LureSight Community Watch

Live trends from phishing emails reported by the LureSight community. Every submission is scrubbed of personal information and carries no identifier linking it to the reporter — what you see here is the attackers, not the reporters.

Know the techniques

The tricks behind the numbers above — every one of these has been seen in real reported mail, and every one is something LureSight checks for.

Lookalike & disguised domains

Domains built to pass a glance: paypa1-secure.com, rnicrosoft-login.top — swapped letters, brand-plus-extra-words, risky endings like .top.

Tell: read the domain right-to-left; the part before the last dot is who you're really visiting.

Link text ≠ destination

The words say paypal.com; the link opens somewhere else entirely — sometimes hidden behind redirectors, security-gateway wrappers, or base64 encoding.

Tell: long-press or hover a link to see where it really goes before you tap.

Callback phishing (TOAD)

A fake charge — "$486.77 renewed" — and a phone number to call to cancel. No links at all; the scam happens on the phone, where no filter can follow.

Tell: real companies let you manage charges in your account. Never call numbers from the email.

QR-code phishing ("quishing")

The link is hidden inside a QR code image, so email security can't read it — and scanning moves you onto your phone, away from protection.

Tell: a legitimate sender has no reason to make you scan a code from an email on the same device.

Image-only messages

The entire "invoice" is one big picture — amounts, threats, and phone numbers rendered as pixels that text filters can't see.

Tell: if you can't select the text with your cursor, someone chose to hide it from scanners.

Brand impersonation

Real logos (often hotlinked from Wikipedia), copied email templates, and display names one letter off — "DocSign" — from mailboxes with no connection to the brand.

Tell: check the actual sending address and where links point, not the pictures.

Compromised trusted accounts

A real colleague or vendor's hacked mailbox mails their whole contact list a fake "attachment" — a link dressed as Document.pdf that opens a file-sharing site.

Tell: unexpected file links from known senders deserve a phone call, not a click.

Mass-merge harvesting

"Personalized" to random-character names ("Hello Uvpixhuymn"), pushing government-benefit or prize lures with fine print admitting it's a "non-government site."

Tell: agencies mail from .gov, and real senders know your actual name.

Sender ≠ who they claim to be

The message presents itself as being from a company — in the signature, the footer, or the display name — but the address it was actually sent from is an unrelated domain. Works for any organization, not just famous brands.

Tell: read the actual email address, not the display name. "Meridian Bank" from a gmail.com or a secure-pay-portal.top address is not Meridian Bank.

Crypto "airdrop" & free-money lures

"You've been selected" for an airdrop, token eligibility, or fee rebate — enter a code or claim link to unlock rewards. Often invokes a real crypto or prediction-market brand (Polymarket, Coinbase) from an unrelated sender.

Tell: real token distributions are never claimed through an unsolicited email link. The brand name in the text won't match the sending domain.

Pressure language

"Within 24 hours," "account suspended," "verify immediately," secrecy and "quick favor" asks — urgency exists to make you act before you think.

Tell: manufactured deadlines are the oldest trick there is. Slow down; verify independently.

Authentication failures

SPF, DKIM, and DMARC are how mail proves who sent it. Failures — or "passing" only because the scammer used a real free-mail account — are hidden in the headers.

Tell: you can't see headers easily, which is exactly why LureSight reads them for you.