Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

Hello [Recipient First Name],


Are you available? I need your assistance and I've got Credence in you to take care of this. I would have called your phone, I am out of town now for a meeting and I do not have access to my mobile phone. [Target Company Name] needs some gift cards for donation to Community Welfare with patients and Veterans at Hospice Care, can you confirm if you can get some today? I will need you to get 6 pieces x 100 denominations of either Target , Amazon or Best Buy gift cards which totals 600:00 online or at any convenience store near you. 


When you have the physical cards.


(1) Take snapshots to capture the front and back of the gift cards. (Scratch Target)

(2) Attach the pics & send to the Veterans Hospice Palliative Care e-mail address <veterans@anglewingscare.com> and cc me.

The idea is to make the card readable for the Vets can have access to it.


Let me know if you can get this done today. You will be reimbursed guaranteed by me.


Regards,

[Executive Name].

Executive Impersonation Community Service Gift Card Request BEC Attack

Subject:
"
[Target Company Name]
"
Attack Date:
May 20, 2022

This text-based BEC attack impersonates an executive using a spoofed display name, a free webmail account, and a community service theme to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Please advise once payment has been made so I can confirm with my AR department that it has been received. Once we have received payment, we will be able to update our records..


Thank you,


[Vendor Employee Name], CPA

Chief Financial Officer

PwC network.



PricewaterhouseCoopers LLP

411 Hamilton Boulevard

Peoria, Illinois 61602

United States



On Fri, May 20, 2022 at 6:51 AM [Executive Name] <send-via@mail-net-suites.com> wrote:


  [Recipient First Name],


  Could you please arrange ACH payment for this PWC LLP invoice today. See below and attached.


  ---------- Forwarded message ---------



  From: [Vendor Employee Name] <[Vendor Employee Username]@accounts-pwc.com>

  Sent: Thursday, May 12, 2022 10:14 AM

  To: [Executive Name]

  Cc: [Vendor Employee Name] <[Vendor Employee Username]@accounts-pwc.com>

  Subject: PWC LLP: INVOICE# 001691134 PAYMENT DUE


  A new invoice 001691134 has been generated and is attached for your review and payment.


  Please make payment via ACH (Automated clearing house). Bank information is on the invoice.


  If you are experiencing issues viewing the attached pdf via a mobile device, please use your standard mail client or webmail.


  Thank you,


  [Vendor Employee Name], CPA

  Chief Financial Officer

  PwC network.



  PricewaterhouseCoopers LLP

  411 Hamilton Boulevard

  Peoria, Illinois 61602

  United States

Vendor Impersonation Payment Inquiry BEC Attack

Subject:
"
Re: Fw: Re: PWC LLC: #1691134
"
Attack Date:
May 20, 2022

This text-based BEC attack impersonates a vendor/supplier using a fake email chain, a look-alike domain, and a payment inquiry theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hallo [Recipient First Name],


Ik heb mijn bankrekening gewijzigd en wil dat u mijn salarisgegevens wijzigt. Kan de wijziging ingaan op de huidige betaaldatum? Zo ja, op welke dag in mei kan de betaling worden verwacht?


Dank u,

[Impersonated Employee First Name]

Dutch Employee Impersonation Payroll Diversion BEC Attack

Subject:
"
Wijziging van gegevens
"
Attack Date:
May 20, 2022

This text-based Dutch-language BEC attack impersonates an employee using a spoofed display name and a free webmail account to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
Dutch
See Attack Details

Hi [Recipient First Name],


Are you available at the moment? I am out of the State now and I need your assistance to handle a little project. I would have called your phone but I presently do not have access to my mobile phone. Can you please handle this for me on behalf of the association? [Target Company Name] is requesting gift card donations to assist Veterans at hospice care welfare with patients who have been negatively affected by the impact of the COVID-19 pandemic. Every gift helps provide resources that will help stabilize a Veteran and ensure a positive upward trajectory during this critical time. I have decided to make it a personal duty and I'll be responsible for the reimbursement of cards bought. Kindly confirm if you can help out.


