Scams & fraud
347 signals in this category. Every entry links to a full explanation, severity tier, and false-positive notes.
What most signals in this category mean
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
- Advance-fee personal loan scamthreat
advance-fee-personal-loan-scam - Advance-fee prize release demandthreat
advance-fee-prize-release-demand - AI voice-clone charity donation scam — deepfake audio/video of a celebrity or executive soliciting urgent crypto/wire donation at a non-official URL. FBI IC3 2025; Chainalysis 2026 charity-scam spike post-disaster.threat
ai-voice-clone-charity-donation-scam - Background check / data removal scam — your records publicly exposed + pay to remove or enter personal infothreat
background-check-removal-scam - Business grant / govt funding scam — free SBA/government grant + upfront processing fee to release fundsthreat
business-grant-loan-scam - Callback phone scam (no link)threat
callback-phone-number-scam - CBDC / digital-dollar wallet onboarding scam — fraudulent email impersonating the Federal Reserve, US Treasury, or FedNow claiming a "digital dollar" wallet is ready to activate, harvesting SSN, bank details, or an activation fee. FBI IC3 2025 report: 4,200+ complaints / $89M; FTC alert Feb 2026.threat
cbdc-digital-dollar-wallet-onboarding-scam - Celebrity-endorsed investment scamthreat
celebrity-endorsement-investment-scam - Charity thank-you / impact reportwarning
charity-impact-thankyou - Marathon / charity run / race resultswarning
charity-run-marathon - Charity volunteer event / drivewarning
charity-volunteer-event - Contest / giveaway / sweepstakes promotionwarning
contest-giveaway - Credit score repair scamthreat
credit-score-repair-scam - Crypto airdrop/claim scam — requests wallet connection or seed phrasethreat
crypto-airdrop-scam - Crypto / DeFi portfolio notificationwarning
crypto-defi-notification - Crypto giveaway / doubling scamthreat
crypto-giveaway-doubling-scam - Crypto pump & dump schemethreat
crypto-pump-dump - Crypto recovery scam — "we recover your lost Bitcoin" + upfront fee or 100% guarantee demandthreat
crypto-recovery-scam - Fake staking / yield farming / liquidity mining reward claim with a wallet-connect link to an off-brand or suspicious TLD domain — real staking rewards are claimed on-chain via the protocol's verified dApp, not via inbound email.warning
crypto-staking-reward-claim - Crypto wallet auth-ritual lure — Ledger/Trezor/MetaMask + "Authentication Check" / seed phrase requestthreat
crypto-wallet-authentication-check-lure - Debt relief / settlement fee scamthreat
debt-relief-fee-scam - Deepfake CEO BEC — exec impersonation + Loom/Vimeo/YouTube video link + urgent wire / M&A / payroll change (post-Arup pattern)threat
deepfake-ceo-video-link-wire-urgency - Deepfake video-call follow-up BEC email — post-call enforcement email "confirming" wire transfer discussed in a deepfake Teams/Zoom call, with inline routing numbers and confidentiality instructions. Mandiant Apr 2026; FBI IC3 2025 ($1.4B deepfake BEC); FinCEN 2026.warning
deepfake-video-call-follow-up-bec-email - Deepfake video message lurethreat
deepfake-video-message-lure - Video-based sextortion / deepfake threat (danger)threat
deepfake-video-threat - Deepfake voice/audio lure with authority impersonation (danger)threat
deepfake-voice-lure - Fake voicemail/audio with play CTA or audio attachmentthreat
deepfake-voicemail-lure - EV charging network billing fraud — impersonates ChargePoint, Tesla Supercharger, BP Pulse, Electrify America, or EVgo with an overdue-invoice / payment-declined urgency + credential/payment harvest. FTC 2025-2026 EV-charging fraud advisories; distinct from iter-Round 7 ev-charging-account-takeover.warning
ev-charging-network-billing-fraud - Fake 42 CFR Part 2 substance-use-disorder (SUD) record consent-revocation lure — "Patient consent revocation — purge SUD records within 30 days" targets behavioral-health EHR admins. 42 CFR Part 2 Final Rule (effective Apr 16, 2024 / compliance Feb 16, 2026) harmonized SUD-record consent with HIPAA, lending the lure narrative immediate credibility. Drainer harvests behavioral-health admin credentials + SUD-record PHI exfil (irreversible HIPAA + 42-CFR-Part-2 + SUD-stigma exposure). Real 42-CFR-Part-2 / SAMHSA / SUD-record notifications come through samhsa.gov / hhs.gov / ocr.hhs.gov / EHR-vendor (Netsmart / Epic / Cerner) portals, never via inbound email link demanding 30-day purge of SUD records from an unfamiliar domain. PHI +0.05% budget; SUD-stigma scope flag; B2B-behavioral-health scope. Source: GC1 R9 multiagent council P1 (S2 healthcare specialist).warning
fake-42-cfr-part-2-sud-record-consent-revocation-spoof - Fake account frozen/suspended scam — your account has been frozen/blocked + pay unlock/reinstatement/reactivation fee via gift card or wire to restore accessthreat
fake-account-frozen-verification-scam - Fake advance fee / inheritance scam (419 fraud) — deceased stranger left millions + pay attorney/transfer/demurrage fees to claimthreat
fake-advance-fee-inheritance-scam - Fake advance-fee personal loan approval scam — loan approved for $N regardless of credit + pay insurance/processing/origination fee upfront to receive/unlock/release fundsthreat
fake-advance-fee-personal-loan-approval-scam - Fake OpenAI / Anthropic / Vertex AI / AWS Bedrock API key leak lure — "your API key was exposed in a public GitHub repo, rotate immediately or incur charges" targeting developers with paid AI API keys; key + billing-dashboard harvest enables $10K-$100K+ rapid drain at high-end model rates + billing-email rotation to hide usage alertsthreat
fake-ai-api-key-leak-lure - Fake AI platform storage-quota-full upgrade lure — email impersonates ChatGPT / Claude / Gemini / Copilot claiming workspace or Projects storage is full and requires plan upgrade at a spoofed checkout page. OpenAI + Google + Anthropic phishing wave post-Projects launch 2025-2026.threat
fake-ai-storage-quota-full-upgrade-lure - Fake AI-vendor support / account-verification brand-spoof — "Your ChatGPT / Claude / Copilot / Gemini account requires verification within 24 hours or access will be suspended" via lookalike domain harvests AI-vendor account credentials. Sender domain NOT on the AI-vendor canonical allowlist (openai.com, anthropic.com, google.com, microsoft.com, mistral.ai, cohere.com, x.ai, meta.com, perplexity.ai). Air Canada chatbot ruling (BCCRT Feb 2024) + DPD chatbot incident (Jan 2024) + 2025 Microsoft Copilot prompt-injection findings prove jailbroken or hallucinating support bots can issue real commitments, lending the brand-spoof immediate credibility. Distinct from R8 agent-voice-clone (phone modality) — this is email-only. Distinct from R12 #4 (consumer ChatGPT/Claude renewal phish) — this is the support / account-verification spoof. Source: Red-Team R9 multi-agent council S5 (LLM-jailbroken-support specialist), Lead consensus C5.threat
fake-ai-vendor-support-spoof-lure - Fake Airbnb host payout-hold lure — "payout held due to guest complaint / KYC re-verification / policy review, verify within 24 hours or listing delisted" targeting 5M+ Airbnb hosts; host credentials + 2FA + bank routing harvest enables payout redirect, listing hijack (attacker relists under trusted-reputation account), reservation-fee extraction, past-guest PII exfilthreat
fake-airbnb-host-payout-hold-lure - Fake Airbnb/VRBO off-platform payment scam — host or impersonator asks to pay outside the platform via Zelle/wire/crypto to "save on fees" or due to "payment system issues" + bypasses all buyer protections + property often nonexistentthreat
fake-airbnb-vrbo-off-platform-payment-scam - Fake Delta SkyMiles / American AAdvantage / United MileagePlus / Southwest Rapid Rewards / Alaska Mileage Plan / JetBlue TrueBlue / British Airways Avios / Lufthansa Miles & More / Air France Flying Blue / Emirates Skywards / Singapore KrisFlyer / Cathay Asia Miles airline-miles expiration lure — "your miles are expiring in 48 hours, reinstate now or forfeit permanently" targeting 115M+ AAdvantage + 115M+ SkyMiles + 110M+ MileagePlus + 69M+ Rapid Rewards + 40M+ Avios members; post-compromise attacker transfers miles to attacker-controlled account, redeems for gift cards / flight bookings, and liquidates at 25-50% face value ($0.20-$1 per 1K miles) on dark markets — miles average $500-6K per account, $5-50K for high-status flyers, and redemption bypasses KYC so account takeover IS the attackthreat
fake-airline-miles-expiring-lure - Fake Amazon Seller Central suspension lure — "your Seller Central account will be suspended in 24 hours, verify your seller account or respond to performance notification" targeting Amazon FBA / FBM merchants; Seller Central credential harvest leads to disbursement redirect, inventory hijack, customer-PII exfil (2024-2025 Q4/Prime-Day-era phish)threat
fake-amazon-seller-central-suspension-lure - Fake Anthropic console org-admin spend-cap / API-key-rotation lure — "spend cap exceeded, verify and approve overage to avoid throttle" or "Anthropic API key found exposed on GitHub, rotate within 24 hours or usage suspended" targeting developer + ML-platform admins. Two narrative variants but shared phishing surface: console.anthropic.com lookalike harvests API keys + admin credentials, then attacker burns the key budget at high-end model rates ($10K-$100K rapid drain) or pivots to organization-level data (workbench prompts, fine-tune corpora). Distinct from R12 #4 consumer Claude.ai subscription-renewal phish — this signal is B2B-admin-scoped (org admin / API key / spend cap / exceeded vocabulary). Source: GC1 R7 multiagent council top-5 (S5 SaaS specialist).warning
fake-anthropic-console-org-admin-spend-cap-spoof - Fake antivirus subscription renewal scare scam — Norton / McAfee / Kaspersky / AVG / Bitdefender impersonation claiming subscription expired and device is unprotected / infected, driving card-harvest renewal or gift-card support call; FTC 2024 top-10 impersonation categorythreat
fake-antivirus-subscription-renewal-scare-scam - Fake antivirus tech support renewal callback scam — impersonates Norton, McAfee, Geek Squad, or generic "PC Protection" with a fabricated auto-renewal charge ($249–$399) and a callback phone number to "cancel"; connects to scammer who installs remote desktop software to steal banking credentials or install ransomwarethreat
fake-antivirus-tech-support-renewal-callback-scam - Fake app update download lurethreat
fake-app-update-download-lure - Fake Apple Activation Lock / Find My device-unlock lure — post-theft phishing arriving 1-30 days after a loss/theft report: "Your lost iPhone 15 Pro has been located in [city]. Sign in to remove Activation Lock." Exploits the victim's urgency to recover a $1,000+ device. Harvested Apple ID credentials enable thief-resale of the stolen hardware PLUS full iCloud takeover (photos / Keychain passwords / contacts / messages across every tied device) PLUS password-reset access to every service receiving email at the iCloud mailbox. Distinct from generic Apple-ID phish (no device-loss framing), fake-icloud-storage-full-lure (quota), fake-apple-id-purchase-lure (fake receipt). Evidence: Krebs on Security + Wired 2018-2020 organized post-theft phish-ring coverage; AppleInsider 2023-2025 "fake iCloud unlock service" warnings; FBI Cyber 2024 advisory on post-theft-phish targeting NBA players + high-profile theft victimsthreat
fake-apple-activation-lock-device-unlock-lure - Fake Apple Family Sharing invite — "someone added you to their Family Sharing group / Screen Time invite" from non-Apple sender; harvests Apple ID credentials via invite-acceptance phishing page (2025 Bleeping Computer / Malwarebytes)threat
fake-apple-family-sharing-invite-lure - Fake Apple receipt tech support callback scam — impersonates Apple receipt/App Store invoice for large purchase (iCloud+, in-app, Apple One/TV+/Music) with callback phone number to "dispute"; connects to scammer requesting remote access or credit card for refundthreat
fake-apple-receipt-tech-support-callback-scam - Fake Authy / Google Authenticator / Microsoft Authenticator / 1Password Authenticator / Okta Verify / Duo Mobile migration-sync lure — "Authy Desktop is shutting down, migrate your TOTP codes to our portal" / "enable Google Authenticator cloud sync" / "verify Microsoft Authenticator cross-device sync" + credential-harvesting link to a non-vendor host, or a malicious "Authy Migrator" installer that exfiltrates TOTP seeds + backup codes. Catastrophic blast — TOTP seeds are the master key behind every 2FA-protected account; harvested seeds let the attacker generate valid 6-digit codes indefinitely until the victim manually rotates each. The Twilio Authy 33M-record breach (July 2024) pre-identified real Authy user emails just before the Aug 2024 desktop-app sunset. Distinct from backup-codes-solicitation-phishing (iter 1109, one-time recovery codes) and fake-password-manager-master-breach-lure (vault). Evidence: Twilio Authy sunset Aug 19 2024; Proofpoint + BleepingComputer + ITPro 2024-2026 migration-phish telemetry; Google Authenticator cloud-sync rollout 2023-2025threat
