Back to All Attacks
Attack Details
Attack Date:
Mar 10, 2022

Executive Impersonation Employee Incentive Gift Card BEC Attack

Initial Email Content

Subject
New Incentive Program
Body

Hi [Recipient First Name],

I am thinking of implementing an Employee Incentive Program to show our employees we care about them. I would like to surprise them and put a smile on their faces today. Can we purchase some cards (Walmart/Target) from the store?  

Reply and let me know how soon you can get this done and which of the cards you can easily buy at the store. Keep this surprise package confidential until we give it out to them.


Thanks,

Sent from my iPhone

Attack Screenshots

No items found.

Malicious Artifacts

Additional Indicators of Compromise

Type

Description

No items found.

Attack Description

This text-based BEC attack impersonates an executive using display name spoofing, a free webmail account, and an employee incentive theme to request the purchase of gift cards.

Analysis Overview

Tactic
Spoofed Display Name
Maliciously Registered Domain
Goal
Gift Card Request
Impersonated Party
Employee - Executive
Vector
Text-based
Theme
Employee Incentive
Language