Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

Good Morning [Recipient First Name],

­­

I trust you are doing very well. I'm looking forward to surprising some staff with Gifts for their hard work and dedication. What do you suggest we surprise them with? Email me once you receive this.



[Executive Name]

[Executive Title]

sent from my mobile device

Executive Impersonation Employee Incentive Gift Card Request BEC Attack

Subject:
"
routine ­­staff appreciation
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a spoofed display name, a free webmail account, and an employee incentive theme to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Good Morning,


I am circling back around with you regarding the final payment breakdown for the claim payment(s) that have been issued.


We are currently sitting at an amount owed of $ 9874.18 to pay this account in full. Please provide a response ASAP or we will be forced to place a lien on the insured’s property.


[Vendor Employee Name]

A/R Manager 



[Hijacked Thread Content]

Vendor Impersonation Overdue Payment BEC Attack

Subject:
"
RE: FW: [Hijacked Thread Subject]
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates a vendor/supplier using a hijacked email thread, a look-alike domain, a matching malicious domain username, and an overdue payment theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Goedemorgen ,

  

Wij moeten een bedrag van € 59.754,21 betalen aan een bedrijf in Engeland. Welke gegevens heb je nodig om nu te betalen?

  

Groeten

Dutch Executive Impersonation Payment Fraud BEC Attack

Subject:
"
[Recipient First Name]
"
Attack Date:
June 29, 2022

This text-based Dutch-language BEC attack impersonates an executive using a personalized email subject, a spoofed display name, and a free webmail account to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
Dutch
See Attack Details

Hi [Recipient First Name],

 

I have a quick question for you, I changed my bank account and I'll like to update my direct deposit details on file,Can the change be effective for the current pay date?.

 

Warm Regards.

 

[Executive Name]

[Executive Title]

 

[Target Company Name]

Executive Impersonation Payroll Diversion BEC Attack

Subject:
"
Update Payroll Account
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a matching free webmail username and a spoofed display name to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],


Kindly email me the latest A/R report. You are to include the following on the report, Invoice number, Invoice due date, Payment terms, Client name or ID, Aging Bucket, Client Contact Name and AP Email.

I need to review them.


Regards,

[Executive First Name]



Sent from my iPhone

Executive Impersonation Aging Report Theft BEC Attack

Subject:
"
Status of Payment
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to request a copy of an aging report.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

This is Ok to pay. See below and attached. 


Please set up ACH for the attached invoice today.



---------- Forwarded message ---------

From: LinkedIn Receivables Team <david.hoffman[@]receivables-linkedin[.]com>

Sent: Friday, June 10, 2022 12:27 PM

Subject: Reference Number(s):CS48155550-18 LinkedIn Invoice(s)

To: [Executive Name]


Dear Customer,

Invoices on your LinkedIn account are past due.

This is a friendly reminder that you currently owe:


Please send payment via ACH only using the bank details provided on the invoice.


Please note: You may notice some improvements to your invoice. As part of our ongoing commitment to deliver a better billing experience, we have introduced several changes. To learn more about your new invoice, check on our website.


For payment related questions please reply to this email without changing the subject line.



Sincerely,

David Hoffman

LinkedIn Collections

Executive Impersonation Overdue Payment Payment Fraud BEC Attack

Subject:
"
Daily Invoice from Linkedln
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a fake email chain, a maliciously registered domain, a spoofed display name, and an overdue payment theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],

 

I just received a follow up e-mail from Francesca a lawyer from Allen & Overy representing a firm we worked with, regarding a late bill for the amount of £65,560.90 issued last year for a services rendered on our behalf and I have asked her to contact you.

 

I understand that the invoice was sent before but didn't get into the system for payment. Attached is a copy of the outstanding invoice. Can we get this paid today? 

 

Many Thanks,


[Executive Name]

 

From: Francesca Bennetts francesca.bennetts@allenovarysglobal.com>

Posted: Wednesday, June 29, 2022 9:02 AM 

To: [Executive Name] <[Executive Email Address]>

Subject: Unpaid Invoice

 

Hi [Executive First Name],

 

I have sent the invoice again to you as reminder. I wish to inform you that this invoice is already due and if this is not paid this week, we will have to open a case against your firm. 

 

Kind Regards.

 

Francesca Bennetts | Senior Associate

Executive Impersonation Overdue Payment Legal Matter Payment Fraud BEC Attack

Subject:
"
Unpaid Invoice
"
Attack Date:
June 29, 2022

This text-based BEC attack impersonates an executive using a fake email chain, a spoofed email address, a matching malicious domain username, an overdue payment theme, and a legal matter theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[Recipient First Name],


Need you to initiate a wire transfer today, how soon can you get this done

So i can send the information required 


Regards



[Executive Name]


Sent from my iPhone 

Executive Impersonation Payment Fraud BEC Attack

Subject:
"
FYI !!!
"
Attack Date:
June 28, 2022

This text-based BEC attack impersonates an executive using a spoofed email address, a matching malicious domain username, and a maliciously registered domain to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[Target Company Name] Verification Expires 01 July, 2022


Hi [Recipient Username],


Your password for your email account [Recipient Email Address] will expire on 01 July, 2022.

To continue using your account [Recipient Email Address] Please reconfirm account ownership below.


Reconfirm Password


[Target Company Name] Mail Team

Message securely sent to [Recipient Email Address], please ignore if wrongly received.

Expired Account Credential Phishing Attack

Subject:
"
[Target Company Name] Urgent deactivation alert
"
Attack Date:
June 28, 2022

This link-based attack uses a personalized email subject, a maliciously registered domain, and an expired account theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hoi [Recipient First Name]

  Wat is je telefoon nummer? Uw aandacht is nodig om meteen een taak voor mij af te handelen.


Vriendelijke groeten,

Bedankt.


Verzonden vanaf mijn mobiele apparaat.



Kind Regards

Dutch Executive Impersonation Gift Card Request BEC Attack

Subject:
"
[Recipient First Name]
"
Attack Date:
June 28, 2022

This text-based Dutch-language BEC attack impersonates an executive using a personalized email subject, a cell phone number request, a spoofed display name, and a free webmail account to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
Dutch
See Attack Details

Whoops.. There are no results found.