Skip to main content
ThreatPhishing & impersonation

Meeting transcript attachment phishing lure — fake Zoom / Teams / Meet transcript PDF/DOCX with embedded phishing URLs framed as "action items" (Proofpoint / KnowBe4 / Abnormal 2025 campaigns)

meeting-transcript-attachment-phishing-lure

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Email delivers a fake meeting-transcript document (.pdf, .docx, .doc, .txt, .rtf) claiming to be the transcript, recording, summary, or call-log from a recent Zoom / Microsoft Teams / Google Meet / Webex / GoToMeeting / BlueJeans / Jitsi / Riverside / Loom / Fathom / Otter.ai / Grain session. Proofpoint, KnowBe4, and Abnormal Security documented multiple 2025 campaigns where attackers used AI-generated transcripts from ChatGPT or Claude to give phishing emails contextual legitimacy — recipients trust "meeting notes" and "action items" documents far more than cold invoices or unsolicited package notifications. The transcript body contains embedded phishing URLs framed as "the shared link from the meeting" or "the action item I mentioned." Fires when the email has a transcript-shaped attachment filename (containing transcript/recording/minutes/notes/summary/call-log keywords) with a document extension (.pdf / .doc(x) / .txt / .rtf) AND the subject or body references a meeting context. Excludes known videoconferencing vendors (Zoom, Microsoft, Google Meet, Webex, GoToMeeting, BlueJeans, Jitsi, Riverside, Loom, Fathom, Otter.ai, Grain) who send real transcripts through their own infrastructure, reply threads, and newsletters discussing transcript tools. Auto-classified as danger via the `-lure` suffix.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started