
Summary
Detects inbound email messages that impersonate SoFi by analyzing sender display name, content, and headers to identify brand impersonation and credential phishing signals. The rule looks for SoFi-related terms in the body (e.g., SoFi bank/invest/securities/team/tech/wealth), a copyright line containing ©20XX with sofi or social finance, and specific SoFi support phone numbers. It also checks for an exact SoFi street address (2750 E Cottonwood Pkwy, Salt Lake City, UT 84121) and for indicators of credential theft (e.g., trade confirmation or self-directed investing account) when the sender display name includes “sofi.” To reduce false positives, it excludes legitimate replies (references, forwards/replies, previous threads) and newsletters (topic not equal to “Newsletters and Digests”). Additional negations exclude messages from SoFi-related or observed partner domains unless DMARC passes, and exclude messages from high-trust sender roots if DMARC passes. Detection methods include content, header, and sender analysis, plus NLP topic filtering and URL/domain checks, applied to inbound mail in context of brand impersonation and credential phishing."
Categories
- Web
- Application
- Identity Management
Data Sources
- Domain Name
Created: 2026-08-07