1099 information, bank routing numbers, and prior-year adjusted gross income — "your in-progress tax return may be lost" creates extreme urgency to protect irreplaceable uploaded documents and avoid missing the April 15 deadline; TurboTax is consistently in the top-10 most impersonated tax brands during Q1threat
fake-turbotax-hrblock-tax-software-account-phish - Fake Twilio / SendGrid / Postmark / Mailgun communication API subscription payment failed, SMS and voice APIs offline, or email delivery suspended phishing — fraudulent email impersonating Twilio, SendGrid, Postmark, or Mailgun claiming the subscription payment has failed, the SMS/voice API or email delivery service is suspended, or an unauthorized charge was detected — directing them to update billing or restore API access through a credential-harvesting portal; Twilio: 300K+ active accounts ($15-150/month); SendGrid: 80K+ customers ($15-100/month); suspended Twilio account means all SMS and voice communications from the target application stop — customer OTP codes, order notifications, and service alerts all fail simultaneouslythreat
fake-twilio-sendgrid-communication-api-billing-phish - Fake Twilio / SendGrid communications API account suspended, SMS and voice API disabled, phone numbers released, or email delivery suspended due to billing failure phishingthreat
fake-twilio-sendgrid-communications-api-billing-phish - Fake Twitch Partner/Affiliate monetization-review lure — "your Twitch Partner application is under review / Affiliate payout on hold / creator dashboard re-authentication required, verify within N hours" + credential-harvesting link to a non-twitch.tv host impersonating the Twitch creator dashboard. Targets ~9M active streamers. Blast radius: payout redirection, channel takeover (fake endorsements / crypto scams posted to the streamer's subscriber base), subscriber PII + brand-deal inbox access. The 2021 Twitch 125GB breach pre-identified streamer emails for ongoing campaigns. Distinct from fake-twitch-turbo-prime-gaming-subscription-billing-phish (consumer viewers). Evidence: 2021 Twitch breach, Proofpoint 2022-2024 streamer-phishing telemetry, r/Twitch megathread advisoriesthreat
fake-twitch-partner-affiliate-monetization-phish - Fake Twitch Turbo or Prime Gaming subscription suspended — ad-free Twitch Turbo membership payment failed, Prime Gaming benefits revoked, in-game loot and free channel subscription no longer active due to billing failure phishingthreat
fake-twitch-turbo-prime-gaming-subscription-billing-phish - Fake two-factor authentication bypass or disable phishing — fraudulent security alert claiming the recipient's two-factor authentication (2FA/MFA) has been compromised, disabled, flagged, or that someone is attempting to bypass it, and urging them to click a link to verify their identity, confirm account security, or re-enable authentication — a social engineering attack designed to trick users into disabling account security protections or surrendering credentialsthreat
fake-two-factor-authentication-bypass-phish - Fake Typeform / SurveyMonkey / Jotform form and survey platform subscription payment failed, forms suspended, or response collection inaccessible phishing — fraudulent email impersonating Typeform, SurveyMonkey, or Jotform claiming the subscription payment has failed, forms and surveys are no longer collecting responses, or submission data is inaccessible — Typeform: 2M+ paying users ($29-99/month Basic/Plus/Business); SurveyMonkey: 300K+ paying users ($25-75/month/user); forms collecting payments, lead data, or NPS survey responses all stop simultaneously — payment forms stop processing transactions, lead-gen forms stop capturing prospects, and customer satisfaction surveys stop mid-campaignthreat
fake-typeform-surveymonkey-form-platform-billing-phish - Fake Uber, Lyft, or rideshare driver account deactivated or earnings withheld phishing — fraudulent email impersonating Uber, Lyft, Uber Eats, or another gig economy platform claiming the recipient's driver account has been deactivated, suspended, or flagged, or that their earnings have been withheld or placed on hold — directing them to click a link to verify their identity, appeal the deactivation, provide driver's license and vehicle registration, or confirm bank account details to release their earnings — a credential-harvesting and financial data theft attack targeting gig workers whose income depends on continuous platform accessthreat
fake-uber-lyft-driver-account-deactivated-phish - Fake Uber Eats / DoorDash / Grubhub unauthorized charge, account suspended, or order delivery issue phishing — fraudulent email impersonating Uber Eats, DoorDash, Grubhub, or Instacart claiming an unauthorized charge was detected, the account is suspended due to a payment issue, a refund is pending requiring account verification, or an order cannot be delivered — directing the recipient to sign in, dispute the charge, update payment details, or verify their account — a credential-harvesting and payment card theft attack targeting food delivery app users; Uber Eats has 90M+ active consumers; DoorDash 37M+ users; unexpected charge lures combine financial urgency with account security fear to drive uncritical clicksthreat
fake-ubereats-doordash-food-delivery-order-charge-phish - Fake UKG / Kronos workforce management and time and attendance platform subscription payment failed, licenses suspended, timekeeping and scheduling disabled, or workforce management access no longer active phishingthreat
fake-ukg-kronos-workforce-management-billing-phish - Fake unemployment benefits government impersonation phishing — fraudulent email impersonates the Department of Labor, EDD, or a state unemployment agency falsely claiming the recipient's unemployment benefits have been approved, are available, or are pending, then directing them to verify their identity, provide SSN and bank routing details, or update direct deposit information through a phishing portalthreat
fake-unemployment-benefits-government-phish - Fake Unity Pro / Unreal Engine / Epic Games developer subscription suspended, game license revoked, builds disabled, or game export blocked due to billing failure phishingthreat
fake-unity-unreal-game-engine-developer-subscription-phish - Fake USAA / Navy Federal Credit Union / Pentagon Federal military banking account suspended, locked, or unauthorized transaction phishing — fraudulent email impersonating USAA, Navy Federal Credit Union, or PenFed claiming the recipient's military bank account has been suspended, locked, or restricted due to suspicious activity or unauthorized access — directing them to sign in, verify identity, or secure their account through a credential-harvesting portal; USAA 13M+ members; Navy Federal Credit Union 13M+ members; Pentagon Federal 2.7M+; military banking accounts store direct deposit payroll, savings, investment, and insurance products in one institution; military members are specifically targeted because geographically mobile deployments delay response times; FTC and CFPB both publish annual warnings about military member financial targeting; IC3 2024: active duty and veteran financial fraud exceeded $120Mthreat
fake-usaa-military-navy-federal-banking-account-phish - Fake utility company shutoff threat phishing — PG&E / ConEd / Xcel / National Grid / Dominion impersonation threatening same-day power or gas disconnection unless immediate payment is made via a link; FBI IC3 2024: $158M+ in utility impersonation lossesthreat
fake-utility-electric-gas-shutoff-phish - Fake Vercel Pro / Netlify / Railway developer cloud platform subscription payment failed, deployments offline, or services suspended phishing — fraudulent email impersonating Vercel, Netlify, or Railway claiming the subscription payment has failed, deployments and custom domains are going offline, or services and databases are at risk — directing them to update billing or restore deployments through a credential-harvesting portal; Vercel: 700K+ teams ($20-400/month Pro/Team); Netlify: 3M+ developers ($19/month Pro); Railway: 100K+ teams; deployment going offline means production websites and APIs are down — immediate revenue and user-impact urgencythreat
fake-vercel-netlify-developer-cloud-platform-billing-phish - Fake Vercel / Netlify hosting and deployment platform subscription payment failed, deployments suspended, sites disabled, or project access no longer active phishingthreat
fake-vercel-netlify-hosting-deployment-billing-phish - Fake Verint / NICE CXone workforce engagement management subscription payment failed, workforce management licenses suspended, quality management and recording disabled, or workforce optimization access no longer active phishingthreat
