◆ kanex-ai
Loading…
Kelvin Yan Aug 16 1:13 AM
Re: Furnished 1BR at Veer Towers / CityCenter — owner inquiry, immediate move-in
⚠ PHISHING: employee impersonation: display name matches 'kelvin yan' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 7:55 PM
TEST — Veer 304E, how the Izeal reply will look
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 7:46 PM
Veer Towers 304E - furnished 1BR, corporate housing
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Kelvin Yan Aug 15 7:34 PM
Veer 304E — three drafts for review before sending
⚠ PHISHING: employee impersonation: display name matches 'kelvin yan' but sender is email.sydneeinc.com
phishing urgent
Bank of America Aug 15 5:44 PM
Your statement is available
Bank of America: Your statement is available
financial
Bank of America Aug 15 5:43 PM
Your statement is available
Bank of America: Your statement is available
financial
Sydnee Agent (AI) Aug 15 5:39 PM
[Calibration Daily] 2026-08-16
Sydnee Agent (AI): [Calibration Daily] 2026-08-16
employee high
Sydnee Inc Legal Aug 15 5:34 PM
Access test 1 of 3 - link
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 5:33 PM
Access test 3 of 3 - verified
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 5:09 PM
Access test 3 of 3 - verified
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 5:09 PM
Access test 1 of 3 - link
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:48 PM
Access test 1 of 3 - link (opens straight away, no code)
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Microsoft Outlook Aug 15 4:47 PM
Undeliverable: FW: Dr Cat's Video Insights on $NOW and $TEAM-Video 2 of 12 (August 16, 2026)
Microsoft Outlook: Undeliverable: FW: Dr Cat's Video Insights on $NOW and $TEAM
employee high
Microsoft Outlook Aug 15 4:46 PM
Undeliverable: FW: Dr Cat's Video Insights on $ABCL-Video 3 of 12 (August 16, 2026)
Microsoft Outlook: Undeliverable: FW: Dr Cat's Video Insights on $ABCL-Video 3
employee high
Sydnee Inc Legal Aug 15 4:26 PM
Veer 304E - all three access levels
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:16 PM
Veer 304E - replacement links
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:10 PM
Veer 304E - short links, one with a code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:04 PM
Your access code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:04 PM
Your access code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:00 PM
Veer 304E - test of the secure file links
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Sydnee Inc Legal Aug 15 4:00 PM
Your access code
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydneeinc.com
phishing urgent
Amazon Payments Aug 15 12:52 PM
Action requise sur le compte Amazon Payments
Fake Amazon Payments suspension threat; credential harvesting attempt.
phishing urgent
Guest Relations at The Ritz-Carlton, Laguna Niguel Aug 15 10:49 AM
Kelvin, please complete the travel request form to customize your stay at The Ritz-Carlton, Laguna Niguel
Suspicious Ritz-Carlton email with obfuscation; potential credential theft attempt.
phishing urgent
Manus Team Aug 15 7:33 AM
ACTION REQUIRED: 7 days left to back up Kelvin Yan for future restoration
⚠ PHISHING: phishing subject pattern: 'ACTION REQUIRED' from external sender privaterelay.appleid.com
phishing urgent
Benjamin & Williams Aug 15 5:02 AM
Commercial Claim Discovery Documents Our file:D-8222 Debtor: VICTORIA ROPA ELEGANTE
Fake debt collection demand with 24h payment pressure; spoofed domain.
phishing urgent
Sydnee Agent (AI) Aug 15 4:15 AM
Sydnee nightly — PERFORMANCE audit 2026-08-15 — 0P0 2P1 13R
Sydnee Agent (AI): Sydnee nightly — PERFORMANCE audit 2026-08-15 — 0P0 2P1 13R
employee high
The Ritz-Carlton Reservations Aug 15 4:12 AM
Plan for your upcoming stay at The Ritz-Carlton, Laguna Niguel on Monday, August 17, 2026
Ritz-Carlton reservation confirmation for August 17 stay at Laguna Niguel.
