Third-Party Service Misuse
Attackers exploit trusted platforms—such as PayPal, DocuSign, Microsoft 365, or e-commerce and invoicing services—to deliver phishing content. These appear as legitimate notifications but contain links or prompts that lead to attacker-controlled infrastructure.
Mapped to
MITRE ATT&CK®