heroui logo

Service Abuse: American Express callback scam

Sublime Rules

View Source
Summary
This rule detects a specific callback-phishing tactic that fraudulently uses American Express branding. It targets inbound emails where the sender’s domain resolves to americanexpress.com. The detector looks for a greeting line in the email body matching the pattern: "Hello, <name>" followed by a newline. If such a line is found, the captured <name> is fed into a natural language classifier (ml.nlu_classifier on the captured name) to assess intent. If the classifier returns an intent named "callback_scam", the rule triggers. The combined signals—sender-domain trust check, a structured greeting from the message body, and classifier-confirmed intent—aim to reduce false positives by requiring both a recognizable scam-intent pattern and the framing of a personal greeting that aligns with the known callback-scam pattern. This approach uses content analysis (NLU), sender analysis, and pattern extraction to identify social-engineering attempts that impersonate a trusted brand. The rule is categorized as high severity, reflecting the risk of credential or information exfiltration if a user calls a listed phone number. Potential limitations include variations in greeting formats (e.g., different salutations or missing newline), multilingual or obfuscated content, and dependence on classifier training quality. Operators should ensure the ML model is kept current with evolving scam patterns and consider accommodating alternate greet formats to reduce misses while maintaining low false positives.
Categories
  • Web
Data Sources
  • Domain Name
Created: 2026-10-06