fake-authy-authenticator-migration-lure - Fake Progressive / GEICO / State Farm / Allstate / USAA / Liberty Mutual / Nationwide / Farmers / Travelers / American Family / Esurance / Root / Lemonade auto-insurance policy-EXPIRATION lure — "auto-pay failed / policy expiring in 24 hours / coverage will lapse, pay now or you will be driving illegally" targeting 230M+ US licensed drivers; post-2022-2024 auto-insurance rate-spike (+25-40% YoY), drivers are primed for "pay now" messaging; "driving illegally" framing triggers immediate compliance anxiety (uninsured driving is criminal in every state except NH — fines + license suspension + impound); harvests policy number + credit card ($300-500 "immediate reinstatement") + SSN + driver's license + VIN (enables DMV ID theft + title fraud); distinct from Round 141 quote-scam signal which targets NON-policyholders with "get a lower rate" framingthreat
fake-auto-insurance-policy-expiring-lure - Fake auto / vehicle warranty expiry scamthreat
fake-auto-vehicle-warranty-expiry-scam - Fake AWS free-tier expiration + IAM credential rotation lure — email impersonates AWS Billing / Support, claims the free-tier expires in 24-72 h with a large pending charge, directs to a fake AWS console to "rotate IAM credentials" or "verify account." Security Boulevard Jan 2026 "Phishing at Cloud Scale"; THN Dec 2025 IAM-crypto-mining chain; AWS Jul 2025 free-tier model change seeds Q2-Q3 2026 expiration-phish wave. Distinct from fake-cloud-compute-budget-lure (budget-alert framing)threat
fake-aws-free-tier-expiration-iam-rotate-lure - Fake background check / people-search notification spamthreat
fake-background-check-notification-spam - Fake bank account verification phishthreat
fake-bank-account-verification - Fake bank / account alert (danger)threat
fake-bank-alert - Fake bank wire transfer fraud (BEC)threat
fake-bank-wire-transfer-fraud - Fake bank wire transfer / Zelle / ACH fraud alert scamthreat
fake-bank-wire-transfer-fraud-alert - Fake Bitcoin ATM cash payment scam — IRS/SSA/utility/tech support demands payment via Bitcoin ATM + go to nearest Bitcoin ATM + deposit cash + send Bitcoin to wallet address + no government agency or utility accepts Bitcoin ATM paymentsthreat
fake-bitcoin-atm-cash-payment-scam - Fake Klarna / Afterpay / Affirm / Zip / Sezzle Buy-Now-Pay-Later suspension lure — "account suspended / missed payment / forwarded to collection, verify bank details within 24 hours" targeting 360M+ Klarna + 24M+ Afterpay NA + 17M+ Affirm users; bank-routing + SSN-last-4 + debit-card harvest enables ACH drain + identity fraud for new BNPL accountsthreat
fake-bnpl-account-suspension-lure - Fake BSA / FinCEN / OFAC SDN sanctions-screening blocked-property lure — "Wire blocked under OFAC SDN sanctions match; submit OFAC license attestation and treasury-attestation within 14 days or funds released to Treasury under specially designated property forfeiture" targeting compliance officers + small-bank BSA staff. 2026 OFAC SDN list churn (Russia / Iran / cartel cross-border) + FinCEN BSA E-File sanctions hits give attackers a real and credible compliance pretext. Highest-stakes (+6) wire-fraud + treasury-attestation pressure cluster. Real OFAC blocked-property notices come through formal Treasury channels (postal letter + ofac.treasury.gov portal with OFAC-license-issued credentials), never via inbound email link demanding attestation upload to forfeit-or-release a wire under 14-day pressure. Distinct from R7/R8 FinCEN BOI (CTA) — this signal is specifically the OFAC SDN / blocked-property / treasury-attestation framing. Source: GC1 R9 multiagent council top-5 P0 (S1 fin specialist).warning
fake-bsa-fincen-ofac-sdn-sanctions-blocked-property-spoof - Fake business directory SEO invoice scam — unsolicited invoice for Yellow Pages/Google Business/national directory listing + $350 annual fee + listing will be removed if unpaid + business never subscribed + invoice designed to trick accounts-payable staffthreat
fake-business-directory-seo-invoice-scam - Fake business registration compliance fee scam — LLC/business annual filing or registered agent due + pay compliance/state fee to maintain good standing / avoid penaltythreat
fake-business-registration-compliance-fee-scam - Fake Canva brand kit / Premium workspace billing phishing — impersonates Canva with subscription-expired or workspace-suspended urgency + billing-update CTA at a non-canva.com host. Proofpoint 2025-2026; Abnormal Security Q1 2026.threat
fake-canva-brand-kit-upgrade-lure - Fake car accident personal injury attorney spam — were you in a recent accident + claim compensation + no win no fee / our records show you were in an accidentthreat
fake-car-accident-personal-injury-attorney-spam - Fake carbon credit / ESG investment scam — impersonates ESG brokers or UN bodies with guaranteed-return carbon-offset / green-bond investment offers. SEC/FCA 2025; Chainalysis 2026; FTC Mar 2026.threat
fake-carbon-credit-esg-investment-scam - Fake caregiver / nanny / babysitter / personal assistant overpayment cheque scam — responds to job listing + sends cheque/money order for more than agreed amount + asks worker to cash it and wire/Zelle/CashApp back the difference + cheque bounces days later + FTC: #2 fraud type targeting job seekersthreat
fake-caregiver-nanny-babysitter-overpayment-cheque-scam - Fake Cash App / Zelle / Venmo / PayPal 1099-K AML/KYC threshold-flag lure — "Account flagged under FinCEN AML KYC review for the new 1099-K threshold; submit ID and SSN documents within 7 days or funds will be frozen pending Patriot Act review" cross-platform payment-app harvest. The TY2026 1099-K threshold dropped to $2,500 (down from $5K TY2025), giving attackers a real and credible compliance pretext. Real Cash App / Zelle / Venmo / PayPal AML reviews never request SSN / ID upload via inbound email link; identity verification flows happen in-app or via the registered phone number. PII-credential-harvest cluster. Source: GC1 R8 multiagent council (S1 fin specialist).threat
fake-cashapp-zelle-venmo-1099k-aml-kyc-threshold-lure - Fake non-US central-bank-digital-currency (CBDC) brand-spoof — covers PBoC e-CNY (数字人民币) wallet upgrade, ECB Digital Euro pilot enrollment (digitaler Euro / euro numérique / euro digitale), and BIS Project mBridge / Project Agorá wholesale CBDC settlement. Sender NOT on the CBDC canonical-allowlist (PBoC, ECB, Banque de France, Bundesbank, Banca d'Italia, Banco de España, NBB, DNB, BIS, RBI, BCB) and NOT on the .europa.eu / .gov.cn umbrella. Live 2026 rails: PBoC e-CNY (>260M wallets), ECB digital-euro pilot Q4 2025 → 2026 expansion, BIS Project mBridge wholesale (HK/CN/UAE/TH/SA), BIS Project Agorá G7 wholesale 2025-26. Distinct from `cbdc-digital-dollar-wallet-onboarding-scam` (US digital-dollar / FedNow / generic CBDC-en in body-signals-rounds-10.ts) — this signal covers the non-US sovereign-CBDC + wholesale-settlement scope (zh-CN / de / fr / it / nl / es / treasury-XML). Source: Red-Team R9 multi-agent council S2 (CBDC / wholesale-settlement specialist), Lead consensus C3.threat
fake-cbdc-ecny-digital-euro-mbridge-spoof-lure - Fake celebrity endorsement crypto investment scam — Elon Musk / Jeff Bezos / Warren Buffett / Richard Branson / Dragon's Den falsely endorsing a Bitcoin/crypto investment platform + guaranteed 300-500% returns + limited spots + minimum investment $250 + celebrity never endorsed anything + FCA: £250M+/year UK lossesthreat
fake-celebrity-endorsement-crypto-investment-scam - Fake CFTC + NFA Form CPO-PQR (Commodity Pool Operator quarterly pool reports) / CTA-PR (Commodity Trading Advisor quarterly reports) filing-rejection lure — "EasyFile rejection — re-submit pool risk metrics within 7 days or NFA registration suspended" via fake `easyfile.nfa.futures.org` harvests CPO/CTA principal credentials + AUM (assets under management) data. Q1 due May 15, 2026 post-2024 amendments expanding pool reporting. Targets commodity-pool-operator + commodity-trading-advisor + swap-dealer principals. Real CFTC / NFA filings go through cftc.gov / nfa.futures.org / easyfile.nfa.futures.org / sec.gov portals with NFA-issued credentials, never via inbound email link demanding re-submission of pool-risk metrics under a 7-day suspension threat. B2B-fundmgr scope; quarterly-cycle cluster; SACRED `regulatory_filing` guard. Source: GC1 R9 multiagent council P1 (S1 fin specialist).warning
fake-cftc-cpo-pqr-cta-pr-quarterly-filing-spoof - Fake charity crypto-donation scamthreat
fake-charity-crypto-donation-scam - Fake charity / disaster relief donation fraudthreat
fake-charity-disaster-covid-relief-fraud - Fake charity / disaster relief donation scam — earthquake/flood/conflict victims need help + donate via PayPal/wire transfer/Western Union/MoneyGram/Bitcoin to unregistered fundthreat
fake-charity-disaster-relief-donation-scam - Fake charity / disaster relief donation fraudthreat
fake-charity-disaster-relief-fraud - Fake charity / disaster relief donation scam — urgent disaster appeal + donate via gift cards / wire transfer / Zelle to personal accountthreat
fake-charity-donation-disaster-relief-scam - Fake charity / disaster-relief fraud — charity impersonation + Western Union / gift card / crypto donationthreat
fake-charity-solicitation - Fake ChatGPT Plus / Claude Pro / Gemini Advanced / Copilot subscription renewal lure — "your AI subscription has been canceled, update payment within 24 hours to restore access" targeting 600M+ paid-AI users; credit-card + AI-vendor credential harvest leads to dark-GPT-as-a-service, conversation history exfil, pivot to linked Google/Microsoft/Apple accountthreat
fake-chatgpt-plus-subscription-renewal-lure - Fake check employment scamthreat
fake-check-equipment-employment-scam - Fake class action settlement processing fee scam — eligible for $500-$3500 data breach / overcharging / consumer fraud settlement + must pay $25-$45 processing / administration / claim fee to receive payout + real settlements never charge upfront fees + attorneys work on contingencythreat
fake-class-action-settlement-processing-fee-scam - Fake classified ad buyer overpayment check scam — buyer sends cashier's check for more than asking price + wire back the difference to their shipping agent + check bounces days later + seller loses item and wired moneythreat
fake-classified-ad-buyer-overpayment-check-scam - Fake AWS / Azure / Google Cloud / DigitalOcean / Vercel / Cloudflare compute-overage lure — "your compute spend exceeding budget, verify billing within 24 hours or services suspended" targeting IT/DevOps engineers + SaaS founders; cloud-console credentials harvested → crypto-mining on victim cloud + $500-5K/bundle dark-market resale (Unit 42: cloud-account compromise +60% YoY 2024-2025)threat
fake-cloud-compute-budget-lure - Fake CMS-0057 Interoperability & Prior Authorization Final Rule denial / appeal lure — "Your prior authorization was denied under CMS-0057 final rule; submit medical records and verify insurance member ID via the patient portal before the 60-day appeal deadline expires" targeting patients and providers. The CMS-0057 PA Final Rule (effective Jan 2026) requires payers to respond in 72hr / 7d, lending the deadline-pressure framing immediate credibility. Lookalike patient portals harvest insurance member-ID, DOB, claim-number, and provider NPI — sufficient data for downstream insurance-claim fraud and synthetic-identity creation. Real CMS / payer PA-denial communications come through the patient portal directly, never via inbound email link demanding immediate upload of patient records. Distinct from `no-surprises-act-balance-billing-idr-arbitration-lure` (NSA out-of-network IDR scope). Source: GC1 R8 multiagent council (S2 healthcare specialist).threat
fake-cms-prior-authorization-final-rule-denial-appeal-lure - Fake Coinbase / Kraken / Binance / Gemini / Crypto.com exchange alert lure — "suspicious login / withdrawal attempt / unauthorized access, verify identity within 24 hours or account locked" targeting crypto exchange users; exchange credentials + 2FA + seed-phrase harvest enables $5-50K/victim irreversible theft + KYC data extractionthreat