[Executive Name]

[Executive Title]

[Target Company Name]

Executive Impersonation COVID-19 Community Service Gift Card Request BEC Attack

Subject:
"
[Target Company Name]
"
Attack Date:
May 20, 2022

This text-based BEC attack impersonates an executive using a maliciously registered domain, a spoofed display name, a COVID-19 theme, and a community service theme to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],

 

 

Can you initiate a transfer that goes out today?

 

If you could expedite this, notify me when you are set to proceed so I can forward an attachment of the payment instructions.

 

Thanks,

 

 

[Executive First Name]

Executive Impersonation Payment Fraud BEC Attack

Subject:
"
Management Consultancy Services
"
Attack Date:
May 20, 2022

This text-based BEC attack impersonates an executive using a matching malicious domain username, a free webmail account, and a spoofed display name to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Dear Valued ADP Client,


Account operator refused payroll operation on your ADP® Employee Access® account.

For your security, kindly verify your account by clicking on the button below.



This message and any attachments are intended only for the use of the addressee and may contain information that is privileged and confidential. If the reader of the message is not the intended recipient or an authorized representative of the intended recipient, you are hereby notified that any dissemination of this communication is strictly prohibited. If you have received this communication in error, notify the sender immediately by return email and delete the message and any attachments from your system.



Important: Please be advised that calls to and from your Service Team may be monitored or recorded.


Please do not respond to this message. It comes from an unattended mailbox.

ADP Account Verification Credential Phishing Attack

Subject:
"
Payroll System Update
"
Attack Date:
May 19, 2022

This link-based attack impersonates ADP using a free webmail account and an account verification theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
ADP
Attachment Type:
Language:
See Attack Details

Dear [Recipient Name] & Accounts Team,

 

Please note that all current/outstanding invoices have been sent .Kindly confirm receipt for more information and instructions.Note also that the invoices for December, 2021 to March, 2022 appear to be in arrears.We request that you kindly provide the status of these invoices with proofs of payment if remittances have been made already against any of these invoices in question so as to enable us update our records and accounts accordingly.

 

Thanks for your cooperation. We await your prompt response.

 

My best regards

 

[Vendor Employee Name]

General Manager Accounts

Head of CAT / CO2 (Collection of Air Navigation Charges)

CRCO / CAT / CO2

EUROCONTROL

96 Rue de la Fusée, 1130 Brussels, Belgium

Email: [Username]@eurocontrolint.com

Vendor Impersonation Overdue Payment BEC Attack

Subject:
"
Re[5]: EUROCONTROL Payment Delays
"
Attack Date:
May 19, 2022

This text-based BEC attack impersonates a vendor/supplier using a look-alike domain and an overdue payment theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
EUROCONTROL
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],


Are you in today?


Is there a full list of receivables aging reports that I might look at? including contact information (email and phone numbers)? Please create a spreadsheet and send it to me via email as soon as feasible.


Thank you very much

[Executive Name]

[Executive Title] at [Company Name]

Executive Impersonation Aging Report Compromise BEC Attack

Subject:
"
Quick Follow-UP
"
Attack Date:
May 19, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to request a copy of an aging report.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Good morning,


Please i will need your assistance in updating my banking details for payroll. I'm now with another bank and i do not want to lose my next paycheck.


I have my new bank details to take effect next payroll.


Kindly advise.


Regards,

[Impersonated Employee Name]

Employee Impersonation Payroll Diversion BEC Attack

Subject:
"
DD Update [Impersonated Employee Name]
"
Attack Date:
May 19, 2022

This text-based BEC attack impersonates an employee using a spoofed email address, a personalized email subject, and a free webmail account to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello [Recipient Name]


Are you available? I need you to send out a wire payment before the

time runs out, so let me know when you are free so I can send you the

vendor invoice.



 Thank you.


[Executive Name]

Executive Impersonation Payment Fraud BEC Attack

Subject:
"
Treasurer
"
Attack Date:
May 19, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Whoops.. There are no results found.