fake-verint-nice-cxone-workforce-engagement-billing-phish - Fake Vimeo Pro / Loom / Wistia video hosting or screen recording subscription payment failed, video storage suspended, or embedded videos going offline phishing — fraudulent email impersonating Vimeo, Loom, or Wistia claiming the subscription payment has failed, hosted videos and embedded portfolio are at risk, or shared recordings are no longer accessible — Vimeo: 260M+ registered users, 1.5M+ paid subscribers ($12-65/month Pro/Business); Loom: 25M+ users ($12.50/seat/month); embedded video loss threatens business websites, client portfolios, and product demos visible to external audiencesthreat
fake-vimeo-loom-video-hosting-subscription-phish - Fake voicemail / audio message phishing lurethreat
fake-voicemail-audio-message-phish - Fake VPN subscription expired or IP address exposed phishing — fraudulent email impersonating NordVPN, ExpressVPN, Surfshark, or ProtonVPN claiming the recipient's VPN subscription has expired, their payment failed, or their VPN protection has been disabled — warning that their real IP address is now exposed and internet activity is unencrypted — directing them to sign in and renew their subscription through a credential-harvesting portal; NordVPN: 14M+ users; ExpressVPN: 4M+; Surfshark: 2M+; privacy fear ("your IP is exposed") creates strong emotional urgency that bypasses rational verification; APWG 2024: VPN impersonation phishing grew 160% as mainstream VPN adoption acceleratedthreat
fake-vpn-subscription-expired-ip-exposed-phish - Fake Walmart / Costco / Target survey gift-card phishing — impersonates major retail brands, claims recipient was selected for a customer survey and will receive a $500–$1,000 gift card upon completion; drives to subscription traps or credential-harvest pages; FTC 2024: retailer brand impersonation top-5 phishing lure; Walmart is #2 most impersonated retail brandthreat
fake-walmart-costco-survey-gift-card-phish - Fake Walmart+ / Sam's Club / Costco membership payment failed or membership cancelled phishing — fraudulent email impersonating Walmart+, Sam's Club, or Costco claiming the recipient's warehouse club or retail membership payment has failed, their membership has been cancelled or expired, or an unauthorized membership charge was detected — directing them to update billing, renew the membership, or verify payment through a credential-harvesting portal; Walmart+ 23M+ subscribers ($12.95/month); Sam's Club 50M+ members ($50-110/year); Costco 73M+ cardholders ($65-130/year); membership billing failure emails are common and expected, conditioning users to click billing-failure links without scrutinythreat
fake-walmart-plus-sams-club-costco-membership-billing-phish - Fake Weights & Biases / Comet ML MLops experiment tracking subscription payment failed, experiment runs suspended, model training logs no longer captured, or hyperparameter sweeps disabled phishingthreat
fake-wandb-comet-mlops-experiment-tracking-billing-phish - Fake MetaMask / Phantom / Coinbase Wallet / Rainbow / Trust Wallet signature-drainer lure — "pending transaction / airdrop claim / approve permit, connect wallet to sign within 24 hours" targeting self-custody Web3 wallet users; malicious setApprovalForAll or permit signature = complete + IRREVERSIBLE wallet drain (Chainalysis 2024: $500M+ lost to drainers, typical victim $5-50K, NFT whales $1-10M)threat
fake-web3-wallet-drainer-signature-lure - Fake Webflow / Framer professional website builder subscription payment failed, sites and CMS suspended, or custom domains offline phishing — fraudulent email impersonating Webflow or Framer claiming the subscription payment has failed, websites and CMS collections are suspended, or published sites and custom domains are no longer active — Webflow: 3.5M+ users, 300K+ paying ($14-212+/month Basic/CMS/Business/Enterprise); Framer: 1M+ users, rapidly growing ($15-45/month Mini/Basic/Pro); distinct from Wix/Squarespace consumer builder phishing; Webflow suspension takes all client-built sites and CMS-driven pages offline; agency plans affect multiple client websites simultaneouslythreat
fake-webflow-framer-professional-website-builder-billing-phish - Fake WeTransfer / file-sharing download phishing — impersonates WeTransfer, Smash, Hightail, FileMail, or Transfernow claiming someone sent the victim a file, with a download link that requires Microsoft 365 or Google credential sign-in; Vade Secure 2023–2024: WeTransfer impersonation phishing up 400%; Cofense 2024: file-sharing lures used in 23% of enterprise phishing attacksthreat
fake-wetransfer-file-sharing-download-phish - Fake WhatsApp OTP or account verification phishing — fraudulent email or social engineering claiming to need the recipient's WhatsApp verification code, one-time password, or 6-digit registration code to complete an account transfer, verify a new device, or activate the account — directing them to share the code, provide it, or click a link — an account hijacking attack that uses the victim's own verification code to transfer their WhatsApp account to the attacker's devicethreat
fake-whatsapp-otp-account-verification-phish - Fake WhatsApp/Telegram business verification phishing — account requires verification or will be suspended + click link to confirm phone/identity + sender is never whatsapp.com or telegram.org + designed to harvest phone numbers, government IDs, passwordsthreat
fake-whatsapp-telegram-business-verification-phish - Fake WHOOP / Oura Ring / Fitbit Premium fitness wearable membership payment failed, device disabled, or health data suspended phishing — fraudulent email impersonating WHOOP, Oura Ring, or Fitbit claiming the recipient's fitness wearable membership payment has failed, their wearable device has been disabled, or their recovery scores, HRV data, and health metrics are no longer accessible — directing them to update billing or restore membership through a credential-harvesting portal; WHOOP: 4M+ members at $30/month (device only works with active membership); Oura Ring: 1M+ members; Fitbit Premium: 5M+ subscribers; WHOOP's hardware-requires-subscription model creates uniquely catastrophic urgency — the physical device becomes useless if membership lapsesthreat
fake-whoop-oura-garmin-fitness-wearable-membership-phish - Fake wireless carrier account suspended phishing — impersonates AT&T, Verizon, T-Mobile, or Sprint, claims wireless account suspended or payment failed, drives to credential/card-harvest page via "verify your payment" link; FTC 2024: telecom impersonation scams cost $330M; AT&T and Verizon among top-5 most impersonated brandsthreat
fake-wireless-carrier-account-suspended-phish - Fake Wise / Revolut / N26 / Monzo fintech account phishing — impersonates Wise (TransferWise), Revolut, N26, or Monzo claiming account restriction, suspension, or a pending transfer requiring confirmation, driving to a credential or payment-data harvest page; Wise has 16M+ users, Revolut 40M+ — rapid fintech adoption created a large, under-cautious victim pool; FTC 2024: fintech impersonation phishing up 180%; APWG 2024: Wise and Revolut in top-10 most impersonated financial services brandsthreat
fake-wise-revolut-fintech-account-phish - Fake Wix / Squarespace / Weebly website builder subscription billing or site offline phishing — fraudulent email impersonating Wix, Squarespace, or Weebly claiming the recipient's Premium plan payment has failed, their website plan has expired, or their website is now offline — directing them to sign in, update billing, or renew their plan to restore their website — a credential-harvesting and payment card theft attack exploiting the catastrophic urgency of a business website going offline; Wix has 220M+ registered users, 6M+ paid plans; Squarespace 4M+ paid subscribersthreat
fake-wix-squarespace-website-builder-billing-phish - Fake WordPress / cPanel / web hosting account suspended phishing — impersonates Bluehost, GoDaddy, HostGator, Namecheap, SiteGround, or Hostinger claiming the site is suspended for policy violation, malware, or overdue payment and driving to a credential-harvest page; FTC + CISA: web hosting impersonation grew 78% in 2024; 40%+ of the web runs on WordPress, giving attackers a massive target pool of site owners who panic about losing their online presencethreat
fake-wordpress-cpanel-web-hosting-account-phish - Fake WordPress.com / Jetpack site plan suspended, website taken offline, domain expired, or security and backup features disabled due to billing failure phishingthreat
fake-wordpresscom-site-plan-billing-phish - Fake Workato / Tray.io enterprise iPaaS subscription payment failed, automation workflows stopped, enterprise integrations suspended, or business workflow automation no longer running phishingthreat