fake-coinbase-exchange-alert-lure - Fake Teams/Slack/Zoom notification from non-official senderthreat
fake-collab-tool-notification - Fake compliance questionnaire lure — SOC 2 / ISO 27001 / NIST / HIPAA / PCI DSS questionnaire with credential-harvesting fields targeting vendor-security and compliance teams (2024-2025 Abnormal / GRC threat feeds)threat
fake-compliance-questionnaire-lure - Fake court fine / arrest warrant (danger)threat
fake-court-fine - Fake court summons, jury duty failure to appear, or arrest warrant scam — fraudulent email impersonating a court, law enforcement agency, or legal authority claiming the recipient has a pending arrest warrant, failed to appear for jury duty, or has been named in a lawsuit — directing them to click a link to pay a fine, call a number to avoid arrest, or provide Social Security number and bank account details to settle the case — an authority-impersonation fraud that exploits fear of legal consequences and criminal prosecution to extract urgent payments or steal personal financial informationthreat
fake-court-summons-jury-duty-arrest-warrant-scam - Fake crypto cloud mining / DeFi staking yield scam — fraudulent email promotes cloud mining contracts, hash-rate rentals, DeFi staking pools, or liquidity farming with implausibly high guaranteed returns (e.g. "2% daily", "180% APY", "15% weekly"); victims deposit Bitcoin, USDT, or Ethereum into Ponzi or exit-scam operationsthreat
fake-crypto-cloud-mining-staking-yield-scam - Crypto pig-butchering / romance investment fraud — guaranteed returns + deposit Bitcoin/USDT to trading platformthreat
fake-crypto-investment-pig-butchering-scam - Fake crypto investment / giveaway scamthreat
fake-crypto-investment-platform - Fake crypto trading platform / pig butchering — guaranteed daily returns + deposit USDT/Bitcoin to activate + fake profit dashboard + pay withdrawal fee/tax to release fundsthreat
fake-crypto-investment-trading-platform-scam - Fake crypto recovery service scam — recover lost/stolen Bitcoin/crypto wallet/funds + pay upfront fee/retainer/percentage to begin blockchain investigationthreat
fake-crypto-recovery-service-scam - Fake Cursor AI editor subscription expiry phishing — impersonates Cursor with subscription-expired or billing-failed urgency + renew CTA at a non-cursor.com host. Abnormal Security 2025-2026.threat
fake-cursor-ai-subscription-expiry-lure - Fake customs release fee scam — package/parcel held/seized at customs/border + pay customs duty/clearance fee or package destroyed/confiscatedthreat
fake-customs-release-fee-package-scam - Fake DAO governance flash-loan vote-hijack lure — "Emergency governance proposal P-487 — vote within 6h or treasury auto-drain triggers" via fake Snapshot / Tally / Aragon governance UI harvests delegate-signature for blank-check vote casting. 2026 DAO governance attacks: flash-loan vote-buying + Snapshot/Tally emergency proposals + on-chain timelock-bypass exploits give attackers a credible pretext. Real Snapshot / Tally / Aragon governance flows go through the protocol's verified UI on snapshot.org / snapshot.box / tally.xyz / aragon.org / commonwealth.im / boardroom.io, never via inbound email link demanding emergency-proposal vote signature within 6 hours. Crypto-drainer + signature-fatigue cluster; on-chain-governance scope. Source: GC1 R9 multiagent council P1 (S4 crypto specialist).threat
fake-dao-governance-flash-loan-vote-hijack-lure - Fake dark web personal data found identity monitoring scam — fraudulent email claiming the recipient's SSN, email, passwords, or personal information was found on the dark web or in a data breach — directing them to click a link to enroll in free identity protection, activate dark web monitoring, or remove their information — a scare-tactic lead-generation fraud that harvests personal data, sells fake credit monitoring subscriptions, or delivers malwarethreat
fake-dark-web-personal-data-found-identity-monitoring-scam - Fake debt collection scam — arrest/warrant threat or gift-card payment demand for alleged debtthreat
fake-debt-collection-scam - Fake debt collection threatthreat
fake-debt-collection-threat - Fake debt settlement / credit repair scam — settle your debt for pennies on the dollar + remove negative items from credit report + boost score 200 points + pay upfront enrollment fee + guaranteed resultsthreat
fake-debt-settlement-credit-repair-scam - Fake Deel contractor payment hold / KYC phishing — impersonates Deel with a payment-held or KYC-re-verification narrative harvesting contractor banking credentials + identity documents. Abnormal Security 2025-2026.threat
fake-deel-contractor-payment-hold-lure - Fake delivery tracking from non-carrier senderthreat
fake-delivery-tracking - Fake DMCA copyright infringement settlement fee scam — website/blog/social media uses copyrighted image/music/content without license + pay $350-$1,200 discounted settlement to avoid legal action + may impersonate Getty Images/Shutterstock + real DMCA enforcement never demands fees by emailthreat
fake-dmca-copyright-infringement-settlement-fee-scam - Fake domain name expiry or renewal invoice scam — fraudulent email impersonating a domain registrar or renewal service claiming the recipient's domain name is about to expire, registration is overdue, or a renewal invoice is outstanding — directing them to click a link and pay immediately to avoid losing their domain, having it transferred to a third party, or released to the public — a widespread spam and fraud targeting website owners and small businesses who fear losing their domain namesthreat
fake-domain-name-expiry-renewal-invoice-scam - Fake domain renewal hijack — your domain is expiring / competitors will buy it + pay immediately to renew + final notice + sent from non-registrar domainthreat
fake-domain-renewal-hijack-scam - Fake eBay second chance buyer scam — you were the highest/second bidder + winner backed out + pay directly to seller outside of eBay/platform via wire/gift card/money orderthreat
fake-ebay-second-chance-buyer-scam - Fake e-commerce unauthorized order callback scamthreat
fake-ecommerce-unauthorized-purchase-callback - Fake eIDAS 2.0 EUDI Wallet QTSP (Qualified Trust Service Provider) trust-list revocation lure — "QTSP trust-list revocation pending — re-attest your wallet provider and EUDI signing keys within 7 days or wallet-relier registration will be suspended" → fake eidas-dashboard.ec.europa.eu harvests QTSP signing keys / wallet-relier creds / Article 45a attestation-of-attributes signing material. eIDAS 2.0 EUDI Wallet rollout (member-state pilots 2025-26 → mandatory by 2027) gives attackers a real and credible regulatory pretext. Real EUDI Wallet provider attestation flows go through ec.europa.eu / enisa.europa.eu / eidas-dashboard.ec.europa.eu / member-state supervisory body portals, never via inbound email link demanding QTSP signing-key re-attestation under deadline pressure. Distinct from `eidas-2-eu-digital-identity-wallet-onboarding-lure` (R7 E2, consumer EUDI Wallet onboarding via national eID) — this signal is specifically the QTSP / trust-list / wallet-provider B2B-trust-service framing. Source: GC1 R9 multiagent council top-5 P0 (S3 EU-reg specialist).warning
fake-eidas-2-eudi-wallet-qtsp-trust-list-revocation-spoof - Fake EigenLayer / Symbiotic / Karak / etherfi / Renzo restaking slash-recovery drainer — "operator slashed, claim recovery / re-delegate withdrawal credentials / emergency re-delegate within 48 hours" targeting LRT restakers + AVS operators; signed message gives attacker withdrawal-credentials authority. Real LRT slash recovery happens through the protocol's native UI, never via emailed link. Distinct from EIP-7702 delegation drainer (general account abstraction) and R14 LRT-signup phish (onboarding shape, not slash-recovery). Source: GC1 R8 multiagent council top-5 (S4 crypto specialist).threat
fake-eigenlayer-symbiotic-restaking-slash-recovery-lure - Fake EIP-7702 (Pectra May 2025) account abstraction delegation drainer — "sign authorization tuple to delegate your EOA via setCode" / "approve delegation to enable account abstraction features" targeting Web3 wallet users; signed authorization gives delegate full write access to every token + NFT in the EOA, draining the wallet within minutes (irreversible on-chain). Distinct from generic web3-wallet-drainer-signature-lure (broad signApprovalForAll/permit) — this signal is EIP-7702 / setCode / authorization-tuple specific. Source: GC1 R7 multiagent council top-5 (S4 crypto specialist).threat
fake-eip-7702-account-abstraction-delegation-lure - Fake email/account hacked ransom (sextortion) — I hacked your device + recorded you visiting adult sites + pay Bitcoin or I send video to all your contactsthreat
fake-email-account-hacked-ransom-scam - Fake employer benefits portal redirectthreat
fake-employer-benefits-portal-redirect - Fake job offer background check fee scam — you are hired/selected + pay upfront background check / screening / training materials fee before start datethreat
fake-employment-background-check-fee-scam - Fake employment / remote job offer advance-fee equipment scam — fraudulent job offer email claims the recipient has been hired for a remote position and instructs them to purchase equipment, software, or training materials using personal funds (via gift card codes or a check overpayment scheme) with a false promise of reimbursement that is never fulfilledthreat
fake-employment-job-offer-advance-fee-equipment-scam - Fake CMS EMTALA (Emergency Medical Treatment & Active Labor Act) 409-letter ED on-call roster + transfer-log investigation lure — "CMS Region IV EMTALA complaint — submit ED on-call roster + transfer logs in 409-letter response window or civil money penalty (CMP) accruing" → spoofs CMS regional office, harvests ED scheduler / CMO creds + protected medical screening / stabilization / transfer records (PHI exfil). EMTALA enforcement uptick post-Dobbs + 2025 CMS revised SOM Appendix V give attackers a real and credible regulatory pretext. Real EMTALA investigations come through formal CMS regional-office / state-survey-agency postal correspondence + qsep.cms.gov portal, never via inbound email link demanding ED on-call roster + transfer-log submission to an unfamiliar domain. PHI +0.05% budget; B2B-hospital scope. Source: GC1 R9 multiagent council top-5 P0 (S2 healthcare specialist).threat
fake-emtala-409-letter-ed-on-call-roster-investigation-lure - Fake energy supplier switch scam — lower energy rates / switch today + provide bank direct debit details / sort code / account number to complete the switchthreat
fake-energy-supplier-switch-scam - Fake escrow payment protection buyer scam — marketplace buyer insists on using their escrow service + ship item/send crypto first + escrow will release payment after confirmation + fake escrow never releases funds + seller loses item and paymentthreat
fake-escrow-payment-protection-buyer-scam - Fake EV charging payment-failure lure — "your Tesla Supercharger / ChargePoint / EVgo charging session payment failed — update card to avoid suspension"; credit-card harvest (2024-2025 Malwarebytes / KrebsOnSecurity as EV adoption accelerates)threat
fake-ev-charging-payment-failure-lure - Fake Facebook Marketplace buyer overpayment scam — scammer poses as buyer, claims accidental overpayment via Zelle/Venmo/Cash App/PayPal, asks seller to refund the difference; the original payment is fabricatedthreat
fake-facebook-marketplace-buyer-overpayment-scam - Fake FAFSA deadline lure — "your federal student aid application is overdue, complete in 48 hours or lose eligibility" targeting US college students + families; SSN + tax-return harvest (2024-2025 FAFSA-rollout-disaster exploitation)threat
fake-fafsa-deadline-lure - Fake FBI/Interpol/NSA cybercrime arrest warrant scam — your IP linked to illegal activity/cybercrime/child porn + arrest warrant issued + pay Bitcoin/wire transfer to clear your name + do not contact a lawyerthreat
fake-fbi-interpol-cybercrime-arrest-warrant-scam - Fake FINRA Dispute Resolution Statement-of-Claim wire-fraud lure — "Statement of Claim filed against you, $1,975 filing fee due 30 days via wire / ACH / cashier's check" targeting registered representatives + retail investors named as respondents; harvested wire goes to attacker bank, not FINRA. Real FINRA filing fees pay via finra.org, never via third-party portal. Distinct from R7 F2 (T+1 settlement-failure spoof). Source: GC1 R8 multiagent council top-5 (S1 fin specialist).warning
