Fake Coinbase / Kraken / Binance / Gemini / Crypto.com exchange alert lure — "suspicious login / withdrawal attempt / unauthorized access, verify identity within 24 hours or account locked" targeting crypto exchange users; exchange credentials + 2FA + seed-phrase harvest enables $5-50K/victim irreversible theft + KYC data extraction
fake-coinbase-exchange-alert-lure
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Fake "suspicious activity / unauthorized login / withdrawal attempt on your Coinbase / Kraken / Binance / Gemini / Crypto.com account — verify your identity within 24 hours or your account will be locked" email targeting crypto exchange users. Harvests exchange credentials, 2FA codes, and (in the worst variants) seed phrases. Post-compromise attackers empty the victim's entire crypto balance within minutes, pivot to any linked wallet, and extract KYC data (passport, SSN, address) from the account profile. Crypto exchange accounts are the highest-per-victim-value single credential target on the internet — average balance at top exchanges in 2026 is $5-50K, and theft is irreversible (no chargebacks, no fraud-dispute process). Chainalysis and BleepingComputer documented sustained 2024-2025 campaigns; 2026 variants combine fake withdrawal alerts with fake support phone numbers for the callback phase. Fires when body references Coinbase / Kraken / Binance / Gemini / Crypto.com / Bitstamp / KuCoin / exchange account / crypto withdrawal AND contains suspicious-login / unauthorized-access / withdrawal-attempt / account-locked / verify-identity urgency. Excludes coinbase.com (+.co, +.pro), kraken.com, binance.com (+.us), gemini.com, crypto.com, bitstamp.net, kucoin.com, bitfinex.com, okx.com, bybit.com, plus dead-exchange umbrellas for completeness. Auto-classified as danger via the `-lure` suffix.
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started