Attack Vault
The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.
This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.
[Compromised Third Party Employee Name] sent you a document to review and sign.
REVIEW DOCUMENT
Thank you,
[Compromised Third Party Employee Name]
[Compromised Third Party Company Name]
[Compromised Third Party Company Contact Information]
Evernote Fake Document Credential Phishing Attack
This link-based attack impersonates Evernote and an external third party using a content obfuscation via image, an external compromised account, and a fake document theme to steal credentials.
Hi
Our records show that we haven’t yet received payment for Invoice 992890, which is overdue by 3 months. I would appreciate it if you could check this out on your end. If the payment has already been sent, please disregard this notice. And if you’ve lost this invoice, please let me know, and I’d be happy to send you another copy.
Regards,
[Impersonated Vendor Employee Name]
[Impersonated Vendor Company Name]
[Impersonated Vendor Company Address]
Vendor Impersonation Overdue Payment BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a look-alike domain, a spoofed display name, and an overdue payment theme to request a fraudulent payment.
(no text content - anchor image only)
Office365 Password Expiration Credential Phishing Attack
This link-based attack impersonates Office365 using a hijacked email thread, a content obfuscation via image, an external compromised account, and a password expiration theme to steal credentials.
Hello,
Your invoices are now past due - kindly confirm the payment dates.
Let me know if you require copies.
Kind Regards,
[Impersonated Vendor Employee Name]
Accounts Department
[Impersonated Vendor Company Name]
[Impersonated Vendor Company Address]
Vendor Impersonation Overdue Payment BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a spoofed email address, a look-alike domain, a matching malicious domain username, and an overdue payment theme to request a fraudulent payment.
Hi,
I have a little issue with the bank, I forgot my password and I tried logging with different passwords and my Bank blocked my online access for security purpose because they thought it was an unauthorized person trying to log in, so the bank generated a new account number for me. Can the change be made before the next pay ?
Thanks,
[Executive Name]
Executive Impersonation Payroll Diversion BEC Attack
This text-based BEC attack impersonates an executive using a personalized email subject, a spoofed display name, and a free webmail account to divert payroll deposits to a fraudulent account.
Hello,
Can you please verify that the attached invoice has been submitted for payment. Please feel free to contact me with any questions you may have.
Thank you,
[Compromised Third Party Name]
[Compromised Third Party Email Address]
Fake Invoice Word Document Attachment Credential Phishing Attack
This payload-based attack impersonates a vendor/supplier using an external compromised account and a fake invoice theme to steal credentials.
Good Morning [Recipient First Name]
Please kindly re-update my direct deposit account for upcoming payroll
I have an issue with my bank account, I will try and have it sorted
out later. Please have it updated ASAP.
Please make sure the payroll system process my direct deposit into my
new account and the new account be added today.
Can I email the new routing and account number details for the update
to be made today ?
Thank you.
[Impersonated Employee Name]
[Impersonated Employee Title]
Employee Impersonation Payroll Diversion BEC Attack
This text-based BEC attack impersonates an employee using a spoofed display name and a free webmail account to divert payroll deposits to a fraudulent account.
Hi [Recipient First Name],
I just received a follow up e-mail from Jillian a lawyer from Allen & Overy representing a firm we worked with, regarding a late bill for the amount of $42,338.46 issued last year for a services rendered on our behalf and I have asked her to contact you.
I understand that the invoice was sent before but didn't get into the system for payment. Attached is a copy of the outstanding invoice. Can we get this paid today?
Many Thanks,
[Executive Name]
From: Jillian Ashley <jillian.ashley@allenoverys.com>
Posted: Monday, May 16, 2022 9:08 AM
To: [Executive Name] <[Executive Email Address]>
Subject: Unpaid Invoice
Hi [Executive First Name],
I have sent the invoice again to you as reminder. I wish to inform you that this invoice is already due and if this is not paid this week, we will have to open a case against your firm.
Kind Regards.
Jillian Ashley
Senior Associate
Address: 1221 Avenue of the Americas
New York, NY 10020
Allen & Overy LLP
Executive Impersonation Overdue Payment Legal Matter Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using a fake email chain, a spoofed email address, a matching malicious domain username, a maliciously registered domain, a legal matter theme, and an overdue payment theme to request a fraudulent payment.
Hi [Recipient First Name],
Are you available at the moment?
Sent from my mobile device
-----------
Okay [Recipient First Name], I want you to take care of this for me personally, I have just been informed that we have had an offer accepted by a new international vendor, to complete an acquisition that I have been negotiating privately for some time now, in line with the terms agreed, we will need to make a down payment of 30% of their total, which will be $39,797.20.
An announcement is currently being drafted and will be announced next week, once the deal has been executed, for now I don't want to go into any more details.
Until we are in a position to formally announce the acquisition I do not want you discussing it with anybody in the office, any question please email me.
Can you confirm if international wire transfer can go out today?
Executive Impersonation Mergers & Acquisitions Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using a personalized email subject, a spoofed display name, a free webmail account, and a mergers & acquisitions theme to request a fraudulent payment.
Hello,
Please see attached for [Compromised Third Party Company Name] Inv 41063.
Thank you.
[Compromised Third Party Employee Signature]
Fake Invoice Credential Phishing Attack
This link-based attack impersonates a vendor/supplier using a fake attachment, an external compromised account, and a fake invoice theme to steal credentials.