heroui logo

Service abuse: Power Automate callback scam

Sublime Rules

View Source
Summary
Detects inbound messages received from Power Automate’s official notification address (powerautomatenoreply@microsoft.com) where the message body is analyzed by an NLU model. If the NLU classifier identifies an intent named callback_scam with high confidence, the rule flags potential abuse of the Power Automate service to deliver callback scam content. This targets social-engineering driven phishing attempts that leverage legitimate automation channels. The rule ties inbound message data with sender analysis and NLP to surface credible callback scam content masquerading as legitimate automation notifications. It is labeled with medium severity and categorized under callback phishing and social engineering techniques.
Categories
  • Endpoint
  • Web
  • Application
Data Sources
  • Network Traffic
  • Application Log
Created: 2026-09-04