What is emailsecurity.org?

Emailsecurity.org was created as a resource for the cybersecurity community to provide a centralized, marketing-free location for information about email-based phishing attacks. The site is maintained by Abnormal Security, but contains attack samples and intelligence reports from various sources in the private sector, public sector, law enforcement, and academia.

Recent Entries

Attack Vault

See all Attacks

Executive Impersonation Overdue Payment Legal Matter Payment Fraud BEC Attack

Subject:
"
Unpaid Invoice
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a fake email chain, a spoofed email address, a matching malicious domain username, an overdue payment theme, and a legal matter theme to request a fraudulent payment.

Type:
Business Email Compromise
Theme(s):
Overdue Payment
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Language:
Impersonated Party:
Employee - Executive
Impersonated Party:
Attachment Type:
See Attack Details

Executive Impersonation Overdue Payment Payment Fraud BEC Attack

Subject:
"
Daily Invoice from Linkedln
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a fake email chain, a maliciously registered domain, a spoofed display name, and an overdue payment theme to request a fraudulent payment.

Type:
Business Email Compromise
Theme(s):
Overdue Payment
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Language:
Impersonated Party:
Employee - Executive
Impersonated Party:
Attachment Type:
See Attack Details

Executive Impersonation Aging Report Theft BEC Attack

Subject:
"
Status of Payment
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to request a copy of an aging report.

Type:
Business Email Compromise
Theme(s):
No items found.
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Language:
Impersonated Party:
Employee - Executive
Impersonated Party:
Attachment Type:
See Attack Details

Executive Impersonation Payroll Diversion BEC Attack

Subject:
"
Update Payroll Account
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a matching free webmail username and a spoofed display name to divert payroll deposits to a fraudulent account.

Type:
Business Email Compromise
Theme(s):
No items found.
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Language:
Impersonated Party:
Employee - Executive
Impersonated Party:
Attachment Type:
See Attack Details

Dutch Executive Impersonation Payment Fraud BEC Attack

Subject:
"
[Recipient First Name]
"
Attack Date:
June 29, 2022

This text-based Dutch-language BEC attack impersonates an executive using a personalized email subject, a spoofed display name, and a free webmail account to request a fraudulent payment.

Type:
Business Email Compromise
Theme(s):
No items found.
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Language:
Dutch
Impersonated Party:
Employee - Executive
Impersonated Party:
Attachment Type:
See Attack Details