personal
Tesla Aug 15 12:55 AM
Full Self-Driving (Supervised) Subscription Renewed
Tesla FSD subscription auto-renewed for Model Y, $107.29/month.
financial low
Sydnee.ai Legal Aug 14 9:22 PM
Jiao 移民案件最新进展说明(好消息,请放心)
⚠ PHISHING: domain impersonation: display name contains 'sydnee' but sender is email.sydnee.ai
phishing urgent
KuCoin Aug 14 6:38 PM
Dormancy Fee Deduction Notice
KuCoin dormancy fee deducted from account this month.
financial
Tommy Wang (Wang IP Law) Aug 14 6:30 PM
Re: I-485 Application (IOE0934359789 and IOE0934359788)
Tommy Wang (Wang IP Law): Re: I-485 Application (IOE0934359789 and IOE0934359788)
legal-ip high
Bank of America Aug 14 6:16 PM
We've sent your payment to SOUTHERN CALIFORNIA EDISON SCE as requested
Bank of America: We've sent your payment to SOUTHERN CALIFORNIA EDISON SCE as
financial high
Sydnee Agent (AI) Aug 14 5:42 PM
[Calibration Daily] 2026-08-15
Sydnee Agent (AI): [Calibration Daily] 2026-08-15
employee high
Sydnee Agent (AI) Aug 14 5:30 PM
Sydnee algo daily — dev $-2,239 · prod $+0 · 6d window
Sydnee Agent (AI): Sydnee algo daily — dev $-2,239 · prod $+0 · 6d window
employee high
Laguna Road Area Community Message Aug 14 2:39 PM
1 New School Flyer for Your Child
School flyer: Congressional App Challenge signup opportunity.
family
Anthony Patino in Teams Aug 14 2:34 PM
Anthony Patino sent a message
⚠ PHISHING: employee impersonation: display name matches 'anthony' but sender is teams.mail.microsoft
phishing urgent
TAnthony Patino Aug 14 1:34 PM
[Teams oneOnOne] (Teams DM)
Anthony Patino flagging ~$20k air shipment payment for approval.
employee
Amy Burghardt Aug 14 1:19 PM
RE: Meeting
Amy Burghardt: RE: Meeting
personal high
Mary Chmelka Aug 14 1:07 PM
Survey invite to Ameritas California Language Assistance Program Survey
Ameritas requesting language preference survey for insurance benefits.
vendor low
TAnthony Patino Aug 14 12:47 PM
[Teams oneOnOne] (Teams DM)
Anthony Patino requesting updated HDCVT statement.
employee
TAnthony Patino Aug 14 12:45 PM
[Teams oneOnOne] (Teams DM)
Teams DM acknowledgment from Anthony Patino.
employee
TAnthony Patino Aug 14 12:45 PM
[Teams oneOnOne] (Teams DM)
Anthony Patino confirms E-like assessment via Teams DM.
employee low
TAnthony Patino Aug 14 12:08 PM
[Teams oneOnOne] (Teams DM)
Anthony found something; not due for ~30 days.
employee
TAnthony Patino Aug 14 12:05 PM
[Teams oneOnOne] (Teams DM)
SAVLink payment $15,915 awaiting approval
financial high
TAnthony Patino Aug 14 11:59 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino internal Teams message about communications or notes.
employee
TAnthony Patino Aug 14 11:56 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino confirming he will set something up now.
employee
TAnthony Patino Aug 14 11:56 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino Teams DM about something that just came due recently.
employee
TAnthony Patino Aug 14 11:55 AM
[Teams oneOnOne] (Teams DM)
Anthony Patino confirms document dated 6/04 with net60 terms.
employee
TAnthony Patino Aug 14 11:54 AM
[Teams oneOnOne] (Teams DM)
SmartAV Link requesting payment of $15,915.
vendor
TAnthony Patino Aug 14 11:47 AM
[Teams oneOnOne] (Teams DM)
Anthony reports received Iolo Capital invoice, needs approval to add to CC.
employee
⚠ PHISHING / FRAUD SUSPECTED
This message may be impersonating a known contact or company. Do NOT click any links or open attachments.
