Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

Hi,


Do we have an anticipated payment date for our invoices?.


 

[Vendor Employee Name]

[Vendor Employee Title]

[Vendor Company Name]

[Vendor Contact Information]


------------



Good morning [Recipient First Name],


Thank you for your email.


Could you please confirm invoice number and amount?. We are in the process of changing banks and would stop accepting check payments as well, we are applying payments manually.


Thank you,


[Vendor Employee Name]

[Vendor Employee Title]

[Vendor Company Name]

[Vendor Contact Information]

Vendor Impersonation Payment Inquiry Account Update BEC Attack

Subject:
"
[Impersonated Vendor Company Name] Invoices
"
Attack Date:
May 17, 2022

This text-based BEC attack impersonates a vendor/supplier using a look-alike domain, a spoofed display name, a payment inquiry theme, and an account update theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

I can access the employee portal but I keep getting an error message every time I try to modify my direct deposit information. Can I just forward you a voided check or my new account details for you to update before the next pay circle.


 


[Impersonated Employee Name]


[Impersonated Employee Title] 


[Target Company Name]

Employee Impersonation Payroll Diversion BEC Attack

Subject:
"
Stub
"
Attack Date:
May 17, 2022

This text-based BEC attack impersonates an employee using a spoofed display name and a maliciously registered domain to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello,


I hope you’re well. Invoice number 832 was due on 14th of April and is now over 30 days overdue. Please pay the total balance of this invoice at your earliest convenience.


In line with our payment policies, you will be charged a daily fee until this invoice is paid.


Please let me know if there is any reason why payment of this invoice cannot be made within seven working days.


Regards


[Vendor Employee Name]

Finance Officer

Vendor Impersonation Overdue Payment BEC Attack

Subject:
"
Due Shipping Bill
"
Attack Date:
May 17, 2022

This text-based BEC attack impersonates a vendor/supplier using a look-alike domain and an overdue payment theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

To: [Recipient Email Address]


Shareholders requests your signature on

Salary Increase Request - [Recipient Email Address]


Review and sign


This document is for [Recipient Email Address]


Please review and sign.


After you sign Salary Increase Request, the agreement will be sent to HR Department

Then, all parties will receive a final PDF copy by email.


Don't forward this email: If you don't want to sign, you can delegate to someone else.

Adobe Employee Incentive Fake Document Credential Phishing Attack

Subject:
"
Salary Increase Request
"
Attack Date:
May 16, 2022

This link-based attack impersonates Adobe using an employee incentive theme and a fake document theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Adobe
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],


I am closing my current account and I would like to make changes to my

Direct Deposit information with my new Bank account.


Can the changes be in effect before the current pay date?


Best Regards,


[Impersonated Employee Name]


Sent from my iPhone

Employee Impersonation Payroll Diversion BEC Attack

Subject:
"
Hello [Recipient Name]
"
Attack Date:
May 16, 2022

This text-based BEC attack impersonates an employee using an extended spoofed display name, a matching malicious domain username, a personalized email subject, and a maliciously registered domain to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello team,


Please download the documents now and store them for your records.


Download Documents


Sign into your account for more options


-Commitment for Title Insurance

-Tax Certificate

-Wiring Instructions

-Insured Closing Letter

-Preliminary CD

-Vesting Deed

-Survey-has been ordered will send over to you once it has been received and reviewed.

-HOA

-Hazard Insurance – Please provide a copy of the insurance Dec. Page



Please let us know if you have any questions.

Stewart Title Company Real Estate Transaction Fake Document Credential Phishing Attack

Subject:
"
****Closing Package (CD) and Wiring Instructions Attached****
"
Attack Date:
May 16, 2022

This link-based attack impersonates Stewart Title Company using an external compromised account, a real estate transaction theme and a fake document theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Stewart Title Company
Attachment Type:
Language:
See Attack Details

[External Third Party Name] ([External Third Party Email Address]) has shared Westpac_Remittance05152022.pdf.  

   

 

Open

 

 

SENT BY  

[External Third Party Name] ([External Third Party Email Address])

MESSAGE FROM SENDER  

Please confirm from your bank you receive the payment.

SHARED ON   15-May-2022 10:20 AM PDT

Adobe Fake Document Credential Phishing Attack

Subject:
"
Westpac_Remittance05152022
"
Attack Date:
May 16, 2022

This link-based attack impersonates Adobe and an external third party using a fake document theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
External Party - Other
Impersonated Brand:
Adobe
Attachment Type:
Language:
See Attack Details

Hi ,


I have recently changed banks and like to have my May payslip deposit changed to my new account. I need your prompt assistance on this matter.


Best Regards,

[Executive Name].

Get Outlook for iOS

Executive Impersonation Payroll Diversion BEC Attack

Subject:
"
May Payroll Updates ​
"
Attack Date:
May 16, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi ,


I need you to email me the Sales Ledger Aged Debtors Report in detail.

Also, include their email contact on this report.


Thank you.


Best Regards,

[Executive Name]

Chief Executive Officer

[Company Name]

[Executive Email Address]

Executive Impersonation Aging Report Compromise BEC Attack

Subject:
"
Sales Ledger Aged Debtors Report Request
"
Attack Date:
May 16, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to request a copy of an aging report.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

---------- FEDPOL message ---------


Im Anhang finden Sie weitere Informationen. Bitte beziehen Sie sich auf die oben genannte Datei.

German Legal Matter PDF Attachment Extortion Attack

Subject:
"
TR: Fédéral Police.
"
Attack Date:
May 16, 2022

This payload-based German-language extortion attack uses an external compromised account, a legal matter theme, and a PDF attachment to demand a payment.

No items found.
Type:
Extortion
Theme(s):
...
Tactic(s):
...
Vector:
Payload-based
Goal:
Extortion
Impersonated Party:
Impersonated Brand:
Europol
Attachment Type:
PDF
Language:
German
See Attack Details

Whoops.. There are no results found.