fake-workato-tray-enterprise-ipaas-billing-phish - Fake Workday HCM and enterprise payroll platform subscription payment failed, tenant licenses suspended, payroll and workflows disabled, or Workday tenant access no longer active phishingthreat
fake-workday-hcm-enterprise-payroll-billing-phish - Fake WorkRamp / Docebo learning management system subscription payment failed, training licenses suspended, e-learning courses disabled, or LMS access no longer active phishingthreat
fake-workramp-docebo-lms-learning-billing-phish - Fake WP Engine / Kinsta / Cloudways managed WordPress hosting subscription payment failed, WordPress sites suspended, or hosting environments offline phishing — fraudulent email impersonating WP Engine, Kinsta, or Cloudways claiming the subscription payment has failed, managed WordPress hosting and sites are suspended, or server environments are no longer active — WP Engine: 200K+ customers ($25-290+/month Professional/Growth/Scale); Kinsta: 35K+ customers ($30-1,500+/month); distinct from generic web hosting (GoDaddy/Bluehost); managed WordPress suspension takes all client WordPress sites offline simultaneously — agencies lose every client site in a single billing failurethreat
fake-wpengine-kinsta-managed-wordpress-hosting-billing-phish - Fake X Premium / Twitter Blue / Snapchat+ / Telegram Premium subscription billing failure phishing — fraudulent email impersonating X (formerly Twitter), Snapchat, or Telegram claiming the recipient's premium subscription payment has failed, their blue checkmark has been removed, or their premium features have been downgraded — directing them to update billing to restore their subscription; X has 250M+ daily active users with 8M+ Premium subscribers at $8-16/month; losing the blue checkmark reduces algorithmic reach for creators and removes brand verification for businesses; Snapchat+ 7M+ subscribers; Telegram Premium 6M+; APWG 2024: premium social media subscription impersonation is a growing phishing vector as subscription tiers expandthreat
fake-x-twitter-premium-blue-subscription-billing-phish - Fake Xbox Game Pass / PlayStation Plus / Nintendo Switch Online subscription payment failed or access suspended phishing — fraudulent email impersonating Xbox, PlayStation, or Nintendo claiming the recipient's gaming subscription payment has failed, their online multiplayer access has been suspended, or an unauthorized charge was detected — directing them to sign in or update billing to restore access; Xbox Game Pass Ultimate ~34M subscribers at $10-20/month; PS Plus 47M+ subscribers; Nintendo Switch Online 38M+ subscribers; suspension of online multiplayer is an acute disruption for active gamers who rely on it for daily play sessions; different attack surface from account-ban phishing — specifically targets billing failure urgencythreat
fake-xbox-playstation-nintendo-subscription-billing-phish - Fake Xero / FreshBooks / Wave accounting subscription suspended or payment failed phishing — fraudulent email impersonating Xero, FreshBooks, or Wave Accounting claiming the recipient's subscription has been suspended, their account payment has failed, their invoices are inaccessible, or their payroll has been suspended — directing them to sign in, update billing, or restore access through a spoofed accounting portal — distinct from the QuickBooks/Intuit signal; Xero has 3.5M+ subscribers (dominant in UK, AU, NZ, Canada); FreshBooks 30M+ users; Wave 5M+ small businesses; when accounting access is cut, payroll stops and client invoicing fails — extreme urgency for small business ownersthreat
fake-xero-accounting-invoice-billing-phish - Fake YNAB / Monarch Money / Copilot Money personal budgeting subscription payment failed, budget data at risk, or bank connections suspended phishing — fraudulent email impersonating YNAB, Monarch Money, or Copilot Money claiming the subscription payment has failed, their budget history and spending reports are no longer accessible, or bank account connections will be severed — directing them to update billing or protect financial data through a credential-harvesting portal; YNAB: 6M+ users ($14.99/month or $99/year); Monarch Money: rapidly growing at $14.99/month; personal finance app accounts link directly to bank accounts via Plaid, creating a payment card theft and banking credential theft vector beyond simple subscription accessthreat
fake-ynab-monarch-personal-finance-app-subscription-phish - Fake YouTube Premium or YouTube Music subscription suspended — consumer ad-free subscription payment failed, YouTube Music access revoked, ad-free playback and background play no longer active due to billing failure phishingthreat
fake-youtube-premium-music-subscription-billing-phish - Fake Zapier / Make / n8n workflow automation subscription payment failed, zaps and scenarios suspended, or automated workflows stopped phishing — fraudulent email impersonating Zapier, Make (formerly Integromat), or n8n Cloud claiming the subscription payment has failed, automated zaps and scenarios have stopped running, or workflow integrations are no longer active — Zapier: 2.2M+ paying users ($19.99-799+/month); Make: 500K+ active users ($9-99+/month); n8n Cloud: 40K+ teams; automation suspension simultaneously breaks every connected workflow — order processing, lead routing, CRM syncs, and notification pipelines all fail at oncethreat
fake-zapier-make-workflow-automation-billing-phish - Fake Zendesk customer support subscription payment failed, support tickets inaccessible, or helpdesk and live chat suspended phishingthreat
fake-zendesk-customer-support-billing-phish - Fake Zendesk / Freshdesk customer support helpdesk subscription payment failed, account suspended, agents cannot respond to tickets, or ticket routing disabled phishingthreat
fake-zendesk-freshdesk-customer-support-billing-phish - Fake Zoom / Microsoft Teams / Google Meet cloud-recording-ready phishing — "your cloud recording is ready to view / meeting transcript available / recording expires in 24h" + credential-harvesting link to a non-vendor host (typosquat SSO sign-in page or malicious "video player" download). High WFH-era volume, sustained through 2026. Distinct from fake-zoom-pro-subscription-billing-phish (billing), zoom-calendar-phishing-url (calendar), meeting-transcript-attachment-phishing-lure (attachment-gated). Evidence: Abnormal Security 2024 Top Phishing Brands (Zoom #3); KnowBe4 2024-2025 threat reports; Microsoft MSRC 2024 Teams impersonation advisory; Bleeping Computer 2023-2025 SSO-harvest campaign coveragethreat
fake-zoom-cloud-recording-ready-phish - Fake Zoom Pro / Zoom Business subscription payment failed, meetings limited to 40 minutes, cloud recording suspended, or webinars disabled phishing — fraudulent email impersonating Zoom claiming the Pro or Business subscription payment has failed, meetings are now limited to 40 minutes (free tier cap), cloud recording and transcriptions are suspended, webinars are disabled, or Zoom Rooms are at risk — Zoom: 220K+ paying customers ($15-20/user/month Pro/Business), 150M+ daily meeting participants; distinct from fake Zoom meeting-invitation credential phishing — targets Zoom BILLING suspension specifically; the "meetings limited to 40 minutes" hook is unique to Zoom billing and highly recognizable to any Pro subscriber; cloud recording suspension threatens all recorded meeting archives simultaneouslythreat
fake-zoom-pro-subscription-billing-phish - Fake Zoom / Teams / Meet / Webex meeting invite RAT lure — email-delivered meeting invite with a "download installer" or "install helper extension" link pointing to a typosquat domain that drops AsyncRAT / QuasarRAT / Remcos; heavy 2025-2026 uptick as remote work normalized the email → click → install chainthreat
fake-zoom-teams-meeting-invite-malware-phish - Fake Zoom, Webex, or video conferencing account suspended or meeting credential phishing — fraudulent email impersonating Zoom, Webex, or another video conferencing platform claiming the recipient's account has been suspended, their license has expired, or directing them to click a fake meeting invitation link requiring login — directing them to enter credentials, verify their account, or confirm subscription details through a fraudulent portal — a credential-harvesting attack targeting workers who rely on video conferencing for business communications and may click meeting invitations without scrutinythreat
fake-zoom-webex-meeting-credential-phish - Fake mortgage servicer or insurer claiming the homeowner's insurance lapsed and an expensive force-placed lender policy will be charged to escrow unless coverage is renewed or proof of insurance is provided via email link immediately — credential-harvest and advance-fee fraud; real force-placed insurance notices require 45 days advance written notice under RESPA/CFPB rules, never cold email same-day threats.threat