fake-finra-arbitration-statement-of-claim-spoof - Fake free trial / negative option subscription trap — try free for 14 days just pay $4.99 S&H + auto-enrolled in $89/month subscription + cancel before trial ends or be charged monthlythreat
fake-free-trial-negative-option-subscription-trap - Fake FTC / CFPB / consumer protection settlement or class action refund scam — fraudulent email impersonating the FTC, CFPB, attorney general, or consumer protection agency claiming the recipient is eligible for an unclaimed class action settlement, government refund, or consumer compensation award — directing them to click a link, verify their identity, and provide SSN and bank routing details to receive their settlement check — an advance-fee fraud and identity theft scheme exploiting legitimate consumer protection programsthreat
fake-ftc-consumer-protection-settlement-refund-scam - Fake Geek Squad / Norton / McAfee auto-renewal billing scam — impersonates Best Buy Geek Squad or antivirus brands, claims annual protection plan auto-renewed at $299–499, provides toll-free number to "cancel" that routes to tech-support scammer who takes remote access; FTC 2022–2024: $800M+ in tech-support refund scams; FBI IC3: top-10 consumer fraud by volume; AARP: 60%+ of victims are over 60threat
fake-geek-squad-norton-auto-renewal-billing-scam - Fake gift card prize redemption scam — you won a $500 Amazon/Walmart/Visa gift card + pay small shipping/processing fee + OR boss impersonation: buy gift cards urgently + send redemption codes + reimburse laterthreat
fake-gift-card-prize-redemption-scam - Fake executive gift card purchase request scam — fraudulent email impersonates a CEO, manager, or trusted contact asking the recipient to urgently purchase gift cards (Amazon, Apple, Google Play, iTunes, Steam) and email back the redemption codes or PIN numbers, often with instructions to keep the request confidential and a promise of reimbursement — a high-volume Business Email Compromise variant that targets employees and individualsthreat
fake-gift-card-purchase-request-scam - Fake DoorDash / Uber / Lyft / Instacart / Grubhub driver-deactivation lure — "account deactivated, background recheck, payout frozen, verify within 24 hours or lose earnings" targeting 8M+ DoorDash, 5M+ Uber, 2.5M+ Lyft, 600K+ Instacart drivers; driver-license photo + SSN + bank-routing harvest → payout redirect + ghost-driver identity theft ($100-400/bundle on dark markets 2024-2025)threat
fake-gig-worker-deactivation-lure - Fake Google Business listing suspension scam — Google Business Profile/Maps listing suspended/removed + pay verification/reinstatement fee to Google-certified support teamthreat
fake-google-business-listing-suspension-scam - Fake Google Business Profile verification lure — "verify your GBP / GMB listing within 24 hours or it will be removed from Maps / Search" targeting SMB owners; Google-account credential harvest leads to phone-number redirect, review hijack, customer-PII exfil from Q&A inboxthreat
fake-google-business-profile-verification-lure - Fake Google Voice verification code hijacking scam — scammer posing as buyer, renter, or employer asks victim to share a "verification code" sent to their phone; code is actually a Google Voice setup code or 2FA token that gives the scammer control of the victim's phone number or linked accountsthreat
fake-google-voice-verification-code-hijack-scam - Fake Medicare / Medicaid / SNAP / SSI / unemployment reapplication lure — "reapply in 7 days or lose benefits" targeting seniors and low-income recipients (2024-2025 AARP FraudWatch / FBI IC3 top senior-citizen vector)threat
fake-government-benefits-reapplication-lure - Fake government grant scam (danger)threat
fake-government-grant - Fake government grant approval / advance fee scamthreat
fake-government-grant-approval-fee-scam - Fake government grant / free money scam — fraudulent email claims the recipient has been approved or selected for a government grant, federal award, or stimulus payment that "never needs to be repaid," then demands a processing or administration fee or harvests bank account and routing numbers to "disburse" funds that never arrivethreat
fake-government-grant-free-money-scam - Fake Grammarly Premium renewal phishing — impersonates Grammarly with subscription-expired or payment-failed urgency + renew CTA at a non-grammarly.com host. Cofense 2025-2026; Proofpoint Q1 2026.threat
fake-grammarly-premium-renewal-lure - Fake grandparent or family emergency scam — fraudulent email impersonating a grandchild, family member, or authority figure claiming a grandchild or relative has been arrested, is in the hospital, stranded abroad, or in an emergency — directing the recipient to urgently wire money, send gift cards, bitcoin, or Western Union to cover bail, medical bills, legal fees, or travel coststhreat
fake-grandparent-emergency-grandchild-scam - Grandparent emergency scam — family member in crisis (jail/accident/stranded) + send bail/money + keep secret from familythreat
fake-grandparent-emergency-scam - Fake government grant / unclaimed benefit scam — federal grant/stimulus/COVID relief approved + pay processing/administrative fee to release fundsthreat
fake-grant-government-benefit-claim-scam - Fake hardware-wallet firmware-update lure — impersonates Ledger (Nano S/X, Stax, Flex, Live) / Trezor (Suite, One, Model T, Safe 3) / BitBox / Coldcard / KeepKey / NGRAVE / SafePal / Ellipal with "urgent / mandatory firmware update required, install within 24 hours or device will be locked" + link to typosquat "Ledger Live" / "Trezor Suite" installer that exfiltrates seed phrase on fake device reconnection. Catastrophic loss: every wallet derived from the compromised seed drains within minutes. Ledger 2020 customer email breach (1M+ emails) continues to feed targeted campaigns through 2026. Distinct from seed-phrase-verify-phish (direct email reply harvest). Evidence: Ledger Connect Kit supply-chain attack Dec 2023 ($600K stolen); Trezor "address poisoning protection firmware" phishing wave Jan 2024; ongoing Ledger Recover / mandatory-patch impersonation 2024-2026threat
fake-hardware-wallet-firmware-update-lure - Fake health insurance enrollment scam (ACA / Medicare)threat
fake-health-insurance-enrollment-scam - Fake UnitedHealthcare / Aetna / Cigna / Anthem / Blue Cross Blue Shield / Humana / Kaiser Permanente / Oscar / Elevance / Molina / Centene health-insurance prior-auth DENIAL lure — "prior authorization denied / claim denial / coverage will be suspended, verify within 24 hours or appeal before deadline" targeting 200M+ US commercial insurance enrollees + 75M Medicaid + 64M Medicare; post-UnitedHealth 2024 auto-denial-algorithm controversy (NYT/ProPublica) primed victims to read denial lures as plausible; harvests member-ID + SSN + DOB + credit card ("$299 expedited review fee") + provider info; medical-ID bundles sell $500-1,500 on dark markets (highest per-record identity-fraud price, enables BOTH fraudulent medical billing AND regular ID theft); distinct from enrollment PII-harvest signal (covers ACA/Medicare enrollment scams, opposite attack shape)threat
fake-health-insurance-prior-auth-denial-lure - Artificially marked high-prioritythreat
fake-high-priority - High-priority flag set from a free webmail account — no legit business mails from gmail.com with X-Priority: 1threat
fake-high-priority-from-freemail - Fake HOA, homeowners association, or condominium association past-due fee lien scam — fraudulent email impersonating an HOA, condo board, or property management company claiming the recipient has unpaid dues, overdue assessments, or delinquent fines, and that a lien has been or will be placed on their property — directing them to click a link to pay, provide bank account details, credit card, or routing number to settle the balance and remove the lienthreat
fake-hoa-homeowners-association-fee-lien-scam - Fake home appliance / product warranty expiry spam — email claims refrigerator, washer, dryer, dishwasher, TV, or electronics warranty has expired, offers extended appliance protection plan via link or toll-free number; FTC: second-highest warranty robocall category; tens of millions of contacts per yearthreat
fake-home-appliance-product-warranty-expiry-spam - Fake home improvement contractor advance fee scam — roofing/paving/tree crew in your area + pay cash deposit upfront today + cash only + no contract/invoice + contractor disappearsthreat
fake-home-improvement-contractor-advance-fee-scam - Fake home / vehicle warranty expiration scamthreat
fake-home-warranty-expiration-scam - Fake State Farm / Allstate / Farmers / USAA / Liberty Mutual / Nationwide / Travelers / Chubb / Citizens Florida / Erie / American Family / The Hartford / Lemonade / Hippo homeowner-insurance NON-RENEWAL lure — "policy non-renewed / your carrier is leaving / re-verify within 24 hours or mortgage lender will force-place coverage at 3x rate" targeting 90M+ US homeowner-insurance policyholders; 2023-2026 CA + FL home-insurance crisis (State Farm stopped new CA policies May 2023, Allstate same, Farmers limited 2023-2024; 14+ carriers left FL 2022-2024) primed millions of real non-renewal letters so template is indelibly familiar; mortgage-lender force-placement threat is REAL escrow behavior (actually happens at 2-3x market rate); harvests policy number + property address + mortgage-lender + loan number (enables downstream mortgage fraud at $200-800K/victim) + SSN + CC + bank routing; distinct from iter 1015 auto-insurance (different lure framing: "mortgage force-placement" vs "driving illegally")threat
fake-homeowner-insurance-non-renewal-lure - Fake Marriott Bonvoy / Hilton Honors / World of Hyatt / IHG One Rewards / Accor ALL / Wyndham Rewards / Choice Privileges / Best Western Rewards / Radisson Rewards hotel-loyalty points-expiring lure — "your points are expiring in 48 hours, reinstate now or forfeit permanently" targeting 200M+ Bonvoy + 180M+ Hilton Honors + 50M+ Hyatt + 100M+ IHG + 90M+ Accor ALL + 100M+ Wyndham members (430M+ aggregate enrolled); points average $250-2K per account, $5-20K for high-status; post-compromise attacker transfers points, books rooms on stranger's behalf for resale, redeems for gift cards, or siphons Bonvoy→airline-miles via conversion ratio (Marriott→Delta/United/AA 3:1); dark-market liquidity 20-40% face value ($0.10-$0.40 per 100 points); redemption bypasses SSN KYC so account takeover is entire attackthreat
fake-hotel-loyalty-points-expiring-lure - Fake HR payroll redirect (BEC)threat
fake-hr-payroll-redirect - Fake immigration visa / work permit / green card approved + pay processing/courier/stamp duty fee via wire/Western Union + provide passport scan/SSN to receive visathreat
fake-immigration-visa-application-fee-scam - Fake immigration / visa fee demandthreat
fake-immigration-visa-fee-demand - Fake influencer brand collaboration advance-fee scam — fraudulent brand deal requiring upfront payment (shipping fee, check wire-back, starter kit purchase) before products or payment are received; advance funds are never reimbursedthreat
fake-influencer-brand-collaboration-advance-fee-scam - Fake inheritance / advance-fee 419 scam — purported attorney, barrister, or solicitor claims the recipient is the next of kin or beneficiary of a deceased stranger's large unclaimed estate and requires a legal, processing, or transfer fee to release the funds; or solicits a "foreign partner" to help move frozen funds in exchange for a sharethreat
fake-inheritance-advance-fee-419-scam - Fake inheritance / estate attorney advance-fee scam — you are next of kin to a deceased stranger with millions + provide bank account details + pay legal/transfer/tax fee to release fundsthreat
fake-inheritance-estate-attorney-advance-fee-scam - Fake inheritance / unclaimed estate scam — barrister/lawyer contacts you about deceased relative's millions + you are next of kin + provide bank details to transferthreat
fake-inheritance-unclaimed-estate-scam - Fake inheritance / unclaimed funds advance-fee fraud (419)threat
fake-inheritance-unclaimed-funds-advance-fee - Fake insurance settlement / class action claim processing fee — claim approved for $N + pay processing/release/tax clearance/court fee upfront to receive payoutthreat
fake-insurance-claim-processing-fee-scam - Fake investment / Ponzi scheme scam — guaranteed 30%+ monthly returns + exclusive investment fund + limited spots + capital 100% guaranteed + send funds via Bitcoin/wire transferthreat
fake-investment-high-return-ponzi-scheme-scam - Fake investment pump-and-dump stock spamthreat
fake-investment-pump-and-dump-stock-spam - Fake forex / binary options / crypto investment scam — guaranteed 15–30% monthly returns + minimum deposit + trading seminar or signal groupthreat
