Alerts & campaigns

Flow 4 · spike detection within 15 minutes, weekly reporting (FR7)

Active alerts 2 open

Spam rate spike — +24% above 7-day rolling average

Critical Investigating

Triggered Jun 8, 2026 at 14:32 · assigned to Priya Nandakumar · fired 6 minutes after threshold breach (target < 15 min)

Spam rate vs. 7-day average

08:00
10:00
12:00
13:00
14:00
15:00

Spam rate climbed from a baseline of 13.1% to 16.2% within two hours — consistent with a coordinated campaign rather than normal variance.

Sample messages driving the spike

  • "CASH prize of £5000 is waiting! Text WIN to 80082 now to claim before midnight…" · CASH-LINE
  • "Congratulations! You've been selected for a FREE flagship phone. Click to claim…" · +1 302 555 0142
  • "URGENT! Your Mobile No. has won £2000 Bonus Caller Prize. Call 09066362231…" · +44 7700 900112

Recommended actions

  • Confirm campaign pattern against top spam phrases (CASH, FREE, WIN/WINNER)
  • Review related senders for allowlist/blocklist action in Settings
  • Flag the affected phrases for priority inclusion in next month's retraining corpus

New spam pattern detected — "claim your reward" phrase surge

Medium Investigating

Triggered Jun 7, 2026 at 09:14 · assigned to Devon Reyes · 41 occurrences in 24 hours (vs. 6 the week before)

A new variant of prize-claim phishing is circulating using the phrase "claim your reward" paired with shortened links. Devon is cross-referencing sender IDs against the allowlist and preparing labelled examples for the July retraining run.

Recently resolved

False positive rate approached threshold — peaked at 6.3% (target ≤ 6.5%)

Resolved Jun 6, 2026 · root cause: a legitimate appointment-reminder campaign sharing vocabulary with spam · added 40 examples to allowlist review

Low

Weekly security report — Jun 1–7, 2026

Auto-generated every Monday and emailed to the security distribution list (Story 4)

Messages classified

1.21M

Spam rate

13.8%

Precision / recall

93.7% / 91.2%

New spam phrases

"claim your reward", "verify account now"