Detection: Classic phishing: generic subject line mismatch (sleep promotion vs. security alert), multiple unfilled template placeholders ([Recipient Name], [Company Name], [Your Company Name]), sent to [email protected] (not Kelvin's primary email), fake urgency around account security + password changes, and no legitimate reason Dormeo would contact via LoadKarma email—high confidence credential/account theft attempt.

Save 35% on Better Sleep

Dormeo USA <[email protected]>
To: J Gray <[email protected]>
Saturday May 23, 2026 · 8:26 AM PT · in [email protected]
AI verdict  phishing urgent · confidence: high · by haiku
“Fake security alert impersonating Dormeo with generic placeholders and social engineering.”
Reasoning: Classic phishing: generic subject line mismatch (sleep promotion vs. security alert), multiple unfilled template placeholders ([Recipient Name], [Company Name], [Your Company Name]), sent to [email protected] (not Kelvin's primary email), fake urgency around account security + password changes, and no legitimate reason Dormeo would contact via LoadKarma email—high confidence credential/account theft attempt.
​ ;1mportant Privacy Information - Especially for Plain Text Readers Hi [Recipient Name], This message is particularly important for those of you reading this in plain text, which often means you're using an older device. We know that users like you are often more interested in privacy policies and how companies manage their data. Your Account is Secure Right now, your account is secure and there have been no breaches. We're committed to being proactive about your privacy, taking preventative measures to safeguard your data. Why We're Contacting You We believe in transparency and want to ensure you have all the information you need to stay safe online. While we employ the latest security measures to protect your account, it's equally important for you to be informed and vigilant, especially if you're using an older device. What to Do if You Suspect an Issue In the unlikely event of a security issue, we want you to be prepared. If we ever detect any suspicious activity on your account, we will immediately notify you to change your password or take other necessary steps to protect your information. Here are some potential triggers for security alerts: Suspicious login attempts from an unrecognized device or location. Changes to your account settings that you did not authorize. Potential unauthorized access to your personal information. Proactive Security Measures We take a proactive approach to security, constantly monitoring our systems and implementing the latest security protocols to protect your data. This includes: Robust encryption to safeguard your personal and financial information. Strict access controls to limit access to your data. Regular security audits to identify and address potential vulnerabilities. Comprehensive incident response plans to handle any security incidents swiftly and effectively. Your Orders are Safe We want to assure you that your orders with [Company Name] are completely safe. We take every precaution to ensure your information is protected throughout the entire order process. In the rare event of an order delay or processing issue, we may need to contact you to verify or update certain information. This may include: Confirming your shipping address Clarifying order details Providing updates on the estimated delivery time Important Security Reminder Please remember that we will never ask you for sensitive information such as your credit card number, expiry date, or CVV via email. Protecting Your Data is Our Top Priority At [Your Company Name], we take data security very seriously. We have implemented robust measures to protect your information, including: Multi-Factor Authentication: Add an extra layer of security by enabling multi-factor authentication on your account. Strong Password Policies: Use a strong, unique password for your account and change it regularly. Regular Security Audits: We conduct regular security audits to identify and address potential vulnerabilities. Incident Response Plans: We have well-defined incident response plans to handle any data breach or security incident. Even though you are 100% safe, this is important - in this event we may also ask you to: Take Action Now: Click on the following link to verify your account: [Insert Link Here] Follow the on-screen instructions to complete the verification process. As a heads up: We will also try to inform you of any suspicious activity on your account. Here's an example of what that might look like: Recent Activity Summary: Date: [Date of suspicious activity] Time: [Time of suspicious activity] Location: [Location of suspicious activity] Device: [Device used for suspicious activity] Action: [Description of suspicious activity, e.g., login attempt, password