Attack Vault
The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.
This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.
This invoice is for the billing period May 05.
Greeting from Microsoft Service, we�re writing to provide you with an electronic invoice for your use of Microsoft service. Additional information regarding your bill, individual service charge details, and your account history are available on the account activity page.
 
Customer Id:225222819
Email:[Recipient Email Address]
Date : Thursday, 05-05-2022
Hello,
We would much appreciate if you could let us know the status of this Micorosoft service. Please do not hesitate to call us if you have any questions about the balance due on your account if you have already sent us your payment. Contact +1(845-789-5291)
ORDER CONFIRMATION
Total
 
Next Generation Windows Defender
Windlow 11 Advanced Threat Protection
$199.00
$149.00
 
Discount
Total
$8
$340.00
 
 
Microsoft Account
 
Thank you for using our services
Get 20% OFF on your next order
Microsoft Fake Billing Scam
This text-based fake billing scam impersonates Microsoft using a fake payment receipt theme.

Hi [Recipient First Name],
 
         Please  can you share with me a PDF or XL list of all our outstanding receivable invoice / aging  report to date with contacts
Regards,
[Executive Name].
Executive Impersonation Aging Report BEC Attack
This text-based BEC attack impersonates an executive using display name spoofing and a maliciously registered domain to request a copy of an aging report.

Hello,
We want to update our accounting record for the previous months till date which has not yet been balanced. We are currently looking to clear all outstanding, due and open invoices and would like to request an up-to-date statement of our account showing all unpaid and outstanding invoices for our reference.
Please send us as a reminder a copy of the invoice or the unpaid balance with the due dates for accounting purposes and do not make any payment without notifying us for confirmation.
Best regards,
[VENDOR EMPLOYEE NAME]
CFO
Vendor Impersonation Payment Inquiry BEC Attack
This text-based BEC attack impersonates a vendor/supplier using email spoofing, a free webmail account, and a payment inquiry theme to request a fraudulent payment.

Hi,
  Do you mind giving me information on how to update my payroll direct
deposit, and also I will like to know when it would be effective as
soon as it is updated?
Thanks.
[Recipient Name]
[Recipient Title]
[Recipient Company]
Employee Impersonation Payroll Diversion BEC Attack
This text-based BEC attack impersonates an employee using a personalized email subject, display name spoofing, and a free webmail account to divert payroll deposits to a fraudulent account.

[Recipient First Name],
We have engaged King & Spalding LLP to represent us in Project Vida which involves the acquisition of certain distressed assets. I need you to work with Daniel Crosby, the partner in charge, to resolve a time-sensitive matter by the close of business this week.
Please let me know soonest by email when you are available later today and the best number to reach you at.
Thanks.
[Executive Name]
Sent from my iPhone
Executive Impersonation Legal Matter Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using display name spoofing, a maliciously registered domain, and a legal matter theme to request a fraudulent payment.

[First Name] has shared a document with you for loop:
[Address] - [Name]
	
 
	
VIEW DOCUMENT
Dotloop Fake Document Credential Phishing Attack
This link-based attack impersonates Dotloop using a fake document theme to steal credentials.

Check#6253
Dear, Team
View attached Statements
Best regards,
[Impersonated Name]
[Impersonated Title]
[Impersonated Company Name]
[Impersonated Phone Numbers]
 
The information contained in this transmission may contain privileged and confidential information, including patient information protected by federal and state privacy laws. It is intended only for the use of the person(s) named above. If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, or duplication of this communication is strictly prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.
Evernote Fake Payment Receipt Credential Phishing Attack
This link-based attack impersonates Evernote and an external third party using a fake attachment, compromised external account, and a fake payment receipt theme to steal credentials.

EFT Payment Copy For [Recipient Email Address]
Payment Remittance on May 3, 2022
             
DOWNLOAD                   
 
Attached is the payment copy for: EFTPymnt#0503
FileType :-  PDF/HTML                                 
Pages    :-     2
Fake Payment Receipt Credential Phishing Attack
This link-based attack uses a fake payment receipt theme to steal credentials.

Hi [Recipient First Name],
Has payroll been completed? I received a new account today, what information would you need to update my direct deposit account?
Regards,
[Impersonated Employee Name].
Get Outlook for iOS
Employee Impersonation Payroll Diversion BEC Attack
This text-based BEC attack impersonates an employee using a personalized email subject, display name spoofing, and a free webmail account to divert payroll deposits to a fraudulent account.

Dear [Recipient Email Address] , 755748722657
Today 5/3/2022-21:25:12 Meta suspend your facebook account. [322306995]
How to fix a suspended account: [30328459073870]
Start Now
Ref: 146102106175
Facebook Suspended Account Credential Phishing Attack
This link-based attack impersonates Facebook using a free webmail account and a suspended account theme to steal credentials.