force-placed-insurance-lapse-phish - Fake Försäkringskassan (Swedish Social Insurance) brand spoof — urgency + off-domain link.threat
forsakringskassan-brand-phish - Fake client/recruiter payment processing request demanding W-9 + ACH banking details via cold email — real freelance payments use authenticated AP portals (Bill.com / Tipalti / Coupa); cold W-9 + bank request is credential harvest.threat
freelance-w9-payment-phish - Geotargeted tax refund scamthreat
geotargeted-tax-refund-scam - Gift card boss impersonation requestthreat
gift-card-boss-impersonation-request - CEO/BEC gift card fraud: executive impersonation asking employee to urgently purchase iTunes/Google Play/Amazon gift cards and share redemption codes — one of the FBI IC3 top-loss fraud patterns.threat
gift-card-ceo-fraud-phish - Google infrastructure phishing — phishing content sent from legitimate Google domains (Forms, Docs, Sites abuse)threat
google-infra-phishing - Fake Google Workspace / Microsoft 365 billing suspension notice from off-brand domain — credential harvest targeting IT admins and business owners; real billing alerts come from official admin portals.threat
google-workspace-billing-suspension-phish - Fake government agency (FTC, IRS, court, DMV) imposing a civil fine payable via email link — real government fines arrive by certified mail and are paid through official .gov portals.threat
government-fine-penalty-payment-phish - Fake government agency claiming the target qualifies for a government grant or stimulus payment and must verify identity or bank details via email link to claim the money — credential-harvest and bank-drain fraud; real government grants are disbursed through official portals (grants.gov, irs.gov), never cold email credential requests.threat
government-grant-stimulus-phish - Grandparent / family emergency impersonation scamthreat
grandparent-emergency-impersonation-scam - Health insurance enrollment phishingthreat
health-insurance-enrollment-phish - Fake health insurance Summary of Benefits and Coverage (SBC) document requiring portal re-enrollment or coverage verification — impersonating UnitedHealth / Aetna / BCBS / Cigna.threat
healthcare-insurance-sbc-phish - Fake health insurance prior authorization denial demanding credential upload to file an appeal — real prior-auth denials arrive via EOB statements and authenticated insurer portals.threat
healthcare-prior-auth-denial-phish - Helpdesk phishing — fake support ticket + verify identity to view reply (credential harvest)threat
helpdesk-phishing - Fake HOA estoppel certificate notice requiring wire payment before real estate closing — targets estoppel fee fraud specifically.threat
homeowner-hoa-estoppel-phish - Hyphenated security-verb subdomain (login-X, secure-Y) — phishing-kit URL fingerprintthreat
href-credential-verb-subdomain - Fake HSA or FSA administrator claiming the health savings or flexible spending account balance will be forfeited if funds are not spent or claimed before the deadline — advance-fee or credential-harvest fraud; real HSA/FSA deadline communications come through authenticated benefit portals or postal notices, never cold email links claiming imminent forfeiture.threat
hsa-fsa-benefit-expiry-phish - Fake HSA/FSA plan administrator claiming unspent Health Savings Account or Flexible Spending Account funds will be forfeited at the rollover deadline unless banking details are submitted or rollover is confirmed via email link — credential-harvest; real HSA/FSA rollover communications come from authenticated plan administrator portals, never cold email banking-detail requests.threat
hsa-rollover-deadline-phish - Hardware-wallet seed-phrase / recovery-phrase reveal phish — "Enter your 24-word seed phrase to verify your Ledger / Trezor / Tangem wallet" via lookalike domain harvests the master key for every coin held by the device. Categorically illegitimate phrase set: NO canonical wallet vendor (Ledger, Trezor, Tangem, GridPlus, Keystone, BitBox, Coldcard, Foundation, Cypherock) ever asks the user to enter / verify / validate / restore / migrate / reveal a seed phrase via email — the entire hardware-wallet trust model depends on the seed never leaving the device. New SACRED-tier near-absolute-trash class (parallel to "never delete starred" but inverse polarity — "always trash seed-phrase reveal"). Distinct from `fake-hardware-wallet-firmware-update-lure` (firmware-update pretext, not direct seed-phrase harvest). Multi-locale: matches Swedish "ange din återställningsfras" / "bekräfta din återställningsfras" alongside English. Source: Red-Team R9 multi-agent council S4 (hardware-wallet-firmware specialist), Lead consensus C2.threat
hw-wallet-seed-phrase-reveal-phish - ICS Embedded URL Phishingthreat
ics-embedded-url-phishing - Fake USCIS / immigration renewal notice requiring fee payment or personal data entry via a non-.gov link — real immigration notices arrive by physical mail (Form I-797); the USCIS never initiates by email with non-.gov payment links.threat
immigration-visa-renewal-phish - Fake attorney, estate administrator, or foreign official claiming the target is named as a beneficiary in an estate and must pay a transfer tax or legal fee via email to claim the inheritance — advance-fee (419) fraud; real estate administration is conducted through probate courts and licensed attorneys, never cold email upfront-fee demands to release inheritance funds.threat
inheritance-estate-transfer-phish - Fake auto/home/life insurance cancellation notice requiring immediate payment confirmation via click-through — real insurers use direct mail and authenticated portal for cancellation; email payment-link claims are credential/payment fraud.threat
insurance-auto-cancellation-phish - Fake insurance company claiming an approved claim requires a processing fee payment via email link to release settlement funds — advance-fee fraud; real insurance claim settlements never require upfront fees.threat
insurance-claim-fraud-phish - Fake Intercom / Zendesk / Freshdesk support ticket notification with account-suspension urgency phishingthreat
intercom-zendesk-ai-ticket-phish - Fake brokerage or financial advisor requesting urgent email-link authorization for a portfolio rebalancing, IRA rollover, or withdrawal — real brokerages require authenticated portal approval.threat
investment-portfolio-authorization-phish - Fake IRS CP2000 (Automated Underreporter Inquiry) email requiring online response via link — real IRS CP2000 notices arrive exclusively by postal mail; the IRS never emails CP2000 links for payment or document upload.threat
irs-cp2000-response-phish - IRS Direct File impersonation — email spoofs IRS Direct File / Free File Fillable Forms claiming e-file rejected or refund held, harvesting SSN + bank account for tax-refund fraud. IRS Dirty Dozen 2026; TIGTA 2026; 24M Direct File user pool.threat
irs-direct-file-impersonation-lure - Post-deadline US tax-return phishing — IRS or major e-file / tax-prep brand (TurboTax / H&R Block / TaxAct / FreeTaxUSA / TaxSlayer / Cash App Taxes / Jackson Hewitt / Liberty Tax) impersonation with a POST-processing narrative: "e-file rejected," "amended return (1040-X) required," "return under additional review," "additional documentation required," "extension denied," "correct and resubmit." Credential + SSN + prior-year-AGI + bank-account harvest for downstream tax-refund fraud. Shipped into the 2-6 week post-April-15 peak window. Distinct from iter-944 `fake-irs-refund-hold-lure` (pre-processing refund-hold shape). Evidence: IRS Dirty Dozen 2026; IRS CID tax-scam advisories; Proofpoint + Abnormal Security + TIGTA + FTC tax-phishing coveragethreat
irs-post-deadline-efile-amended-return-phishing - Fake IRS tax refund direct deposit confirmation requiring bank account verification via non-.gov link — the IRS NEVER emails refund deposit confirmation links; all IRS tax communication is via mail or irs.gov.threat
irs-refund-direct-deposit-phish - Japanese-language delivery phishing — #1 Japanese phishing pattern by volume. Impersonates Yamato Transport (ヤマト / クロネコ / 黒猫), Sagawa Express (佐川急便), Japan Post (日本郵便 / ゆうパック), or Amazon.co.jp with "ご不在" / "再配達" / "配達できませんでした" phrasing + URL to a credential-harvesting redelivery form. Proofpoint + BleepingComputer: CoGUI kit sent 580M+ such emails early 2025; DarkReading + The Record + Yamato Holdings official scam alerts. Opens Japanese regional coverage; distinct from English delivery-phish signalsthreat
