Government-agency impersonation credential phishing lure

SE_GOV_CREDENTIAL_PHISH

← All detection heuristics · Social Engineering

high SE_GOV_CREDENTIAL_PHISH

What it means

Document impersonates a government agency and uses identity/benefits-verification coercion to drive the reader to a non-.gov link.

Why it fires

The rule fires when a government-agency identity (Social Security Administration, IRS, Medicare/Medicaid, US Treasury, HMRC, DWP, USCIS, Service Canada, etc.) appears together with identity/benefits-verification coercion language ("identity verification required", "this review is mandatory", "temporary account restrictions", "failure to verify") AND the document's action link is NOT an official .gov/.mil destination. A genuine agency notice links to its own government domain, so the non-gov link is the phishing tell that keeps false positives near zero.

Other Social Engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY