Attack Vault
The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.
This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.
Hi [Recipient First Name],
I'd need you to process payment of $1,910 to a vendor and it's imperative the payment goes out today. Let me know if you are available so I can send further instructions.
Thanks.
Employee Impersonation New Vendor Payment Fraud BEC Attack
This text-based BEC attack impersonates an employee using a spoofed email address, a free webmail account, and a new vendor theme to request a fraudulent payment.
Re: Overdue invoice reminder
This is a final reminder that Invoice 960201 Overdue.
Can you confirm this is paid ?
Kind Regards
[Vendor Employee First Name]
[Vendor Employee Name]
[Vendor Employee Title]
[Vendor Company Name]
Vendor Impersonation Overdue Payment BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a look-alike domain and an overdue payment theme to request a fraudulent payment.
Can you handle this today? Payment has to be made via ACH.
---------- Forwarded message ---------
From: [VENDOR NAME] <donotreply@payments-thesilverlining.com>
Date: Mon, May 02, 2022 at 04:11 PM
Subject: Account 100015389930
To: [Executive Name]
You have received an invoice from [VENDOR NAME] which is attached to this email for preview. Please make payment via ACH or Wire Transfer, the Bank information is on the invoice.
If you are experiencing issues viewing the attached pdf via a mobile device, please use your standard mail client or webmail.
Thank you,
[VENDOR NAME]
Please do not reply to this email as this is a non-monitored account.
For assistance, don't hesitate to get in touch with [Vendor Employee Name], Billing Department, via email at [Username]@payments-thesilverlining.com.
Executive Impersonation Fake Invoice Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using a fake email chain, a maliciously registered domain, a spoofed display name, and a fake invoice theme to request a fraudulent payment.
Good Morning
Can we process an ACH or domestic wire transfer for a new vendor today?
The payment is Overdue, so make it a high priority.
Regards
[Executive Name]
[Executive Title] & Director at [Company Name]
Get Outlook for iOS
Executive Impersonation New Vendor Overdue Payment Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using a spoofed display name, a free webmail account, a new vendor theme, and an overdue payment theme to request a fraudulent payment.
Hello Dealer/Distributor,
I am one of the auditors for [Impersonated Vendor Company Name]. We are currently in the middle of the financial statement audit for the year ended 2021/2022 and would like to inquire regarding any outstanding payment/due invoice with the Company, and if you do, how much is the due/outstanding payment and when is the payment due date?
Also if you have not paid yet, kindly hold off with the payment for our further instructions.
Awaiting your email response.
Best Regards,
[Impersonated Vendor Employee Name]
Accounts Receivables
[Impersonated Vendor Company Name]
[Impersonated Vendor Company Address]
Vendor Impersonation Overdue Payment BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a look-alike domain and an overdue payment theme to request a fraudulent payment.
--
Hola [Recipient First Name]
¿Tienes unos minutos libres? Estoy en medio de una conferencia
telefónica y hay algo de lo que necesito que te ocupes ahora mismo.
Proporcione su número de Whatsapp en su respuesta.
Spanish Executive Impersonation Gift Card Request BEC Attack
This text-based Spanish-language BEC attack impersonates an executive using a WhatsApp number request, a spoofed display name, and a free webmail account to request the purchase of gift cards.
Good day
hope you're well and had a good weekend.
We are writing in reference to an overdue invoice, we kindly ask that you reassert to us the status of our outstanding or any due if there are any, as we currently have to give you an updated information.
Please get back to us immediately with the total amount that is outstanding with corresponding due dates and invoices respectively.
kindly hold off on any payment due.
[Vendor Employee Name] - Sales Manager
[Vendor Company Address]
Inside Sales: invoice.outstanding@accountant.com
Vendor Impersonation Overdue Payment Payment Inquiry BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a spoofed email address, a free webmail account, an overdue payment theme, and a payment inquiry theme to request a fraudulent payment.
[Recipient First Name], I'll need you to process an outgoing payment today via Wire
or Zelle for an Operating Expenses which is due.
Kindly let me know if you can get it done today via Wire or Zelle so i
can forward you the details for the payment.
Thanks
[Impersonated Employee First Name]
Employee Impersonation Payment Fraud BEC Attack
This text-based BEC attack impersonates an employee using a spoofed display name and a free webmail account to request a fraudulent payment.
Attention,
After numerous attempts to reach you, we haven't received any payment or any positive feedback from your side, as you are not paying your seriousness on this account which means that you are trying to run away from the situation and repeating the same activity which you did before with the loan company. We tried our best to help you on this matter but you are taking this matter lightly.
Account Status: WARRANT IS ACTIVE FOR SEARCH AND SEIZE (Violation of the Fair Debt Collection Practices Act and Defamation of Character.)
"Debtor (You) has been declared as a guilty by Authorized Law Enforcement Department, Seizure Warrant has been activated under 15 USC 1692g Sec. 809 (b) of the FDCPA”
Unless delayed notice is authorized below, you must give a copy of the warrant and a receipt for the property taken to the person from whom, or from whose premises, the property was taken, or leave the copy and receipt at the place where the property was taken.
The officer executing this warrant, or an officer present during the execution of the warrant, must prepare as required by law and promptly return this warrant. Pursuant to 18 U.S.C. § 3103a (b), I find that immediate notification may have an adverse result listed in 18 U.S.C. 2705 (except for the delay of trial), and authorize the officer executing this warrant to delay notice to the person who, or whose property, will be searched or seized.
Note: You will be contacted by your local county authorities. National Debt Recovery Department is closing this account and declaring as a GUILTY. If we will not receive any feedback from your side, then you will be the only person who will be responsible for any consequences.
NOTE: YOU STILL HAVE CHANCE TO RECTIFY THIS OUTSIDE OF COURT, FOLLOW THE RESOLVEMENT PROCEDURE BELOW
IF YOU WANT TO RESOLVE CASE OUTSIDE OF COURT THEN CONTACT TO RESTITUTION DEPARTMENT: - mailto:attorney.richard.l.beaver@gmail.com
CREDITOR: CASH NET USA.
Regards,
Restitution Head
Department of Debt Settlement
Confidentiality Statement & Notice: This email is covered by the Electronic Communications Privacy Act, 18 U.S.C. 2510-2521 and intended only for the use of the individual or entity to which it is addressed. Any review, retransmission, dissemination to unauthorized persons or other use of the original message and any attachments is strictly prohibited. If you received this electronic transmission in error, please reply to the above-referenced sender about the error and permanently delete this message. Thank you for your co-operation.
Debt Collection Legal Matter Extortion Attack
This text-based extortion attack uses a free webmail account, a debt collection theme, and a legal matter theme to demand a payment.
--
Hallo [Recipient First Name],
Ich habe eine Telefonkonferenz und möchte, dass Sie eine kurze Aufgabe für mich erledigen.
Senden Sie mir Ihre bei WhatsApp registrierte Telefonnummer und warten Sie auf meine Nachricht.
Mit freundlichen Grüßen.
Von meinem Iphone gesendet.
German Executive Impersonation Gift Card Request BEC Attack
This text-based German-language BEC attack impersonates an executive using a WhatsApp number request, a spoofed display name, and a free webmail account to request the purchase of gift cards.