japanese-delivery-redelivery-yamato-sagawa-phish - Fake remote job offer claiming the target has been selected and must purchase equipment or software using a gift card with reimbursement promised on the first paycheck — advance-fee employment fraud; no legitimate employer asks new hires to buy equipment via gift card before starting.threat
job-interview-prepayment-phish - Fake remote job offer requiring the new hire to deposit a check and forward funds to a vendor or trainer — classic fake check scam; real employers never require employees to process money on behalf of the company before starting work.threat
job-offer-check-deposit-phish - Fake Kronofogden (Swedish Enforcement Authority) brand spoof — threat language + off-domain link.threat
kronofogden-brand-phish - Fake landlord or property management demanding immediate payment of an early lease termination fee via email link — real lease penalty disputes go through written notice and legal process.threat
lease-early-termination-penalty-phish - Leet-speak brand impersonation domainthreat
leet-speak-brand-impersonation - Fake legal hold / eDiscovery notice lure — "You are subject to a legal hold / litigation hold / eDiscovery preservation order — take immediate action to preserve all records or face spoliation sanctions." Cold inbound email from an unknown domain with legal-hold language + urgency + off-brand link is a phishing tell. Real legal hold notices come from in-house counsel on internal company email or from known outside counsel domains, never as cold inbound email with a link to an unknown portal. SACRED: engine protects legitimate legal hold / litigation hold / ediscovery notices via safety-keywords guard. Source: GC1 R16.threat
legal-ediscovery-hold-phish - Trusted-platform credential phishingthreat
legitimate-service-abuse-phishing - LinkedIn account phishthreat
linkedin-account-phish - Fake LinkedIn account suspension/verification from non-linkedin.com domain — credential harvest targeting professionals; real LinkedIn security notices come exclusively from linkedin.com.threat
linkedin-account-suspension-phish - LinkedIn background-check consent phishing — email impersonates Checkr, Sterling, HireRight, or SterlingNow claiming background-check consent required; harvests SSN + DOB + address. SHRM 2026; FTC identity-theft complaint spike.threat
linkedin-background-check-consent-harvest-phish - Fake lottery or sweepstakes prize advance-fee fraud claiming the target has won a cash prize but must pay a processing fee, tax withholding, or customs duty before receiving winnings — no legitimate prize requires upfront payment.threat
lottery-sweepstakes-prize-phish - EIP-712 typed-data signature phishing for Liquid Restaking Token protocols (EigenLayer, EtherFi, Kelp DAO, Renzo) from non-protocol senderthreat
lrt-restaking-eip712-phish - Mailbox quota phishing — fake "inbox 99% full" + verify-or-be-suspended CTAthreat
mailbox-quota-phishing - Fake brokerage claiming the target's investment account has triggered a margin call and all open positions will be force-liquidated unless funds are deposited immediately via email link — credential-harvest and payment-diversion fraud; real margin calls are communicated through authenticated brokerage dashboards under FINRA Rule 4210, never cold email deposit links.threat
margin-call-liquidation-threat-phish - Fake hospital or out-of-network billing claiming a surprise medical bill requires immediate payment or insurance verification via email link to avoid collections — credential-harvest and payment-diversion fraud; real medical billing goes through authenticated patient portals or postal mail.threat
medical-billing-surprise-phish - Meeting transcript attachment phishing lure — fake Zoom / Teams / Meet transcript PDF/DOCX with embedded phishing URLs framed as "action items" (Proofpoint / KnowBe4 / Abnormal 2025 campaigns)threat
meeting-transcript-attachment-phishing-lure - MFA fatigue / push bombing lure from non-trusted senderthreat
mfa-fatigue-phishing - MFA fatigue attack lure in subjectthreat
mfa-fatigue-subject-lure - Microsoft/O365 password-expiry phishing — password expires + click-to-verify/enter-credentialsthreat
microsoft-o365-phishing - Fake mortgage servicer claiming an escrow analysis identified a shortage and requiring payment via email link or the monthly mortgage payment will increase significantly next month — credential-harvest and payment-diversion fraud; real escrow shortage notices are delivered by USPS under RESPA requirements and through authenticated servicer portals.threat
mortgage-escrow-shortage-phish - Fake lender claiming a pre-approved mortgage refinance requires identity or bank account verification via email link to lock in the rate — credential-harvest and bank-drain fraud; real mortgage refinance closings happen through authenticated lender portals, not cold email links.threat
mortgage-refinance-closing-phish - Multi-step credential harvest lurethreat
multistage-phishing-lure - Fake municipal authority claiming a tax lien has been recorded against the target's property for unpaid taxes and threatening foreclosure auction unless the delinquent balance is paid immediately via email link — property-owner scam; real tax lien notices are sent via certified postal mail from the county recorder, never cold email payment links.threat
municipal-tax-lien-notification-phish - Fake MyChart / Epic patient portal session-expiry or forced re-authentication lure — portal access expiring / account deactivation threat directing victim to a credential-harvest login page; distinct from breach-notification variant (iter 934) — fires on portal-access urgency without requiring breach contextthreat
mychart-epic-portal-credential-phish - NFT / airdrop phishing — fake free token offer + connect wallet / approve transactionthreat
nft-airdrop-phishing - Fake NIS2/CSIRT 24h/72h mandatory incident disclosure lure — deadline + off-official-domain link.threat
nis2-csirt-phish - Fake NIS2 Directive hospital/healthcare mandatory cybersecurity incident disclosure notice from non-official sender targeting European IT/compliance staff — impersonates ENISA with "report within 24/72 hours or face non-compliance fine" urgencythreat
nis2-hospital-disclosure-phish - OAuth consent phishing — tricks users into granting malicious app accessthreat
oauth-consent-phishing - OAuth device code phishing — microsoft.com/devicelogin or Google device URL + code prompt (Storm-2372 / EvilTokens PhaaS)threat
oauth-device-code-phishing-lure - OAuth/API token expiry phishing lure in subjectthreat
oauth-token-expiry-subject-lure - Fake Okta FastPass re-enrollment or MFA factor reset targeting SSO access from non-okta.com senderthreat
okta-fastpass-recovery-phish - Fake 1Password Emergency Kit reset or Secret Key recovery lure targeting password-manager vault access from non-1password.com senderthreat
onepassword-emergency-kit-phish - Fake security alert asking recipient to share or enter a one-time passcode/OTP by email — real providers never request OTP codes over email; this is an account-takeover interception attack.threat
otp-intercept-account-takeover-phish - Fake sender claiming to have accidentally overpaid the target and demanding the difference be wired back before the account is cancelled — classic overpayment scam; the original payment is fraudulent and the wired-back difference is an immediate loss to the victim.threat
overpayment-check-refund-phish - Fake DHL / FedEx / UPS / Royal Mail customs clearance fee demanding payment before delivery — real carriers notify via authenticated tracking portals, not cold payment-link emails.threat
package-customs-duty-phish - Fake postal service or customs agency claiming a package is held at customs or the post office and requiring a delivery or customs fee payment via email link to release it — advance-fee fraud; real customs fees are collected through official carrier portals or at delivery, not unsolicited email payment links.threat
package-delivery-customs-fee-phish - Package delivery fee phishing — USPS/DHL/FedEx impersonation + pay-a-fee-to-redeliverthreat
package-delivery-fee-phishing - Package-registry maintainer credential / publish-token phishing — impersonates npm / PyPI / RubyGems / crates.io / Packagist / NuGet / CocoaPods / Maven Central / hex.pm with a 2FA-re-verification, mandatory-token-rotation, unusual-publish-activity, or package-ownership-verification narrative + credential-harvesting link on a non-registry host. Targets active package PUBLISHERS (distinct from iter-1194 slopsquatting which targets consumers, and from fake-github-gitlab-developer-account-security-phish which covers generic dev-account phish at platform level). Massive blast radius: one compromised maintainer account → malicious publishes to every package they control → downstream infection of millions of installs within hours. Real precedents: eslint-config-prettier (Jul 2024), chalk/debug/rc (Mar 2025), xmldom + node-ipc + ctx + colors.js/faker.js (2022). Evidence: Socket.dev + Snyk + Phylum + ReversingLabs 2025-2026 supply-chain reportsthreat