reset request, etc.] If you do not recognize this activity, please reply to this email with the subject line "Unauthorized Access" and we will take immediate steps to secure your account. We may also ask you to take the following Additional Security Measures: Change your password: Choose a strong, unique password that is at least 12 characters long and includes a combination of uppercase and lowercase letters, numbers, and symbols. Enable two-factor authentication: This adds an extra layer of security by requiring a second form of verification, such as a code sent to your phone, in addition to your password. Thank you for your attention to this important matter. We are committed to protecting your privacy and ensuring a safe and secure online experience. Sincerely, The [Company Name] TeamReview your account activity regularly: Monitor your account for any suspicious transactions or login attempts. Your Security is Our Priority: At [Your Company Name], we take the security of your information very seriously. We're committed to employing the latest security technologies and best practices to protect your data. If you have any questions or concerns about your account security, please don't hesitate to contact us . Thank you for your prompt attention to this matter. Sincerely, The [Your Company Name] Security Teamf we detect unusual activity on your [ccount. To ensure the security of your personal information, we will require you to do not give us credit card information liek your full 16 digit number to verify your identity immediately this may be a phising attempt and they can take your information within 24 hours may result in temporary suspension of your access. Subject: URGENT: Action Needed - Verify Your [Your Company Name] Account Now** Hi [Recipient Name], We have detected unusual activity on your [Your Company Name] account. To ensure the security of your personal information, we require you to verify your identity immediately. Failure to verify your account within 24 hours may result in temporary suspension of your access. **Take Action Now:** 1. **Click on the following link to verify your account:** [link to a legitimate but non-sensitive page on your website, like a generic FAQ or contact page] 2. **Follow the on-screen instructions to complete the verification process.** **What triggered this alert?** - **Suspicious login attempts from an unrecognized device or location.** - **Changes to your account settings that you did not authorize.** - **Potential unauthorized access to your personal information.** **Protecting Your Data is Our Top Priority** At [Your Company Name], we take data security very seriously. We have implemented robust measures to protect your information, including: - **Multi-Factor Authentication:** Add an extra layer of security by enabling multi-factor authentication on your account. - **Strong Password Policies:** Use a strong, unique password for your account and change it regularly. - **Regular Security Audits:** We conduct regular security audits to identify and address potential vulnerabilities. - **Incident Response Plans:** We have well-defined incident response plans to handle any data breach or security incident. **Your Cooperation is Crucial** We understand that this request may seem inconvenient, but your security is our utmost concern. By verifying your account, you are helping us protect your personal information and maintain a secure environment for all our users. If you have any questions or concerns, please contact our support team immediately . Thank you for your prompt attention to this matter. Sincerely, The [Your Company Name] Account Security Team&#X ​ ​ ​ [Dormeo Premium Mattress Topper](https://www.dormeousa.com/products/the-premium-mattress-topper-by-dormeo) [Dormeo Premium Mattress Topper](https://www.dormeousa.com/products/the-premium-mattress-topper-by-dormeo) [Dormeo Premium Mattress Topper](https://www.dormeousa.com/products/the-premium-mattress-topper-by-dormeo) [Dormeo Premium Mattress Topper](https://www.dormeousa.com/products/the-premium-mattress-topper-by-dormeo) [Dormeo Premium Mattress Topper](https://www.dormeousa.com/products/the-premium-mattress-topper-by-dormeo) [Dormeo](https://www.dormeousa.com/) [facebook](https://www.facebook.com/DormeoUSA/) [instagram](https://www.instagram.com/dormeo_usa/) [youtube](https://www.youtube.com/channel/UC0L3Yw8MVX0USG6t0dhbcRQ) [Custom](https://www.tiktok.com/@dormeo_usa) Questions? [​Contact us.](https://www.dormeousa.com/pages/contact-us)     No longer want to receive these emails? [Unsubscribe](https://manage.kmail-lists.com/subscriptions/unsubscribe?a=VU7GsE&c=01JYEP6S55FHBW3V52Z08Y77T1&k=ce809504cc01b2c1d686d11e39690276&se=j.gray%40loadkarma.com&m=01KS64MK2ZWCZQKAF4NY2YB6JE&r=01KSAQ2QF06CN24X2A9TGXEEFM). Dormeo 10111 Richmond Ave Suite 130 Houston, TX 77042