fake-investment-seminar-forex-trading-scam - Invoice attachment from freemail senderthreat
fake-invoice-attachment-name - Fake invoice callback scam — PayPal/Apple/Norton fake receipt + call-this-number-to-disputethreat
fake-invoice-callback-scam - Ghost Vendor Invoicethreat
fake-invoice-no-prior-relationship - Fake invoice number from freemail addressthreat
fake-invoice-number-from-freemail - Fake IRS tax refund on-hold lure — "your IRS refund of $X is on hold pending identity verification, respond within 72 hours or refund returned to Treasury" targeting US taxpayers during Jan-April refund cycle; SSN + DOB + prior-year AGI + bank-account harvest for downstream tax-return fraud (post-IRS-Notice-2023-26 Dirty-Dozen era)threat
fake-irs-refund-hold-lure - Fake IRS tax debt / arrest threat scamthreat
fake-irs-tax-debt-arrest-scam - Fake IRS tax debt collection scam — outstanding tax liability + federal arrest warrant + pay via gift cards / wire transfer / prepaid debit card to avoid prosecutionthreat
fake-irs-tax-debt-collection-scam - Fake IRS / SSA scam — tax debt arrest threat or Social Security number suspended + call immediatelythreat
fake-irs-tax-debt-social-security-scam - Fake job interview technical task malware download — "coding assessment" requires cloning GitHub repo, running scripts, installing npm/pip packages, or executing downloaded files + delivers malware + associated with North Korean APT groups and opportunistic fraudthreat
fake-job-interview-technical-task-malware-download - Fake job offer advance fee scamthreat
fake-job-offer-advance-fee - Fake job offer / reshipping scam — work from home + receive/reship packages or process payments for commissionthreat
fake-job-offer-reshipping-money-mule-scam - Fake reshipping / money mule job scamthreat
fake-job-reshipping-money-mule-scam - Fake jury duty arrest warrant scam — missed jury summons + arrest/bench warrant issued + pay fine via gift cards / prepaid card to clear warrantthreat
fake-jury-duty-warrant-scam - Fake legal/court notice lurethreat
fake-legal-court-notice-lure - Fake legal notice / lawsuit / IRS threat scamthreat
fake-legal-notice-lawsuit-threat - Fake lottery / sweepstakes prize advance-fee scam — fraudulent email claims the recipient has won a large cash prize in a lottery, sweepstakes, or prize draw and requires upfront payment of a processing, administration, legal, or withholding-tax fee before the prize can be "released"; fees escalate with each payment and no prize is ever deliveredthreat
fake-lottery-prize-advance-fee-scam - Fake lottery / sweepstakes prize claim (advance fee)threat
fake-lottery-prize-claim-advance-fee - Fake lottery / sweepstakes winner notification — your email won $X + pay processing fee/taxes to claim prizethreat
fake-lottery-sweepstakes-you-won-scam - Fake lottery winner scam (danger)threat
fake-lottery-winner - Fake Medicare / ACA / Obamacare health insurance enrollment cold solicitation scam — unsolicited email targeting seniors or uninsured individuals falsely claiming they qualify for free or subsidized Medicare Advantage, Medicare supplement, or ACA marketplace plans and urging them to call a "licensed agent" or act before a fabricated enrollment deadline — a lead-generation fraud that harvests personal information and Medicare beneficiary IDsthreat
fake-medicare-aca-health-insurance-enrollment-cold-scam - Fake Medicare medical equipment scam — free back brace/CPAP/knee brace/diabetic supplies for Medicare beneficiaries + provide Medicare ID/SSN/DOB to verify eligibilitythreat
fake-medicare-medical-equipment-scam - Fake meeting-recording-ready non-canonical-host lure — "Your Google Meet / Microsoft Teams / Webex / GoToMeeting recording is ready, click here to view" via link host NOT on the meet-canonical-host allowlist (meet.google.com, teams.microsoft.com, webex.com, gotomeeting.com, zoom.us). Generalises the pre-existing iter-1119 `fake-zoom-cloud-recording-ready-phish` (Zoom-only) to the rest of the synchronous-meet ecosystem. Synthetic-media provenance family — recording-ready notification often carries a deepfake-video payload. Hong Kong $25M Arup deepfake (Feb 2024) + 2025 LastPass / Ferrari attempts proved synthetic video at scale, lending the recording-ready brand-spoof immediate credibility. Source: Red-Team R9 multi-agent council S3 (deepfake-video specialist), Lead consensus C4.threat
fake-meet-recording-non-canonical-host-lure - Fake Meta Business Suite / Facebook Ads Manager / Instagram Ads suspension lure — "ad account suspended for policy violation, verify business within 24 hours or permanently disabled" targeting 10M+ Meta advertisers; admin credentials + 2FA harvest enables ad-spend drain ($5-500K/account), connected Pages hijack, Instagram Business pivot, WhatsApp Business impersonation, custom-audience PII exfilthreat
fake-meta-business-suite-suspension-lure - Fake MiCA (Markets in Crypto-Assets) asset-referenced-token / e-money-token white-paper notification lure — "ESMA white-paper notification deficient — 30-day cure or CASP suspended" via fake ESMA NCA portal harvests issuer treasury wallet creds + CASP authorisation submission credentials. MiCA Title III/IV (ARTs/EMTs) + Title V CASP (Crypto-Asset Service Provider) authorisation transitional ends Jul 1, 2026, lending the lure narrative immediate credibility. Real MiCA white-paper notifications go through esma.europa.eu / eba.europa.eu / member-state NCA (BaFin / AMF / CSSF / CONSOB) portals using NCA-issued credentials, never via inbound email link demanding cure within 30 days. B2B-CASP scope; SACRED `regulatory_filing` + crypto-cluster; cross-list R7 C1, R8 C6/C7. Source: GC1 R9 multiagent council P1 (S3 EU-reg specialist).threat
fake-mica-asset-referenced-token-white-paper-notification-lure - Fake Microsoft 365 / Office 365 MFA reset lure — "re-register your Authenticator app within 24 hours or account locked" targeting 400M+ M365 seats; credentials + MFA approval harvest enables attacker MFA device consent (persistent backdoor), Exchange Online mailbox exfil, SharePoint/OneDrive document exfil, Teams impersonation, Entra ID admin persistencethreat
fake-microsoft-365-mfa-reset-lure - Fake Microsoft / Apple / McAfee tech support scam — fraudulent email impersonating Microsoft, Apple, Windows Defender, McAfee, Norton, or Avast claiming a virus, malware, or security threat has been detected on the recipient's computer, or that a security license has expired — directing them to call a toll-free support number, contact a technician, or not shut down the device, a high-volume phone-based fraud that leads to remote access scams and fake repair chargesthreat
fake-microsoft-apple-tech-support-scam - Fake Microsoft/Apple tech support remote access scam — PC infected/account hacked + call toll-free number + install AnyDesk/TeamViewer + pay for virus removal servicethreat
fake-microsoft-tech-support-remote-access-scam - Fake Microsoft / Windows virus alert (tech support scam)threat
fake-microsoft-windows-virus-alert - Fake MLM / pyramid scheme recruitment — network marketing business opportunity + buy starter kit + build downline + earn from recruits' recruitsthreat
fake-mlm-pyramid-scheme-recruitment-scam - Fake Verizon / AT&T / T-Mobile / Sprint / Cricket / Mint / Visible / Boost / Xfinity Mobile / Metro / US Cellular / Google Fi / Spectrum Mobile SIM-swap / port-out / eSIM-transfer approval lure — "SIM swap request received, approve within 24 hours or confirm it wasn't you" targeting 450M+ US mobile subscribers; "Yes approve" → attacker takes over SIM and harvests ALL SMS 2FA codes (bank + crypto + retail + email); "No this wasn't me" → credential harvester for account password + PIN enabling SIM swap by attacker (FBI IC3 2024: $48M+ direct + $200M+ crypto-linked losses via Chainalysis, +32% YoY; Verizon / AT&T / T-Mobile 2023 data-breach leaks now give attackers victim's carrier + plan + last-4 of SSN for plausible phish)threat
fake-mobile-carrier-sim-swap-approval-lure - Fake money mule job offer — receive payments/packages to personal bank account + forward/wire abroad + keep % commission + reshipping coordinatorthreat
fake-money-mule-job-offer-scam - Fake loan modification / foreclosure rescue scam — guaranteed principal reduction + pay upfront fee + stop making mortgage payments + debt settlement for cents on the dollarthreat
fake-mortgage-loan-modification-scam - Fake mortgage refi rate-lock lure — "lock in 5.8% before it disappears tonight" from non-lender; SSN/DOB/bank harvest via refi form (2024-2025 Fed rate-cut cycle phish targeting US homeowners)threat
fake-mortgage-refi-rate-lock-lure - Fake MyChart / patient portal breach lure — "your MyChart account was accessed during a recent security incident, verify identity within 24 hours or access will be suspended" targeting US patients; SSN + insurance ID + DOB + medical-history harvest for medical-identity theft (post-2024 Change Healthcare / Ascension / Kaiser breach era)threat
fake-mychart-patient-portal-breach-lure - Fake mystery shopper / secret shopper advance-fee scam — victim selected as shopper, given fake cashier's check, asked to buy gift cards and wire back overpayment keeping a "commission"; FTC 2024: $337M in mystery shopper losses; average loss $1,200+threat
fake-mystery-shopper-gift-card-advance-fee-scam - Fake mystery shopper money transfer evaluation scam — hired to evaluate Western Union / MoneyGram + advance check mailed + keep $100 fee + wire the rest + evaluate gift card store by buying gift cards + check bounces + victim loses wired moneythreat
fake-mystery-shopper-money-transfer-evaluation-scam - Fake Notion workspace page/block limit phishing — impersonates Notion with page-limit-reached or billing-failed urgency + upgrade CTA at a non-notion.so host. Abnormal Security 2025-2026; Cofense Q1 2026.threat
fake-notion-workspace-limit-reached-lure - Fake online dating safety verification subscription scam — scammer asks dating app match to complete "safe dating certification" or "age verification" with credit card "just for verification" but enrolls victim in recurring adult-content subscriptionsthreat
fake-online-dating-safety-verification-subscription-scam - Fake online pharmacy prescription drug scam — buy Viagra/Cialis/Ozempic/Xanax/opioids online without a prescription + no doctor needed + ships from Canada/India/overseas + discreet packagingthreat
fake-online-pharmacy-prescription-drug-scam - Fake online task completion / Amazon review / TikTok like scam — rate products / complete simple tasks + deposit crypto/USDT/USDC to unlock/unfreeze accumulated earningsthreat
fake-online-task-completion-money-mule-scam - Fake order confirmation + callback lurethreat
fake-order-confirmation-callback - Fake overpayment / check refund scam — accidentally sent too much via cashier's check / money order + deposit it + wire back the difference / send gift card codesthreat
fake-overpayment-check-refund-scam - Fake overseas job offer visa processing fee scam — high-salary job abroad (Dubai, Canada, Germany, oil rig) + must pay visa processing fee / work permit fee / sponsorship fee before job starts + legitimate employers always cover visa costs + job does not exist + fee is the only goalthreat
fake-overseas-job-offer-visa-processing-fee-scam - Fake package delivery redelivery / customs fee scamthreat
fake-package-delivery-redelivery-fee-scam - Fake PowerSchool / Infinite Campus / Canvas / Blackboard / Schoology / Aspen / Skyward / ClassDojo parent-portal breach lure — "your child's grades / attendance / IEP records will be locked, verify within 24 hours" targeting US parents of 50M+ PowerSchool + 9M Infinite Campus + 30M Canvas students; parent credentials + student SSN + DOB harvest enables child identity theft (undetected for years until student applies for college loans)threat
fake-parent-school-portal-breach-lure - Fake password-manager breach lure — "your vault was breached" / "master password found on dark web" from non-vendor sender, targeting 1Password / Bitwarden / Dashlane / NordPass / Keeper / Proton Pass / LastPass users (2024-2026 post-LastPass pattern)threat
fake-password-manager-breach-lure - Fake 1Password / LastPass / Bitwarden / Dashlane / Keeper / Proton Pass / NordPass password-manager master-password breach lure — "your vault was accessed in a security incident, verify your master password within 24 hours or vault will be locked / wiped / re-encrypted" targeting 30M+ 1Password + 30M+ LastPass + 10M+ Bitwarden + 20M+ Dashlane users; HIGHEST-blast-radius consumer credential class — one master password unlocks EVERYTHING saved (bank + email + social + gov-ID + crypto exchanges + 2FA recovery + TOTP seeds) = complete digital takeover within hours (LastPass 2022-2023 + 1Password Sept 2023 Okta supply-chain + Norton PM 2023 credential-stuffing + Bitwarden 2024 phishing-page campaign primed the template)threat