package-registry-maintainer-token-phishing - Passkey enrollment / migration phishing — impersonates Google / Microsoft / Apple / Yahoo / Okta / Duo / 1Password with a "we're enrolling you in passkeys, confirm this device" narrative. Either harvests the current password during a fake pre-enrollment confirmation step OR initiates a WebAuthn ceremony that enrolls an attacker-controlled device credential. Distinct from the existing `fido-passkey-downgrade-lure` (which pressures fallback-to-password on a victim who ALREADY has a passkey) — this signal targets the enrollment flow on victims who don't have a passkey yet. Shipped against the 2026 mass-migration wave: Google passkey-default Jan 2026, Microsoft passwordless-by-default enterprise rollout 2026, Apple iCloud passkey default iOS 18.4+. Evidence: FIDO Alliance 2026 Passkey Usage Report; Krebs on Security, Ars Technica, The Verge 2026 scam-wave coveragethreat
passkey-enrollment-migration-phishing - Fake pre-approved paycheck advance or emergency loan requiring bank account and routing number (or SSN) via email link to release funds — advance-fee loan fraud targeting financially stressed individuals.threat
paycheck-advance-loan-phish - Fake court order or debt collector claiming a wage garnishment order has been issued and the target must pay the judgment balance to avoid immediate garnishment enforcement — illegal collection scare tactics and advance-fee fraud; real wage garnishment is served through formal legal process directed to the employer, never settled by clicking an email link.threat
paycheck-garnishment-legal-phish - Fake PayPal notice claiming the account has been limited or put on hold due to suspicious activity, requiring information verification within 48 hours to restore access — credential-harvest attack; real PayPal account limitations are communicated through the authenticated PayPal Resolution Center, never via cold email links demanding 48-hour credential re-entry.threat
paypal-account-hold-phish - Fake HR/payroll direct deposit bank account change request — BEC variant targeting employees; real payroll changes go through authenticated HRIS portals (ADP / Paylocity / Workday / Gusto), never cold email.threat
payroll-direct-deposit-change-phish - Payroll Diversion Fraudthreat
payroll-diversion-bec - Payroll portal credential harvestthreat
payroll-portal-credential-harvest - Fake pension fund, 401k, or 403b administrator claiming a hardship withdrawal or emergency lump-sum rollover has been approved and requiring bank account verification via email link — real retirement distributions never require email-link bank updates.threat
pension-early-withdrawal-phish - Minimal phishing email skeleton: short body (<200 chars) + exactly 1 CTA + urgency keyword.warning
phish-skeleton-shape - Brazilian regional / PIX + boleto payment fraud — Portuguese-language email + Brazilian-banking brand (Banco do Brasil / Caixa / Itaú / Bradesco / Nubank / Santander Brasil / Inter / PicPay / Mercado Pago / Stone / PagSeguro / C6 Bank, etc.) + scam narrative + one of: fake PIX "Copia e Cola" EMV QR code, fake boleto 47-digit "linha digitável" barcode, or "PIX errado / enviei por engano / favor devolver" refund narrative. Delivers payment-rail fraud — victim pastes the code into their bank app, funds transfer directly to the attacker; no malware component. Evidence: Kaspersky BR, Exame, Estado de Minas Jan 2026, Banco Pan, IronVest Brazil-Banking-Fraud 2026, BankInfoSec "$130M grabbed via Brazil's Real-Time Payment System." Distinct from Casbaneiro (court-summons + password-PDF + banking-trojan narrative)threat
pix-boleto-copy-paste-code-latam-phishing - Fake DeFi points-to-token airdrop claim (Blur/Pendle/EigenLayer points) to drain wallets via malicious connect-wallet portalthreat
point-farm-airdrop-drainer - Post-quantum-cryptography certificate-migration phishing — impersonates a public Certificate Authority (Let's Encrypt, DigiCert, Sectigo, Entrust, GlobalSign, GoDaddy SSL, GeoTrust, Thawte, RapidSSL, ZeroSSL, IdenTrust, Comodo, Cloudflare Origin CA) with a "migrate your certificate to PQC / CNSA 2.0 mandate / ML-KEM / ML-DSA / hybrid-certificate renewal" narrative + credential-harvesting link on a non-CA host. Low-volume, very-high-impact: compromised CA admin credentials = fraudulent cert issuance for arbitrary domains = full MITM capability. Shipped into the NIST FIPS 203/204/205 + CNSA 2.0 (2025-2027) PQC transition window when IT admins are unfamiliar with the actual migration process. Evidence: NIST + NSA CNSA 2.0 timeline; Cloudflare / DigiCert / Sectigo / Let's Encrypt / Entrust 2025-2026 PQC roadmap posts; Bleeping Computer + The Register early-PQC-phish-wave coveragethreat
pqc-certificate-migration-phishing - Post-quantum harvest-now-decrypt-later (HNDL) extortion lure — "We have stored your encrypted traffic; pay BTC/Monero ransom within 72h or once Y2Q quantum hardware matures we sell your retroactively-decrypted data." NIST FIPS 203/204/205 (Aug 2024) + Apple PQ3 + Google Workspace PQ-Sigs beta drove the HNDL narrative; attackers ride that pretext to monetise via crypto-ransom. Distinct from `pqc-certificate-migration-phishing` (CA-cert-migration narrative) — this is the ransom variant. FP-controlled by requiring a BTC bech32 / legacy / XMR address to co-occur with the HNDL phrase set + PQC framing + extortion-urgency, so legit security newsletters discussing HNDL (no payment address) do not fire. Canonical PQC-publisher allowlist (NIST, IETF, Cloudflare, Google, Microsoft, Apple, Mozilla, Let's Encrypt) + .gov bypasses the signal. Source: Red-Team R9 multi-agent council S1 (post-quantum specialist), Lead consensus C1 + dissent S1-D.threat
pqc-hndl-extortion-lure - Prize survey data harvestthreat
prize-survey-data-harvest - Fake state licensing board or professional authority (bar association, medical board, nursing board, CPA board) claiming the target's professional license is flagged for non-compliance and will be suspended unless a renewal fee is paid via email link — credential-harvest and advance-fee fraud; real licensing boards communicate through authenticated portals and certified mail.threat
professional-license-renewal-authority-phish - Fake licensing board or certification body claiming a professional license or certification is expiring and requiring renewal fee payment via email link to avoid suspension or revocation — advance-fee fraud targeting licensed professionals; real license renewals are managed through official state licensing board or certification portals, never cold email payment links with suspension threats.threat
professional-license-renewal-phish - Fake county recorder or title company claiming a deed transfer has been recorded on the target property and requiring immediate credential click to protect it — deed fraud phishing for HELOC/mortgage fraud.threat
property-deed-fraud-phish - QR code phishing ("quishing") — scan-this-QR + MFA/credential/renewal hook to bypass desktop URL scannersthreat
qr-code-phishing - Real Estate Wire Fraud — Closing Lurethreat
real-estate-wire-fraud-lure - Real estate closing wire fraud (Business Email Compromise targeting homebuyers / sellers) — "Wire transfer required today for closing — new wire instructions attached / please update bank details for escrow account immediately." Attacker intercepts or spoofs the title company / escrow agent to redirect closing funds. FBI reports $446M lost to real estate wire fraud in 2022 alone. Real wire instructions for closing are delivered through verified, previously established channels and NEVER arrive as a cold inbound email from an unknown sender with same-day urgency. Detection: wire transfer + closing/escrow language + same-day urgency + no In-Reply-To + no List-Unsubscribe. Source: GC1 R16; FBI IC3 Real Estate Wire Fraud PSA 2024.warning
realestate-closing-wire-fraud - Fake earnest money deposit wire instructions from an unknown sender — "new wire instructions for your earnest money deposit — wire closing funds to a different account than previously established"; wire-fraud BEC variant targeting homebuyers.warning
