Skip to main content

Phishing Threat Database

How do we catch these threats?

The Cofense Phishing Detection Center (PDC) acts as a SOC-as-a-service, supporting thousands of leading organizations. With over 35 million trained users and real-time threat reporting, our platform combines automated analysis with expert verification, ensuring reliable and efficient protection. Here, you’ll find real-world phishing emails that bypassed even advanced security measures, posing risks to revenue and reputation.

Cisco IronPort

Booking.com-spoofing emails found in environments protected by Cisco IronPort and Microsoft ATP deliver an embedded link to a fake CAPTCHA website that delivers a malicious PowerShell Script to the clipboard. When run, the script delivers PureRAT.

Posted On: March 27, 2026 Tactic: Embedded Link Theme: Spoofing

Microsoft ATP

Booking.com-spoofing emails found in environments protected by Cisco IronPort and Microsoft ATP deliver an embedded link to a fake CAPTCHA website that delivers a malicious PowerShell Script to the clipboard. When run, the script delivers PureRAT.

Posted On: March 27, 2026 Tactic: Embedded Link Theme: Spoofing

Mimecast

Voicemail-themed emails found in environments protected by Abnormal Security, Mimecast, and Microsoft ATP deliver an attached PDF that contains a link to an OAuth 2.0-based Credential Phishing site.

Posted On: March 26, 2026 Tactic: PDF Attachment Theme: Voicemail

Abnormal Security

Voicemail-themed emails found in environments protected by Abnormal Security, Mimecast, and Microsoft ATP deliver an attached PDF that contains a link to an OAuth 2.0-based Credential Phishing site.

Posted On: March 26, 2026 Tactic: PDF Attachment Theme: Voicemail

Microsoft ATP

Voicemail-themed emails found in environments protected by Abnormal Security, Mimecast, and Microsoft ATP deliver an attached PDF that contains a link to an OAuth 2.0-based Credential Phishing site.

Posted On: March 26, 2026 Tactic: PDF Attachment Theme: Voicemail

Microsoft ATP

Griffin Editions-spoofing emails found in environments protected by Microsoft ATP, Proofpoint, Cisco IronPort, and Check Point delivers Sectop RAT via an embedded URL to a fake CAPTCHA that prompts to run a PowerShell script from clipboard.

Posted On: March 25, 2026 Tactic: Embedded Link Theme: Spoofing

Microsoft ATP

Griffin Editions-spoofing emails found in environments protected by Microsoft ATP, Proofpoint, Cisco IronPort, and Check Point delivers Sectop RAT via an embedded URL to a fake CAPTCHA that prompts to run a PowerShell script from clipboard.

Posted On: March 25, 2026 Tactic: Embedded Link Theme: Spoofing

Microsoft ATP

Microsoft-spoofing emails found in environments protected by Microsoft ATP deliver a multi-stage ConnectWise RAT via an embedded URL.

Posted On: March 25, 2026 Tactic: Embedded Link Theme: Spoofing

Cisco IronPort

Griffin Editions-spoofing emails found in environments protected by Microsoft ATP, Proofpoint, Cisco IronPort, and Check Point delivers Sectop RAT via an embedded URL to a fake CAPTCHA that prompts to run a PowerShell script from clipboard.

Posted On: March 25, 2026 Tactic: Embedded Link Theme: Spoofing

Check Point

Griffin Editions-spoofing emails found in environments protected by Microsoft ATP, Proofpoint, Cisco IronPort, and Check Point delivers Sectop RAT via an embedded URL to a fake CAPTCHA that prompts to run a PowerShell script from clipboard.

Posted On: March 25, 2026 Tactic: Embedded Link Theme: Spoofing

Cisco IronPort

Social Security Administration-spoofing emails found in environments protected by Microsoft ATP and Cisco IronPort deliver a ConnectWise RAT via an embedded URL.

Posted On: March 23, 2026 Tactic: Embedded Link Theme: Spoofing

Microsoft ATP

Social Security Administration-spoofing emails found in environments protected by Microsoft ATP and Cisco IronPort deliver a ConnectWise RAT via an embedded URL.

Posted On: March 23, 2026 Tactic: Embedded Link Theme: Spoofing