
Summary
Rule detects inbound emails sent to Outlook group distribution lists (groups.outlook.com) where the message body is classified with high confidence as a callback scam by an NLU model. It requires that every recipient is a groups.outlook.com address (non-empty recipient list) and excludes messages where recipients are empty or entirely invalid. When the body text of the current thread yields an intent named 'callback_scam' with high confidence, the rule fires as a medium-severity detection of Callback Phishing. Detection methods combine Natural Language Understanding of the message body and header/recipient context to reduce false positives by focusing on group-based distribution lists rather than individual recipients. The rule is effective for identifying social-engineering attempts delivered through Outlook groups, but may miss clever campaigns that avoid explicit 'callback_scam' intents or rely on non-text content.
Categories
- Web
- Application
Data Sources
- Group
Created: 2026-08-28