realestate-earnest-money-wire-fraud - DNS-registrar admin credential phishing — impersonates GoDaddy / Namecheap / Cloudflare Registrar / Route 53 / Squarespace (ex-Google Domains) / Gandi / Porkbun / Hover / Name.com / Dynadot / Enom / NetworkSolutions / IONOS / OVH with a DNSSEC-key-rotation, authoritative-nameserver-change, domain-transfer-authorization, glue-record-update, or admin-console-re-authentication narrative + credential-harvesting link on a non-registrar host. Targets registrar ADMIN accounts (distinct from iter-1844 / 2013 consumer "pay this renewal invoice" payment-scam shape — disjoint vocabulary). Blast radius: one compromise = transfer the domain + change authoritative NS + redirect MX to harvest email + issue valid TLS certs for the victim's brand. Full infrastructure takeover. Sixth entry in the platform-operator sub-family (booking-extranet 1068, storm-2755 1061, PQC 1079, npm-maintainer 1084, extension-publisher 1085, this iter). Real precedents: Sea Turtle / DNSpionage (Cisco Talos 2018-2019), GoDaddy customer-compromise 2022-2024, Namecheap phishing waves 2023-2025, Mandiant M-Trends 2025, ICANN compliance advisoriesthreat
registrar-admin-dns-control-phishing - Fake landlord claiming a rental application was approved and requiring first month rent plus security deposit to hold the unit before viewing — rental advance-fee fraud; no legitimate landlord requires a deposit before an in-person viewing and a signed lease.threat
rental-application-deposit-phish - Fake landlord or property manager claiming a security deposit refund requires bank routing information via email for direct deposit — credential harvest and bank-drain fraud targeting tenants; real deposit refunds are issued by check or the original payment method.threat
rental-deposit-refund-phish - Fake landlord or property manager claiming the lease is up for renewal and requiring wire transfer of security deposit or first month rent to secure the unit before it is re-listed — wire-fraud / advance-fee attack; real lease renewals and deposit collections use authenticated property management portals, never cold email wire-transfer demands.threat
rental-lease-renewal-wire-phish - Fake retirement plan administrator claiming the target's retirement account beneficiary designation is missing or invalid and will revert to default distribution unless updated via email link within a deadline — credential-harvest; real beneficiary updates are managed through authenticated employer HR portals, never cold email link requests.threat
retirement-beneficiary-update-phish - Fake lender or financial advisor claiming the target qualifies for a reverse mortgage cash payout to access home equity with no monthly payments — advance-fee and PII-harvest fraud targeting senior homeowners; real HECMs require HUD-approved counseling and licensed lender underwriting, never cold email credential collection.threat
reverse-mortgage-equity-phish - RMM installer lure — Atera/AnyDesk/ScreenConnect binary or download link as pretext for remote-access compromisethreat
rmm-tool-installer-lure-phishing - Fake SAVE plan / Federal Student Aid forbearance urgency phishing targeting student loan borrowersthreat
save-plan-forbearance-phish - Fake Small Business Administration (SBA) or EIDL loan claiming approval and requiring business banking information via email link to disburse funds — credential harvest and advance-fee fraud targeting small business owners.threat
sba-small-business-loan-phish - Sextortion with Bitcoin demand (danger)threat
sextortion-bitcoin - Sextortion Password Lurethreat
sextortion-breach-password-lure - Sextortion / extortion scam (webcam + Bitcoin demand)threat
sextortion-scam - SharePoint/OneDrive Phishingthreat
sharepoint-onedrive-phishing-lure - Fake Skatteverket (Swedish Tax Agency) brand spoof — urgency + off-domain link.threat
skatteverket-brand-phish - Fake Teams/Slack notification lurethreat
slack-teams-notification-impersonation - Social media account phishing — copyright strike / community violation + fake appeal linkthreat
social-media-account-phishing - Fake social media platform notice claiming the target's account has been suspended for policy violations and requiring identity verification via email link to restore access — credential-harvest attack; real platform account actions are communicated through in-app notifications and the platform's authenticated support portal.threat
social-media-account-suspended-phish - Fake SSA notice claiming Social Security benefits are being reviewed or suspended and requiring SSN or bank account verification to continue receiving payments — credential-harvest and bank-drain fraud; real SSA benefit changes are communicated through ssa.gov or postal mail, never cold email credential requests.threat
social-security-benefit-phish - Fake SSA benefit verification requiring my Social Security login re-authentication via a non-ssa.gov link — enables benefits diversion and SSA account takeover.threat
social-security-benefit-verification-phish - Starlink / satellite ISP account credential phishing — impersonates SpaceX Starlink, Viasat, or HughesNet with billing, device-upgrade, or suspicious-login urgency + credential-harvesting link. KrebsOnSecurity Jan 2026 (+600%); FCC advisory Mar 2026; CISA 2026.threat
starlink-satellite-account-credential-phish - Steam Mobile Authenticator migration phishing — email claims Steam Guard is migrating to a new app and the recipient must re-link their phone/re-scan QR at a non-steam.com URL, harvesting Steam Guard TOTP + session cookies. Valve/Steam community phish reports; PC Gamer 2026.threat
steam-mobile-authenticator-migration-phish - Fake Department of Education/FAFSA claiming a student aid disbursement requires bank account verification via email link — high-volume student targeting scam; real FAFSA disbursements go through the bursar.threat
student-fafsa-aid-phish - Fake Department of Education or federal loan servicer claiming student loan forgiveness has been approved but requires bank account details submitted within 48 hours to receive the credit — bank-account-takeover attack; real forgiveness notifications come through authenticated studentaid.gov accounts, never cold email banking requests.threat
student-loan-forgiveness-action-required-phish - Fake scholarship administrator or financial aid office claiming a scholarship or financial aid disbursement requires bank account routing number verification before funds are released — credential-harvest and bank-drain fraud targeting students; real disbursements are managed through authenticated institutional financial aid portals, never cold email routing number submission requests.threat
student-scholarship-disbursement-phish - Fake SAVE Plan court injunction / student loan forgiveness status notice from non-official sender targeting federal borrowers — "your SAVE payments are suspended — recertify your loans / update your income" urgency harvesting FSA ID, SSN, and banking datathreat
studentaid-save-injunction-phish - Subdomain Takeover Phishingthreat
subdomain-takeover-phishing-lure - Fake subscription service (Norton/McAfee/Amazon Prime) claiming a large auto-renewal charge occurred and asking recipient to call/click to cancel — refund advance-fee fraud; real subscription cancellations never require toll-free calls from unsolicited emails.threat
subscription-cancellation-fraud-phish - Fake B2B "update banking details / ACH redirect" to avoid late fees — classic vendor impersonation requesting bank account update before next payment run.threat
supplier-payment-terms-phish - Supply-chain BEC — brand impersonation with payment languagethreat
supply-chain-vendor-impersonation - Fake port disruption / cargo hold / customs clearance fee urgency lure targeting importers and freight forwarders — "Your shipment is held at port — pay customs clearance / release fee immediately or cargo will be returned / auctioned." Real port / customs notifications come from CBP (cbp.gov), the freight forwarder, or the shipping line's official domain — never via cold inbound email demanding emergency payment to an unknown portal. Detection: port disruption/cargo hold/customs clearance + fee/payment urgency + urgency language + no In-Reply-To + no List-Unsubscribe. Source: GC1 R16; CBP phishing advisory 2025.threat
supplychain-port-disruption-phish - Survey-reward phishing — brand-impersonated survey + pay-shipping-to-claim prize trapthreat
survey-reward-phishing - SVG Anchor Phishingthreat
svg-anchor-link-phishing - SVG attachment phishing — SVG files can contain executable JavaScript and full HTML phishing pagesthreat
svg-attachment-phishing - Swedish Phishing Urgency Phrasesthreat
swedish-phishing-urgency - Fake sweepstakes notice claiming the target has been selected as a winner and must pay a processing or customs fee to claim their prize — advance-fee prize fraud prohibited by FTC rules; no legitimate sweepstakes requires winners to pay any fee before receiving their prize.threat
sweepstakes-prize-claim-fee-phish - Synthetic KYC / AML re-verification credential phishing — impersonates a fintech or crypto platform with a post-incident KYC/AML re-verification narrative harvesting government ID scans + selfies + financial credentials. FinCEN/CFPB 2025; Abnormal Security Mar 2026; Cofense Feb 2026.threat