fake-password-manager-master-breach-lure - Fake password reset phishing (danger)threat
fake-password-reset - Fake payday loan debt collection arrest threat — you owe a loan/tax debt + arrest warrant issued / criminal charges / sheriff dispatched + pay immediately via wire/prepaid card to avoid arrestthreat
fake-payday-loan-debt-collection-arrest-threat-scam - Fake payday loan guaranteed approval upfront fee scam — $1,500 payday loan approved regardless of bad credit + no credit check + pay $99 activation/insurance/processing fee upfront to release funds + loan never arrives + fee is the theftthreat
fake-payday-loan-guaranteed-approval-upfront-fee-scam - Fake payroll direct deposit change BEC scam — attacker impersonates a CEO, CFO, or HR employee and asks a payroll processor to redirect salary to a fraudster-controlled bank account before the next payroll run; email contains new routing number and account number with urgency framingthreat
fake-payroll-direct-deposit-change-bec-scam - Fake pension early release / liberation scam — cold email claiming to unlock pension before retirement age + processing/administration/liberation fee required + access retirement funds now + avoid waiting + fee is the theft vector + pension cannot legally be accessed early without HMRC penaltiesthreat
fake-pension-early-release-upfront-fee-scam - Fake police / firefighter charity fundraiser scam — Police Benevolent Fund / Firefighter Association donation request + 100% goes to officers + donate by credit card/check + most proceeds go to telemarketerthreat
fake-police-firefighter-charity-fundraiser-scam - Fake political campaign donation urgent-match scam — impersonates ActBlue, WinRed, candidates, or PACs with artificial "3×/5×/10× match expiring at midnight" urgency, routing victims to fake donation pages that harvest card details or accept gift cards / wire transfers; FTC 2024: political donation scams surged 340% during election season; FEC issued formal warnings about fake match-donation campaignsthreat
fake-political-campaign-donation-urgent-match-scam - Fake precious metals investment pitchthreat
fake-precious-metals-investment-pitch - Fake prize drawing / survey completion shipping fee scamthreat
fake-prize-drawing-survey-completion-scam - Fake prize or lottery winner notification advance-fee scam — unsolicited email falsely congratulates the recipient as the selected winner of a lottery, sweepstakes, jackpot, or prize draw and requires payment of a processing fee, clearance fee, or handling charge before the winnings can be released, a classic advance-fee fraud that harvests money or personal banking informationthreat
fake-prize-lottery-winner-notification-scam - Fake prize / lottery winner notificationthreat
fake-prize-notification - Fake foreign lottery prize notification — unsolicited winner notice for Spanish/UK/EuroMillions lottery + claim number + pay processing fee / release tax to collect winningsthreat
fake-prize-notification-foreign-lottery - Fake prize notification / foreign lottery scam — your email selected in Microsoft/Google/EuroMillions/UN lottery + you won millions + pay release fee/lottery tax + provide bank details to claimthreat
fake-prize-notification-foreign-lottery-scam - Fake property deed / home title fraud alert scam — impersonates county recorder or "Home Title Lock" services, claims victim's deed was illegally transferred or altered, harvests PII or charges fake "deed restoration" fees; FBI IC3 2023: real estate fraud $446M; AARP: 70% of victims are seniorsthreat
fake-property-deed-title-fraud-alert-scam - Fake psychic / clairvoyant / medium paid reading scam — urgent vision/message about you + pay for private reading / lucky talisman / protection ritual / deceased loved one messagethreat
fake-psychic-clairvoyant-paid-reading-scam - Fake puppy / pet adoption shipping scam — free pet to good home + pay only shipping fee / health certificate / airline crate fee / transport cost via wire or gift cardthreat
fake-puppy-pet-adoption-shipping-scam - Fake real estate / rental scamthreat
fake-real-estate-rental-scam - Fake SEC Reg NMS Rule 605/606 execution-quality disclosure lure — "Q1 2026 Rule 606 disclosure rejected, re-submit order-routing data within 7 days to avoid deficient-filing penalty" or "Rule 605 PFOF disclosure deadline approaching, file via FINRA Gateway" targeting broker-dealer compliance / supervisory staff. Real Rule 605/606 filings go through firs.finra.org / FINRA Gateway with username/password issued through FINRA on-boarding, never via inbound email link. Pure B2B-broker scope (very low FP). Quarterly recurring cycle (Q1, Q2, Q3, Q4) gives attackers four priming windows per year. Source: GC1 R8 multiagent council top-5 (S1 fin specialist).warning
fake-reg-nms-rule-606-execution-quality-disclosure-spoof - Fake rental listing or apartment deposit scam — fraudulent email impersonating a landlord, property manager, or rental listing claiming a property or apartment is available but requires an immediate wire transfer, security deposit, or advance payment to hold the unit before viewing — or requesting Social Security number, bank account details, or credit report information to complete a rental application — a real estate advance-fee fraud that exploits tight housing markets and urgency to steal deposits or harvest personal and financial information from prospective rentersthreat
fake-rental-apartment-deposit-scam - Fake rental / apartment listing advance-payment scamthreat
fake-rental-apartment-listing-scam - Fake rental car / vacation package scamthreat
fake-rental-car-vacation-package-scam - Fake rental listing advance feethreat
fake-rental-listing-advance-fee - Fake rental property advance-fee scam — below-market apartment/house/room available + owner abroad/overseas/missionary + send deposit/first month rent via Western Union/wire before viewing + keys by mailthreat
fake-rental-property-advance-fee-scam - Fake rental property advance payment scam — beautiful below-market apartment + landlord overseas / deployed + wire first/last month + security deposit to hold unit + keys mailed after payment + property does not exist or belongs to someone elsethreat
fake-rental-property-advance-payment-scam - Re: prefix but not actually a reply (thread-hijack phishing)warning
fake-reply-prefix - Fake Fidelity / Vanguard / Schwab / TIAA / Empower / Principal / Voya / Transamerica / John Hancock / Merrill Edge / T. Rowe Price retirement-account breach-framing lure — "401k / 403b / IRA / Roth / pension accessed by unauthorized device, verify within 24 hours or positions liquidated / rollover pending" targeting 43M+ Fidelity + 50M+ Vanguard + 35M+ Schwab + 18M+ Empower participants ($40T US retirement assets); typical 55+ account $200K-$2M; post-compromise = IRA-to-attacker-IRA rollover (ACATS + plan-to-plan) which is IRREVERSIBLE once funds clear — distinct from brokerage-suspension phish (active trading) and early-withdrawal-scam phish (promising payouts); users check retirement accounts quarterly so attacker has LONG windowthreat
fake-retirement-account-breach-lure - Fake reverse mortgage / equity release senior scam — access $200K home equity tax-free + no monthly payments ever + guaranteed approval + pay $495 application fee upfront + seniors 62+ targetedthreat
fake-reverse-mortgage-equity-release-senior-scam - Fake Ring / Nest / Arlo doorbell disconnection + membership lure — email impersonates Ring, Nest, Arlo, Eufy, Wyze, or Blink, warns the device will be "disconnected" or cloud-storage / subscription will lapse, and directs to a fake portal to update payment. Inky documented subject "Ring Video Doorbell Disconnection"; Snopes Jul 2025 tracked opportunistic phish wave following Ring backend bug; Malwarebytes Jul 2025 + NordVPN 2025. Distinct from fake-smart-home-device-breach-lure (breach narrative)threat
fake-ring-doorbell-disconnection-membership-lure - Fake Robinhood / Fidelity / Schwab / E*TRADE / TD Ameritrade / Webull brokerage suspension lure — "account suspended, verify within 24 hours or positions liquidated" targeting US retail investors (23M+ Robinhood, 30M+ Fidelity, 34M+ Schwab); credentials + 2FA + SSN harvest enables ACH pull from linked bank, position sell + withdraw, pump-and-dump coordinationthreat
fake-robinhood-brokerage-suspension-lure - Fake romance / pig butchering investment scam — romantic connection online + crypto trading mentor/uncle/family + exclusive trading platform + deposit USDT/Bitcoin + account frozen until you pay withdrawal feethreat
fake-romance-pig-butchering-investment-scam - Fake romance scam emergency money request — fraudulent email from a person claiming emotional attachment (fallen in love, soulmate, months of online connection) who fabricates an emergency situation (stuck overseas, oil rig, medical crisis, customs detention) and requests an urgent money transfer via Western Union, MoneyGram, wire transfer, Bitcoin, or gift card, a classic romance/pig-butchering scam pattern that causes catastrophic financial lossesthreat
fake-romance-scam-emergency-money-request - Fake romance scam / sweetheart money requestthreat
fake-romance-scam-money-request - Fake romance / online dating scam — met on dating site or social media + military/oil rig/mission cover story + urgent money requestthreat
fake-romance-scam-online-dating - Fake SaaS license audit lure — "your Microsoft / Oracle / Adobe / Salesforce licenses are over-deployed, respond in 7 days or pay $X" targeting IT admins (2024-2025 real-audit-fear exploitation)threat
fake-saas-license-audit-lure - Fake SaaS seat-overage true-up billing-reconciliation wire-redirect lure — "Your Linear / Notion / Figma / Slack annual commitment has 23 over-allocation seats in true-up; pay the past-due invoice via wire today or your workspace will be downgraded by EOD" targeting billing / IT / procurement admins. 2026 SaaS seat-overage true-up cycles (Linear, Notion, Figma, Slack) are real billing-reconciliation events, lending the lure narrative credibility. Lookalike billing portals harvest admin credentials and redirect the wire payment to attacker-controlled bank accounts. Real billing-reconciliation invoices come from the vendor's verified billing domain on a calendar cycle, never via inbound email link demanding wire transfer with end-of-day downgrade pressure. B2B-admin scope; financial-pressure cluster. Source: GC1 R8 multiagent council (S5 SaaS specialist).warning
fake-saas-seat-overage-true-up-billing-spoof - Fake SaaS workspace renewal panic + installer lure — email impersonates Slack/Zoom/Jira/Linear/Figma/Notion/Asana/Monday workspace billing, claims the workspace will be deactivated/locked/suspended without immediate renewal, and directs the user to "download the latest installer" from a typosquat host (e.g., slacks[.]pro, zoom-workspace[.]update). The installer is the drop: Malwarebytes Feb 2026 tracked Teramind backdoor via fake Zoom update; Security Boulevard Apr 2026 tracked fake Slack download delivering a hidden desktopthreat
fake-saas-workspace-renewal-panic-lure - Fake scholarship or financial aid award fee scam — fraudulent email claiming the recipient has been selected for a scholarship, grant, or financial aid award — then directing them to pay a processing, application, or acceptance fee, or to provide their Social Security number and bank routing details to receive the funds — an advance-fee and identity theft fraud exploiting students and families seeking educational fundingthreat
fake-scholarship-financial-aid-fee-scam - Fake suspicious login security alertthreat
fake-security-alert-login-lure - Fake CVE proof-of-concept / security researcher lure — claims to share a PoC exploit or malware sample for a real CVE under a "responsible disclosure" deadline, delivering a ZIP/RAR dropper disguised as a research artifact. CISA 2026 PoC-lure advisory; Cofense red-team-lure campaign 2025-2026.threat
fake-security-researcher-cve-poc-lure - Fake shipping notification (danger)threat
fake-shipping-notification - Fake Shopify store suspension lure — "store suspended due to policy violation / payout hold / DMCA complaint, verify in 24 hours or store deactivated" targeting 2M+ Shopify merchants; admin credentials + 2FA harvest enables payout redirect, customer-PII + card exfil from admin, malicious-app install, mock-page product swap, Shopify-SMTP relay abuse for trusted-IP phish-blastthreat
