Attack Vault
The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.
This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.
[Recipient First Name],
I am looking to have my direct deposit account information updated to my other account, let me know when you get this as I want the next payroll payment deposited in my new account.
Thanks.
[Executive Name]
Executive Impersonation Payroll Diversion BEC Attack
This text-based BEC attack impersonates an executive using a spoofed email address and a maliciously registered domain to divert payroll deposits to a fraudulent account.
kindly view attachment
Fake Invoice Word Document Attachment Credential Phishing Attack
This payload-based attack impersonates a vendor/supplier and DocuSign using an external compromised account, a Word Document attachment, and a fake invoice theme to steal credentials.
[Recipient First Name],
How are you doing today, before this skip my mind today i think i will like to appreciate some of the staff with little incentive today, so i will like you to perform little task for me soon, let me know if you are available so that i can send you details.
Regards,
[Executive Name]
Executive Impersonation Employee Incentive Gift Card Request BEC Attack
This text-based BEC attack impersonates an executive using a spoofed display name, a maliciously registered domain, and an employee incentive theme to request the purchase of gift cards.
Hello,
Our payment record file shows that there is an outstanding payment that is overdue with you. Can you confirm to us the status of our outstanding and due payments? Please get back to us at the earliest with the total amount outstanding with corresponding due dates and invoices respectively.
We would appreciate it if you could check this out on your end and If the payment has already been sent, please kindly notify us but put a hold on any due payments because of recent changes in our company details.
Kind regards,
[Vendor Employee Title]
[Vendor Company Name].
[Vendor Contact Information]
Vendor Impersonation Payment Inquiry BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a spoofed email address, a free webmail account, and a payment inquiry theme to request a fraudulent payment.
Hi [Recipient First Name],
I asked Karen Page, Finance Controller at Collins Contractor LTD to contact you some days ago regarding a late invoice.
These are consulting services that CC LTD offered us, I will give you more information about it later after review.
Could you have it paid today?
Regards,
[Executive Name]
Forwarded message --------- ----------
From: Ange Page <ange.page@collins-contractor.com>
Sent: 28 April 2022 15:59
Subject: Invoice 960201 Overdue
Hi Rich,
I have sent the invoice back as a reminder. I would like to inform you that it is OverDue today.
Should we expect this payment soon?
Sincerely,
Karen Page
Financial Controller
Collins Contractors Ltd
Executive Impersonation Overdue Payment Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using a fake email chain, a spoofed display name, a maliciously registered domain, and an overdue payment theme to request a fraudulent payment.
Hello [Recipient First Name],
How are you doing, Are you available? I need your help in getting gift cards for the community health center. Please confirm if you can get some today.
Have a Great Day!
[Impersonated Employee Name]
Employee Impersonation Community Service Gift Card Request BEC Attack
This text-based BEC attack impersonates an employee using a spoofed email address, a free webmail account, and a community service theme to request the purchase of gift cards.
Office 365
Password for [Recipient Email Address] will expire on 5/13/2022
Action required Fix this below:
Keep Same Password
[Recipient Email Domain]
Microsoft Password Expiration Credential Phishing Attack
This link-based attack impersonates Microsoft using a password expiration theme to steal credentials.
Hi,
Just wanted to say thank you for your action. Your account has been debited $485 for the 2-years renewal of your Geek Squad computer & tablet services. We’re so happy to have customers like you.
Your Extended Service Summary:
Your account number: 28836822429631
Transaction date: May 12, 2022
✆✆ If you have any questions about the quick cancellation & refund, please reach out soon at 888-985-2139
We truly appreciate your business and look forward to serving you again.
Faithfully Yours,
Geek-Squad™ Customer Service Center
✆ 24x7 Helpline: 888-985-2139
28400 Telegraph Rd, Southfield, MI 48034
Copyright © 2002-2022 GeekSquadInc. All rights reserved.
Geek Squad Subscription Renewal Fake Billing Scam
This text-based fake billing scam impersonates Geek Squad using a subscription renewal theme.
Good day,
How soon can I get a copy of our current aging report (receivables by their due dates), this report should include their various email addresses in an excel spreadsheet.
How soon can you sort this ?
Treat as urgent.
Thanks.
Executive Impersonation Aging Report Compromise BEC Attack
This text-based BEC attack impersonates an executive using display name spoofing and a free webmail account to request a copy of an aging report.
Netflix
Your subscription suspended
Dear Customer,
We could not authorize your payment for the next
billing cycle of your subscription therefore we've
suspended your membership. But your current
subscription is active until it expires.
To resolve the issue, Please update your payment information by pressing the button below.
RESTART MEMBERSHIP
For more information. Please visit the Help Center for more info or contact us.
Netflix Suspended Account Credential Phishing Attack
This link-based attack impersonates Netflix using a maliciously registered domain and a suspended account theme to steal credentials.