Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

[Recipient First Name],

I am looking to have my direct deposit account information updated to my other account, let me know when you get this as I want the next payroll payment deposited in my new account.

Thanks.

[Executive Name]

Executive Impersonation Payroll Diversion BEC Attack

Subject:
"
New Details
"
Attack Date:
May 12, 2022

This text-based BEC attack impersonates an executive using a spoofed email address and a maliciously registered domain to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

kindly view attachment

Fake Invoice Word Document Attachment Credential Phishing Attack

Subject:
"
Outstanding Invoice Paid
"
Attack Date:
May 12, 2022

This payload-based attack impersonates a vendor/supplier and DocuSign using an external compromised account, a Word Document attachment, and a fake invoice theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Payload-based
Goal:
Credential Theft
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
DocuSign
Attachment Type:
Word Document
Language:
See Attack Details

[Recipient First Name],

How are you doing today, before this skip my mind today i think i will like to appreciate some of the staff with little incentive today, so i will like you to perform little task for me soon, let me know if you are available so that i can send you details.

Regards,

[Executive Name]

Executive Impersonation Employee Incentive Gift Card Request BEC Attack

Subject:
"
Surprise Incentive
"
Attack Date:
May 12, 2022

This text-based BEC attack impersonates an executive using a spoofed display name, a maliciously registered domain, and an employee incentive theme to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello,

Our payment record file shows that there is an outstanding payment that is overdue with you. Can you confirm to us the status of our outstanding and due payments? Please get back to us at the earliest with the total amount outstanding with corresponding due dates and invoices respectively.

We would appreciate it if you could check this out on your end and If the payment has already been sent, please kindly notify us but put a hold on any due payments because of recent changes in our company details.


Kind regards,
[Vendor Employee Title]
[Vendor Company Name].
[Vendor Contact Information]

Vendor Impersonation Payment Inquiry BEC Attack

Subject:
"
Payment Outstanding
"
Attack Date:
May 12, 2022

This text-based BEC attack impersonates a vendor/supplier using a spoofed email address, a free webmail account, and a payment inquiry theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],

I asked Karen Page, Finance Controller at Collins Contractor LTD to contact you some days ago regarding a late invoice.

These are consulting services that CC LTD offered us, I will give you more information about it later after review.

Could you have it paid today?

Regards,
[Executive Name]

Forwarded message --------- ----------

From:  Ange Page <ange.page@collins-contractor.com>
Sent: 28 April 2022 15:59
Subject: Invoice 960201 Overdue

Hi Rich,

I have sent the invoice back as a reminder. I would like to inform you that it is OverDue today.

Should we expect this payment soon?

Sincerely,

Karen Page

Financial Controller

Collins Contractors Ltd

Executive Impersonation Overdue Payment Payment Fraud BEC Attack

Subject:
"
Overdue
"
Attack Date:
May 12, 2022

This text-based BEC attack impersonates an executive using a fake email chain, a spoofed display name, a maliciously registered domain, and an overdue payment theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello [Recipient First Name],

How are you doing, Are you available?  I need your help in getting gift cards for the community health center. Please confirm if you can get some today.

Have a Great Day!
[Impersonated Employee Name]

Employee Impersonation Community Service Gift Card Request BEC Attack

Subject:
"
Community Giving
"
Attack Date:
May 12, 2022

This text-based BEC attack impersonates an employee using a spoofed email address, a free webmail account, and a community service theme to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Office 3­6­5­

Password f­or [Recipient Email Address] w­ill expire o­n 5/13/2022

Action required Fix t­hi­s b­el­ow:

K­ee­p S­am­e Password

[Recipient Email Domain]

Microsoft Password Expiration Credential Phishing Attack

Subject:
"
Admin Report:5/13/2022
"
Attack Date:
May 12, 2022

This link-based attack impersonates Microsoft using a password expiration theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Microsoft
Attachment Type:
Language:
See Attack Details

Hi,

Just wanted to say thank you for your action. Your account has been debited $485 for the 2-years renewal of your Geek Squad computer & tablet services. We’re so happy to have customers like you.

Your Extended Service Summary:

Your account number: 28836822429631

Transaction date: May 12, 2022

✆✆ If you have any questions about the quick cancellation & refund, please reach out soon at 888-985-2139

We truly appreciate your business and look forward to serving you again.

Faithfully Yours,

Geek-Squad™ Customer Service Center

✆ 24x7 Helpline: 888-985-2139

28400 Telegraph Rd, Southfield, MI 48034

Copyright © 2002-2022 GeekSquadInc. All rights reserved.

Geek Squad Subscription Renewal Fake Billing Scam

Subject:
"
127573870813247
"
Attack Date:
May 12, 2022

This text-based fake billing scam impersonates Geek Squad using a subscription renewal theme.

No items found.
Type:
Fake Billing Scam
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Impersonated Party:
Impersonated Brand:
Geek Squad
Attachment Type:
Language:
See Attack Details

Good day,

How soon can I get a copy of our current aging report (receivables by their due dates), this report should include their various email addresses in an excel spreadsheet.

How soon can you sort this ?

Treat as urgent.

Thanks.

Executive Impersonation Aging Report Compromise BEC Attack

Subject:
"
Aging Reports AR With Contacts Emails
"
Attack Date:
May 12, 2022

This text-based BEC attack impersonates an executive using display name spoofing and a free webmail account to request a copy of an aging report.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Netflix
Your subscription suspended

Dear Customer,

We could not authorize your payment for the next
billing cycle of your subscription therefore we've
suspended your membership. But your current
subscription is active until it expires.
To resolve the issue, Please update your payment information by pressing the button below.

RESTART MEMBERSHIP
For more information. Please visit the Help Center for more info or contact us.

Netflix Suspended Account Credential Phishing Attack

Subject:
"
Your subscription suspended : Netflix
"
Attack Date:
May 12, 2022

This link-based attack impersonates Netflix using a maliciously registered domain and a suspended account theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Netflix
Attachment Type:
Language:
See Attack Details

Whoops.. There are no results found.