fake-shopify-store-suspension-lure - Fake Ring / Nest / SimpliSafe / Arlo / Wyze / Eufy / ADT / Vivint smart-home device breach lure — "your camera / doorbell / alarm was accessed by an unauthorized device, verify within 24 hours or home security suspended" targeting 10M+ Ring, 10M+ Nest, 4M+ SimpliSafe, 2M+ Arlo consumer households; post-compromise attacker watches live camera feed, disarms alarm, manipulates geofencing to know when home is unoccupied for physical-world burglary handoff (Krebs + Ars Technica 2024-2025 documented smart-home breach → physical burglary chain)threat
fake-smart-home-device-breach-lure - Fake SOC2 Type II audit evidence-collection lure — "Auditor flagged 23 missing controls — re-upload evidence to portal in 5 business days or qualified opinion" via fake `app.drata.com` / `app.vanta.com` / `app.secureframe.com` lookalikes harvests admin SSO + cloud-IAM (AWS / GCP / Azure) credentials. SOC2 Type II rolling 12-month audit windows + 2025-26 Vanta / Drata / Secureframe / TrustCloud GRC ecosystem give attackers a real and credible compliance pretext — even experienced CISOs can mistake the lookalike for a routine pre-audit evidence-collection reminder. Real SOC2 audit / evidence-collection flows go through the GRC vendor's verified domain (drata.com / vanta.com / secureframe.com / trustcloud.ai / aicpa.org) with In-Reply-To threading from an established auditor engagement, never via inbound email link demanding evidence re-upload within 5 business days under qualified-opinion threat. B2B-CISO / IT-admin scope; SSO-credential-harvest cluster; SACRED `regulatory_filing`-adjacent. Source: GC1 R9 multiagent council P1 (S5 SaaS specialist).warning
fake-soc2-type-ii-audit-evidence-collection-spoof - Fake social media account hacked friend stranded scam — friend's Facebook/Instagram/WhatsApp account hacked + friend stranded abroad after mugging + wallet/passport stolen + send $400 via Zelle or wire + keep it between us + money never recoveredthreat
fake-social-media-account-hacked-friend-stranded-scam - Fake social media account suspension appeal — impersonates Meta, Instagram, Facebook, TikTok, LinkedIn, or X/Twitter with a policy-violation / suspension narrative + fake appeals-portal CTA at a non-official host. CISA/Meta/TikTok 2025-2026; Proofpoint Q1 2026.warning
fake-social-media-account-suspension-appeal - Fake social media prize / giveaway scamthreat
fake-social-media-prize-giveaway - Fake Social Security number suspended government impersonation scam — fraudulent email impersonates the Social Security Administration (SSA) falsely claiming the recipient's Social Security number (SSN) has been suspended, blocked, or compromised due to suspicious or criminal activity, and threatening arrest, criminal charges, or legal action unless the recipient calls a number immediately to resolve the investigationthreat
fake-social-security-number-suspended-scam - Fake SSA / Social Security number suspension scamthreat
fake-social-security-number-suspension-scam - Fake Social Security suspension scam — SSN suspended due to criminal activity + call SSA officer + arrest warrant + verify SSN / buy gift cards to protect assetsthreat
fake-social-security-suspension-scam - Fake solar panel government rebate scam — free/zero-cost solar installation under federal program + claim your $8,000 rebate + limited spots + provide address/income + government-funded schemethreat
fake-solar-panel-government-rebate-scam - Fake sports betting prediction system / tipster scam — guaranteed winning picks + 97% win rate + VIP tipster subscription + beat the bookmakers + consistent monthly profits + fixed matches insider tipsthreat
fake-sports-betting-prediction-system-scam - Fake US state-tax-authority refund-verification lure — impersonates CA Franchise Tax Board (FTB) / NY Department of Taxation (DTF) / IL / TX / FL / NJ / OR / PA / MA / MI / OH / GA / NC / VA revenue departments with "your state tax refund is on hold pending identity verification, verify within 48 hours or refund forfeited" targeting US state-tax filers in the mid-April-through-July window when state refunds (which arrive weeks later than federal) are actively awaited; SSN + DL number + bank routing + AGI harvest feeds downstream refund fraud (attacker files amended state return redirecting refund). Distinct from `fake-irs-refund-hold-lure` (federal IRS). Evidence: CA FTB phishing advisories, NY DTF 2024 impersonation alerts, IRS State Tax Security Summit 2024-2025threat
fake-state-tax-refund-verification-lure - Fake streaming subscription payment failure phishthreat
fake-streaming-subscription-payment-failed - Fake Stripe Dashboard alert lure — "unusual activity on your Stripe Dashboard, review within 24 hours or payouts will be suspended" targeting SaaS founders + e-commerce merchants; Stripe credentials + 2FA harvest leads to payout-bank-redirect, Radar card-data exfil, fraudulent payouts, Stripe Connect platform pivotthreat
fake-stripe-dashboard-alert-lure - Fake Stripe Radar / risk-review RFI (Request For Information) account-restriction lure — "Account restricted — submit beneficial-ownership + bank-statement RFI within 7 days or payouts paused 90 days" via fake `dashboard.stripe.com/account-update` harvests merchant SSN / EIN + bank creds. Stripe Radar / risk-review RFIs + 2026 1099-K $2,500 threshold + dispute-rate spikes give attackers a real and credible compliance pretext. Real Stripe Radar / risk-review RFIs come from `@stripe.com`, `@payments.stripe.com`, `@email.stripe.com` with DMARC + In-Reply-To, surface inside the dashboard, and never demand SSN / EIN / bank-statement upload via inbound email link from an unfamiliar lookalike domain. Direct Gorganizer-customer overlap (Stripe-merchant base). Distinct from `stripe-atlas-delaware-franchise-tax-1120-deadline-lure` (R8 P5, Atlas C-corp tax) — this signal is specifically the Stripe Radar / RFI / account-restriction / SSN-EIN-PII framing. Source: GC1 R9 multiagent council top-5 P0 (S5 SaaS specialist).warning
fake-stripe-radar-rfi-account-restriction-spoof - Fake student loan forgiveness / advance fee scamthreat
fake-student-loan-forgiveness-advance-fee - Fake student loan forgiveness advance-fee scam — student loan forgiveness/relief/discharge program + pay enrollment/processing fee + provide FSA ID/SSN + guarantee approvalthreat
fake-student-loan-forgiveness-advance-fee-scam - Fake student loan forgiveness / debt relief scam — pre-approved forgiveness + upfront fee or FSA credentialsthreat
fake-student-loan-forgiveness-debt-relief-scam - Fake Aidvantage / MOHELA / Nelnet / EdFinancial / Great Lakes / Navient / PHEAA federal student-loan SERVICER payment-failed lure — "your auto-pay failed / account on hold, update payment within 24 hours or your loan will enter default" targeting 44M+ US federal student-loan borrowers; Oct 2023 payment-resumption chaos (after 3+ year pause) + 2024-2026 SAVE plan court-order ping-pong + post-2022 servicer consolidation (Navient+PHEAA exited, 6M+ moved to Aidvantage, 7M+ PSLF to MOHELA) all primed borrowers for servicer-specific "payment failed" emails; federal-default threat is REAL (destroys credit + wage garnishment + tax-refund blocks); harvests loan account number + SSN + DOB + bank routing (attacker reroutes future auto-pay) + servicer login; distinct from `fake-student-loan-forgiveness-phish` (Round 144, promises forgiveness — opposite attack shape) and iter 932 FAFSA-deadline (targets new applicants)threat
fake-student-loan-servicer-payment-failed-lure - Fake subscription charge scam (danger)threat
fake-subscription-charge - Fake subscription renewal + phone callback scamthreat
fake-subscription-renewal-callback - Fake subscription auto-renewal scare — Norton/McAfee/Geek Squad $200–$400 invoice + call to cancel + do not contact your bankthreat
fake-subscription-renewal-cancellation-scare - Fake sugar daddy / sugar mommy allowance upfront-fee scam — fraudster poses as a wealthy benefactor offering a weekly or monthly allowance but demands gift-card codes, a commitment deposit, an overpayment wire-back, or banking/payment-app credentials before sending any moneythreat
fake-sugar-daddy-allowance-upfront-fee-scam - Fake Supabase project-paused / migration-rollback service-role-key harvest lure — "Your Supabase project has been paused; migration rollback required to restore the database — reactivate within 7 days or your service-role / anon key will be invalidated" targeting developers who hit the inactivity-pause threshold. Free-tier auto-pause is a real Supabase behavior, lending the phish narrative immediate credibility. The fake dashboard harvests `service_role` (full Postgres bypass) + `anon` keys + RLS policy details. Real Supabase project lifecycle notifications come from supabase.com / app.supabase.com and never demand key re-input via email link. Source: GC1 R7 multiagent council (S5 SaaS specialist).warning
fake-supabase-project-paused-migration-rollback-spoof - Fake survey reward / gift card redemption scamthreat
fake-survey-reward-redemption-scam - Fake sweepstakes / entry fee contest scam — you won a national sweepstakes you never entered + pay $49 entry fee / processing fee / tax clearance fee to release your $50,000 prize + prize does not existthreat
fake-sweepstakes-entry-fee-contest-scam - Fake sweepstakes / lottery prize scamthreat
fake-sweepstakes-lottery-prize - Fake tech support scamthreat
fake-tech-support - Fake tech support / remote access scam — email impersonating Microsoft, Apple, Norton, McAfee, or Windows Defender falsely claims the recipient's computer has a virus, malware, or unauthorized access and directs them to call a toll-free number, avoid restarting, or install TeamViewer/AnyDesk so a "technician" can gain remote control and steal banking credentials or charge for fake repairsthreat
fake-tech-support-remote-access-scam - Fake tech support subscription renewalthreat
fake-tech-support-subscription-renewal - Fake telehealth / patient-portal impersonation — email impersonates MyChart, FollowMyHealth, athenaPatient, NextGen, Cerner HealtheLife, Epic Open Scheduling, Teladoc, MDLive, Amwell, or Doxy.me with a health-action hook (new secure message, test results available, refill decision, after-visit summary) + portal-login CTA pointing at an off-allowlist URL. HIPAA Journal Feb 2026: 9.65M PHI records exposed Jan-Feb 2026; Scamicide Apr 2025 personalized MyChart phish; HHS OCR Dec 2024 PIH Health $600K phishing-breach settlement; KnowBe4 2025 flagged healthcare as a priority phishing verticalthreat
fake-telehealth-patient-portal-mychart-lure - Fake ticket resale scam — concert/event tickets for sale + pay first via Zelle/Venmo + transfer after payment + cannot meet in personthreat
fake-ticket-event-resale-scam - Fake timeshare exit company scam — cancel/exit timeshare guaranteed + pay upfront/advance fee + do not contact the resortthreat
fake-timeshare-exit-company-scam - Fake trademark/patent registration agent invoice scam — annual trademark/patent renewal fee + "National Trademark Registry" or similar fake official-sounding body + trademark will lapse/be removed if unpaid + real USPTO/EUIPO fees paid directly to government, no middlemanthreat
fake-trademark-patent-registration-agent-invoice-scam - Fake TurboTax / H&R Block / TaxAct / FreeTaxUSA / Credit Karma Tax breach lure — "your tax-software account was accessed in a recent security incident, verify within 24 hours or filing access suspended" targeting 60M+ TurboTax + 10M+ H&R Block users during Jan-April filing season; prior-year return exfil is the highest-value ID-theft document ($500-2000/bundle dark market) — SSN + DOB + spouse SSN + all W-2 employers + dependents + bankingthreat
fake-turbotax-hrblock-breach-lure - Fake Twitch DMCA copyright-strike lure — email impersonates Twitch Legal / Trust & Safety, claims the recipient's channel received a DMCA copyright strike (often the "3rd strike" / repeat-infringer threshold), threatens channel termination, and provides a counter-notice/appeal link that harvests Twitch credentials. Dexerto Mar 2025: Pirate-Software impersonator false-DMCA; Bitdefender 2025: AI voice/face-clone escalation. Distinct from fake-twitch-partner-affiliate-monetization-phish (monetization) and fake-legal-court-notice-lure (court summons)threat
fake-twitch-dmca-copyright-strike-lure - Triple domain mismatch: From, List-Unsubscribe, and body unsubscribe link all differthreat
fake-unsubscribe-trap - Fake utility bill service disconnection threatthreat
fake-utility-bill-disconnect-threat - Fake utility shutoff scam — electricity/gas/water disconnection threat + pay immediately with gift cards or call fake numberthreat
