← All detection heuristics · Social Engineering
high
SE_GOV_CREDENTIAL_PHISH
What it means
Document impersonates a government agency and uses identity/benefits-verification coercion to drive the reader to a non-.gov link.
Why it fires
The rule fires when a government-agency identity (Social Security Administration, IRS, Medicare/Medicaid, US Treasury, HMRC, DWP, USCIS, Service Canada, etc.) appears together with identity/benefits-verification coercion language ("identity verification required", "this review is mandatory", "temporary account restrictions", "failure to verify") AND the document's action link is NOT an official .gov/.mil destination. A genuine agency notice links to its own government domain, so the non-gov link is the phishing tell that keeps false positives near zero.
Other Social Engineering heuristics
SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY