heroui logo

Brand impersonation: SoFi

Sublime Rules

View Source
Summary
Detects inbound email messages that impersonate SoFi by analyzing sender display name, content, and headers to identify brand impersonation and credential phishing signals. The rule looks for SoFi-related terms in the body (e.g., SoFi bank/invest/securities/team/tech/wealth), a copyright line containing ©20XX with sofi or social finance, and specific SoFi support phone numbers. It also checks for an exact SoFi street address (2750 E Cottonwood Pkwy, Salt Lake City, UT 84121) and for indicators of credential theft (e.g., trade confirmation or self-directed investing account) when the sender display name includes “sofi.” To reduce false positives, it excludes legitimate replies (references, forwards/replies, previous threads) and newsletters (topic not equal to “Newsletters and Digests”). Additional negations exclude messages from SoFi-related or observed partner domains unless DMARC passes, and exclude messages from high-trust sender roots if DMARC passes. Detection methods include content, header, and sender analysis, plus NLP topic filtering and URL/domain checks, applied to inbound mail in context of brand impersonation and credential phishing."
Categories
  • Web
  • Application
  • Identity Management
Data Sources
  • Domain Name
Created: 2026-08-07