fake-utility-bill-overdue-cutoff-scam - Fake utility bill overdue disconnection scam — electricity/gas/water/broadband overdue + service disconnected in 2–24 hours + pay via gift card/prepaid debit card/wire transfer immediately to avoid cutoffthreat
fake-utility-bill-overdue-disconnection-scam - Fake utility / electric / gas / water service termination payment scam — non-official sender impersonates an electric, gas, water, internet, or cable company claiming the recipient's account is overdue or past due and service will be disconnected within hours unless immediate payment is made — often demanding prepaid gift cards or directing calls to a fraudulent billing departmentthreat
fake-utility-service-termination-payment-scam - Fake utility shutoff threat scam — electricity/gas/water service disconnection today + pay via prepaid card / Green Dot / MoneyGram within hours to avoid cutoffthreat
fake-utility-shutoff-threat-scam - Fake vacation or travel prize package advance-fee scam — unsolicited email congratulating the recipient on winning a free vacation, cruise, resort stay, or travel package and requiring payment of taxes, processing fees, port fees, or activation charges before the prize can be claimed — a classic advance-fee travel fraud that harvests money and personal information with no actual travel prize deliveredthreat
fake-vacation-travel-prize-package-scam - Fake vehicle extended warranty expiration scam — unsolicited email falsely claims the recipient's car or vehicle warranty is expiring, expired, or about to lapse and urges an immediate call to a toll-free number or online action to renew or activate an extended warranty or service contract before a fabricated deadlinethreat
fake-vehicle-extended-warranty-expiration-scam - Fake vehicle extended warranty expiry spam — email claims car/truck warranty expired or is expiring, offers extended warranty / protection plan via link or toll-free number that harvests payment card details; FTC top consumer complaint 2022-2024; FCC fined $300M+ to warranty robocallersthreat
fake-vehicle-extended-warranty-expiry-spam - Fake vehicle warranty expiration scam — vehicle/auto warranty expiring or expired + final notice + call now to extend coverage + limited time offerthreat
fake-vehicle-warranty-expiration-scam - Fake Venmo / Cash App / Zelle P2P verification lure — "$400 payment pending, unauthorized transfer, verify within 24 hours or payment reverses" targeting 90M+ Venmo / 55M+ Cash App / Zelle-on-any-US-bank users; credentials + bank routing harvest enables reverse-direction drain, fake-payment-refund scams (BBB + FTC #1 growing consumer fraud 2024-2025)threat
fake-venmo-cashapp-p2p-verification-lure - Fake Venmo, Cash App, or Zelle money request or pending payment scam — fraudulent email impersonating Venmo, Cash App, Zelle, or PayPal Friends and Family claiming the recipient has a pending payment, money transfer, or payment request waiting — directing them to click a link to accept, confirm account details, or verify their identity to receive the funds — a social engineering and credential-harvesting attack that exploits the increasing prevalence of peer-to-peer payment apps to deceive recipients into clicking phishing links or providing account credentialsthreat
fake-venmo-cashapp-zelle-money-request-scam - Fake veterans benefits claim assistance scam — unclaimed VA disability/pension benefits + pay upfront fee / percentage / coaching fee + guarantee approvalthreat
fake-veterans-benefits-claim-assistance-scam - Fake Meeting Linkthreat
fake-video-meeting-url - Fake weight-loss miracle supplement spamthreat
fake-weight-loss-miracle-supplement-spam - Fake Wise (TransferWise) international transfer verification phishing — impersonates Wise with a transfer-held / account-restricted urgency + verify-identity CTA at a non-wise.com host. FCA / FinCEN 2025-2026.threat
fake-wise-transfer-verification-lure - Fake work-from-home equipment / overpayment check scam — victim hired as virtual assistant, sent fake cashier's check far exceeding salary, asked to buy equipment or wire the remainder; check bounces, victim owes full amount; FTC 2023: $440M in fake-check losses, employment variant fastest-growingthreat
fake-work-from-home-equipment-check-scam - Fake work-from-home reshipping / package inspector job scam — receive packages at home address + inspect and reship/forward to overseas warehouse + earn per packagethreat
fake-work-from-home-reshipping-mule-scam - Gig platform earnings-hold / payment-delay scam — impersonates Uber, Lyft, DoorDash, or Instacart claiming earned wages are on hold and requiring bank account or tax-form verification to release. Abnormal Security Feb 2026; FTC Mar 2026; KrebsOnSecurity Jan 2026.threat
gig-platform-earnings-hold-payment-delay-scam - Fake Google Drive share notificationthreat
google-drive-fake-share-notification - Fake hardware-wallet firmware-update brand-spoof — "Critical Ledger Live / Trezor Suite firmware update — install before 2026 Pectra/EIP-7702 migration" from sender NOT on the hw-wallet canonical-allowlist (ledger.com, trezor.io, tangem.com, gridplus.io, keyst.one, shiftcrypto.ch, coinkite.com, foundationdevices.com, cypherock.com). Real wallet-vendor firmware updates ship through the vendor's signed app (Ledger Live / Trezor Suite) — never via inbound email link. Distinct from `hw-wallet-seed-phrase-reveal-phish` (R9 batch 1, direct SRP harvest) — this signal is specifically the firmware-update pretext, not seed-phrase harvest; the two can co-fire on a single email combining both pretexts. Ledger Connect Kit Dec 2023 ($600K loss) + Trezor T firmware downgrade attacks + Tangem NFC-cloning research (2024) proved the firmware-update vector. Source: Red-Team R9 multi-agent council S4 (hardware-wallet-firmware specialist).threat
hw-wallet-firmware-update-spoof-lure - Unclaimed inheritance scam (danger)threat
inheritance-scam - Investment / guaranteed returns scam (danger)threat
investment-scam - IRS tax payment gift card scamthreat
irs-tax-payment-gift-card-scam - IRS tax phone scam — back taxes owed + call to avoid arrest / gift-card payment / asset seizure threatthreat
irs-tax-phone-scam - LLM-personalized romance pig-butchering follow-up — LLM-generated email from a freemail sender using hyper-personalized romantic framing and an investment-pivot "uncle/mentor" narrative. Group-IB 2026; FBI IC3 PSA 2025 ($5.8B); Stanford IO Mar 2026.warning
llm-personalized-romance-pig-butchering-followup - M365 Direct Send internal spoof — From-domain == To-domain + Outlook relay + SPF/DKIM/DMARC fail (Varonis 2025)threat
m365-direct-send-internal-spoof - Fake Medicare Advantage open enrollment / AEP urgency lure with a deadline and non-.gov link or phone number — real Medicare enrollment communications come from medicare.gov (CMS) and licensed agents following CMS marketing guidelines.warning
medicare-advantage-switch-period - Medicare DME billing fraudthreat
medicare-dme-billing-fraud - Fake Medicare flex card / OTC over-the-counter benefit card offer targeting seniors — "you qualify for a free Medicare flex card worth $XXX for groceries, dental, vision, or hearing" harvesting Medicare Beneficiary Identifier (MBI), SSN, and banking details for Medicare fraud + identity theftthreat
medicare-flex-card-otc-benefit-scam - Medicare supplement identity theftthreat
medicare-supplement-identity-theft - MLM / pyramid scheme recruitmentthreat
mlm-pyramid-recruitment-spam - MLM/pyramid scheme recruitment languagethreat
mlm-pyramid-scheme - Fake mobile banking app verification lurethreat
mobile-banking-app-fake-verification-lure - Money mule / financial agent scam — receive funds to your account + keep % + forward the restthreat
money-mule-scam - Mystery shopper check scamthreat
mystery-shopper-check-scam - Nigerian prince / inheritance / 419 scamthreat
nigerian-prince-inheritance-scam - Advance-fee / Nigerian prince scamthreat
nigerian-prince-pattern - Fake nonprofit / charity donation receipt from a freemail domain (gmail, yahoo, hotmail) with both urgency language and a payment link — real donation receipts are proof of payment already made and never contain payment links.warning
nonprofit-donor-receipt-spoof - Fake OIDC Back-Channel Logout 1.0 spoof lure — fake `logout_token` JWT delivered out-of-band; if the relying-party (RP) honors it w/o iss/aud claim verification, the user is kicked back to attacker re-login. Sender NOT on the canonical IdP allowlist (okta.com, auth0.com, microsoft.com, microsoftonline.com, azure.com, login.microsoftonline.com, google.com, accounts.google.com, workspace.google.com, amazon.com, amazonaws.com, awsapps.com, onelogin.com, pingidentity.com, forgerock.com, jumpcloud.com, duo.com, cisco.com, idaptive.com, cyberark.com, sailpoint.com, oneidentity.com). Real IdP back-channel logout notifications never arrive as inbound user-facing email — the logout_token is a server-to-server POST to the RP's `backchannel_logout_uri`. Distinct from R7 PAR / device-code / passkey auth-protocol-param family — this signal is specifically the OIDC Back-Channel Logout 1.0 primitive (openid.net/specs/openid-connect-backchannel-1_0.html). Source: Red-Team R8 multi-agent council S3 (technical-AiTM specialist), Lead consensus C2.threat
oidc-backchannel-logout-spoof-lure - Overpayment reversal scamthreat
overpayment-reversal-scam - Package customs fee scamthreat
package-customs-fee-scam - Fake PayPal / Venmo payment scamthreat
paypal-venmo-payment-scam - Pig-Butchering / Sha Zhu Pan Scamthreat
pig-butchering-investment-lure - Fake CA-issuer post-quantum cert reissuance lure — "Your TLS certificate must be reissued to ML-DSA-65 / Dilithium-III before CA/B Forum 2027 deadline" via spoofed Let's Encrypt / DigiCert / Sectigo / Entrust / GlobalSign / SSL.com. Sender NOT on the CA canonical-allowlist (letsencrypt.org, digicert.com, sectigo.com, entrust.com, globalsign.com, ssl.com, identrust.com, godaddy.com, certum.eu, cabforum.org, ietf.org, nist.gov) and NOT under the .gov umbrella. Real CA renewals are ACME-driven or come through the issuer's portal, never via inbound email link demanding cert reissuance under a PQC-migration deadline. Distinct from `pqc-hndl-extortion-lure` (R9 batch 1, ransom variant) and `pqc-certificate-migration-phishing` — this signal specifically targets the cert-reissuance pretext aimed at site operators / DevOps. Niche but high-blast-radius (cert MITM downstream). Source: Red-Team R9 multi-agent council S1 (post-quantum specialist), Lead consensus C1 dissent S1-C.threat
pqc-cert-reissuance-spoof-lure - Puppy / kitten shipping scamthreat
puppy-kitten-shipping-scam - QR code parking payment scam (danger)threat
qr-code-parking-scam - Job scam keywords: "hiring immediately", "no experience needed"threat
recruitment-job-scam - Rental advance fraud — landlord abroad + mail keys after payment + Western Union depositthreat
rental-advance-fraud - Romance / widow scam indicatorthreat
romance-scam-indicator - Romance scam money requestthreat
romance-scam-money-request - Fake Google Workspace / Microsoft 365 / Slack / Zoom / Atlassian workspace admin invoice — sender domain does NOT match the claimed platform domain; urgency + billing-portal link redirecting to off-brand payment portal.warning
saas-workspace-admin-invoice-spoof - Shipping/customs fee demand from non-carrier senderthreat
shipping-fee-scam - Social media verified badge scamthreat
social-media-verified-badge-scam - Social Security / Medicare scam — SSN suspended + urgent call / arrest threat / gift-card payment demandthreat
social-security-benefit-scam - Social Security suspension scamthreat
social-security-suspension-scam - Stranded traveler emergency wire scamthreat
stranded-traveler-emergency-wire-scam - Student loan forgiveness fee scamthreat
student-loan-forgiveness-fee-scam - Student loan forgiveness scam — fake DoE/debt-relief company + upfront fee or FSA ID harvestthreat
student-loan-forgiveness-scam - Fake subscription renewal callbackthreat
subscription-renewal-callback-scam - Sweepstakes / prize draw spamwarning
sweepstakes-spam - Timeshare exit scamthreat
timeshare-exit-scam - Utility disconnect threat scamthreat
utility-disconnect-threat-scam - Visa / immigration scam — fake visa/green card approval + processing fee to release documentsthreat
visa-immigration-scam - Warranty expiration scam with urgency CTAthreat
warranty-scam
Want to see them in action?
Connect your Gmail in 10 seconds and Gorganizer will show you exactly which signals fired on every email — colour-coded by severity, with full explanations.
Get started