synthetic-kyc-reverification-credential-phish - Tax Authority Subject Lurethreat
tax-authority-impersonation-subject-lure - Tax authority phishing — fake IRS/HMRC refund or identity verification demandthreat
tax-authority-phishing - Fake H&R Block, TurboTax, or Jackson Hewitt refund anticipation loan claiming an advance has been approved and requiring bank account verification via email link — advance-fee fraud; real tax preparer advances are offered through authenticated software, not cold email.threat
tax-refund-advance-loan-phish - Fake Microsoft/Apple tech support claiming device is infected/hacked and requesting AnyDesk/TeamViewer remote access install — a high-frequency, high-loss fraud primarily targeting non-technical users.threat
tech-support-remote-access-phish - Fake AT&T, Verizon, T-Mobile, or other telecom claiming a billing credit or overcharge refund requires bank account details for direct deposit — credential harvest and bank-drain fraud; real telecom credits are applied to the next bill.threat
telecom-billing-credit-phish - Title-attorney revised wire-instructions BEC — email impersonates a settlement attorney or title company mid-transaction with "revised" or "updated" wire instructions containing a routing/account number change. FBI IC3 2025 real-estate BEC $446M; distinct from existing wire-transfer and mortgage-refi signals.threat
title-attorney-revised-wire-instructions-bec - TOAD callback phishing — phone number + urgency + no links/attachments (telephone-oriented attack delivery)threat
toad-callback-phishing - Toll-road phishing — E-ZPass/FasTrak/SunPass impersonation + unpaid-toll urgency + click-to-pay trapthreat
toll-road-phishing - Toll road unpaid fee phishingthreat
toll-road-unpaid-fee-phish - Fake toll authority (EZPass, SunPass, FasTrak) claiming unpaid toll violations have escalated to final collection with a DMV registration hold unless paid immediately via email link — credential-harvest and advance-fee fraud; real toll collection notices are delivered by USPS and authenticated toll portals, never cold email payment ultimatums.threat
toll-violations-final-collection-phish - Fake TSA PreCheck / Global Entry renewal requiring payment and SSN re-entry via a lookalike site — impersonating DHS / CBP / TSA.threat
travel-tsa-precheck-renewal-phish - Fake state unemployment agency (EDD/DOL) claiming benefits require identity verification or an overpayment must be repaid via email link — credential harvest + payment fraud targeting benefit claimants.threat
unemployment-benefits-phish - Fake USCIS or DHS immigration authority claiming an immigration application has a fee deficiency requiring immediate payment via email link or the case will be administratively closed or denied — credential-harvest and advance-fee attack; real USCIS fee deficiency notices are delivered by USPS and through authenticated myUSCIS accounts, never cold email payment links.threat
uscis-fee-deficiency-status-phish - Fake utility company (electric, gas, water) claiming a security deposit refund is ready and requiring bank account routing number verification via email to receive the credit — credential-harvest and bank-drain fraud; real utility deposit refunds are applied as account credits or mailed as checks, never via cold email routing-number collection.threat
utility-deposit-refund-phish - Fake utility company claiming a final disconnection notice for unpaid bills with service shutoff within 2–4 hours unless payment is made via email link — credential-harvest attack; real utility disconnection notices require 10–30 days advance written notice under state PUC regulations, never same-day shutoff via cold email.threat
utility-disconnection-final-notice-phish - Fake electric/gas/water utility emergency disconnection notice requiring same-day payment to prevent cutoff — real utility disconnect notices come via physical mail and authenticated portal, not cold payment-link email.threat
utility-emergency-disconnection-phish - Fake utility company targeting new movers claiming account setup requires SSN and bank account via email link to activate service — credential-harvest and bank-drain fraud; real utility activation uses authenticated portals, not cold email credential requests.threat
utility-new-account-setup-phish - Fake smart meter upgrade notice requiring account verification and appointment scheduling — impersonating PG&E / Consumers Energy / Duke Energy / Xcel / ComEd.threat
utility-smart-meter-upgrade-phish - Fake DMV or state motor vehicle authority claiming the target's vehicle registration is delinquent and threatening license plate confiscation and fine escalation unless a registration fee is paid immediately via email link — credential-harvest and advance-fee attack; real DMV delinquency notices arrive by USPS, never cold email payment links.threat
vehicle-registration-delinquency-phish - Fake vehicle extended warranty expiration notice demanding immediate payment or phone call to renew coverage — high-volume consumer scam; real warranty renewals come from the manufacturer or dealership, not cold email links.threat
vehicle-warranty-extension-phish - Vendor Bank Detail Impersonationthreat
vendor-impersonation-bec - Fake BEC-style vendor invoice approval — CEO/CFO impersonation demanding urgent wire transfer via cold inbound email rather than through ERP portal (SAP/NetSuite/QuickBooks).threat
vendor-invoice-approval-phish - Fake Vercel compute credit depletion or spending limit exceeded notice to harvest payment credentials from non-vercel.com senderthreat
vercel-agent-credit-topup-phish - Fake VA or veterans benefit notice claiming VA benefits require reapplication and asking the target to verify their service record via email link to continue receiving payments — credential-harvest and advance-fee fraud targeting veterans; real VA benefit changes are communicated through va.gov or postal mail, never cold email service-record verification links.threat
veterans-benefit-reapplication-phish - Fake voicemail notification phishingthreat
voicemail-notification-phishing - Fake employer or payroll provider claiming W-2 tax documents are ready for download and requiring SSN or employee ID verification via email link to access them — PII-harvest fraud; real W-2 forms are distributed through authenticated payroll portals (ADP, Workday, Paychex, Gusto) or mailed, never via cold email credential requests.threat
w2-tax-document-phish - Fake WebAuthn L3 cross-origin iframe assertion-harvest lure — "re-enroll your passkey within the embedded iframe" / "complete the cross-origin WebAuthn assertion via navigator.credentials.get within 48 hours." Sender NOT on the FIDO-canonical allowlist (yubico.com, fidoalliance.org, microsoft.com, microsoftonline.com, azure.com, google.com, workspace.google.com, apple.com, icloud.com, okta.com, auth0.com, duo.com, rsa.com, thalesgroup.com, feitian-tech.com, hypersecu.com, w3.org). Real WebAuthn assertion flow happens within a top-level navigation to the relying-party origin, never within a cross-origin iframe embedded in an attacker page. Fresh 2024+ surface area (WebAuthn L3 spec); distinct from R6 MFA push-fatigue and R8 OIDC-backchannel-logout — this signal is specifically the *cross-origin WebAuthn assertion harvest* pretext, where the attacker iframes the legitimate RP and harvests the resulting publickey-credential assertion. Source: Red-Team R8 multi-agent council S3 (technical-AiTM specialist), Lead consensus C2 extension.threat
webauthn-cross-origin-iframe-lure - CEO fraud / whaling wire transfer (danger)threat
whaling-ceo-fraud - Wire fraud / BEC — fake wire transfer request or bank-change instructionthreat
wire-fraud-bec - Fake executive (CEO/CFO) impersonation requesting urgent wire transfer before close of business with explicit instruction not to reply to the email but call directly — one of the highest-loss BEC fraud patterns tracked by FBI IC3; real wire-transfer requests go through authenticated banking portals and dual-approval controls, never cold email with "don't reply, call me" directives.threat
wire-transfer-ceo-fraud-phish - BEC Wire Transfer Lurethreat
wire-transfer-no-prior-context-bec - Workspace OAuth app install lure — email asks you to authorize a Slack / Teams / Jira / Notion / Asana app with broad scopes like channels:history or drive.readonly (2026 shadow-IT / SaaS compromise vector)threat
workspace-oauth-app-install-lure - Calendar Meeting Phishingthreat
zoom-calendar-phishing-url
Want to see them in action?
Connect your Gmail in 10 seconds and Gorganizer will show you exactly which signals fired on every email — colour-coded by severity, with full explanations.
Get started