Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

This invoice is for the billing period May 05.

Greeting from Microsoft Service, we�re writing to provide you with an electronic invoice for your use of Microsoft service. Additional information regarding your bill, individual service charge details, and your account history are available on the account activity page.

Customer Id:225222819

Email:[Recipient Email Address]

Date : Thursday, 05-05-2022

Hello,

We would much appreciate if you could let us know the status of this Micorosoft service. Please do not hesitate to call us if you have any questions about the balance due on your account if you have already sent us your payment. Contact +1(845-789-5291)

ORDER CONFIRMATION

Total

Next Generation Windows Defender

Windlow 11 Advanced Threat Protection

$199.00

$149.00

Discount

Total

$8

$340.00

Microsoft Account

Thank you for using our services

Get 20% OFF on your next order

Microsoft Fake Billing Scam

Subject:
"
Order Confirmation
"
Attack Date:
May 5, 2022

This text-based fake billing scam impersonates Microsoft using a fake payment receipt theme.

No items found.
Type:
Fake Billing Scam
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Impersonated Party:
Impersonated Brand:
Microsoft
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],

        Please  can you share with me a PDF or XL list of all our outstanding receivable invoice / aging  report to date with contacts

Regards,
[Executive Name].

Executive Impersonation Aging Report BEC Attack

Subject:
"
Report
"
Attack Date:
May 4, 2022

This text-based BEC attack impersonates an executive using display name spoofing and a maliciously registered domain to request a copy of an aging report.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello,

We want to update our accounting record for the previous months till date which has not yet been balanced. We are currently looking to clear all outstanding, due and open invoices and would like to request an up-to-date statement of our account showing all unpaid and outstanding invoices for our reference.

Please send us as a reminder a copy of the invoice or the unpaid balance with the due dates for accounting purposes and do not make any payment without notifying us for confirmation.

Best regards,
[VENDOR EMPLOYEE NAME]
CFO

Vendor Impersonation Payment Inquiry BEC Attack

Subject:
"
Invoice Settlement Reminder
"
Attack Date:
May 4, 2022

This text-based BEC attack impersonates a vendor/supplier using email spoofing, a free webmail account, and a payment inquiry theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi,

 Do you mind giving me information on how to update my payroll direct
deposit, and also I will like to know when it would be effective as
soon as it is updated?

Thanks.


[Recipient Name]

[Recipient Title]

[Recipient Company]

Employee Impersonation Payroll Diversion BEC Attack

Subject:
"
[Recipient Company Name]
"
Attack Date:
May 4, 2022

This text-based BEC attack impersonates an employee using a personalized email subject, display name spoofing, and a free webmail account to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[Recipient First Name],

We have engaged King & Spalding LLP to represent us in Project Vida which involves the acquisition of certain distressed assets. I need you to work with Daniel Crosby, the partner in charge, to resolve a time-sensitive matter by the close of business this week.

Please let me know soonest by email when you are available later today and the best number to reach you at.

Thanks.

[Executive Name]


Sent from my iPhone

Executive Impersonation Legal Matter Payment Fraud BEC Attack

Subject:
"
Project Vida - Legal Matter
"
Attack Date:
May 4, 2022

This text-based BEC attack impersonates an executive using display name spoofing, a maliciously registered domain, and a legal matter theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[First Name] has shared a document with you for loop:
[Address] - [Name]



VIEW DOCUMENT

Dotloop Fake Document Credential Phishing Attack

Subject:
"
Please review Payoff Authorization
"
Attack Date:
May 4, 2022

This link-based attack impersonates Dotloop using a fake document theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Dotloop
Attachment Type:
Language:
See Attack Details

Check#6253

Dear, Team

View attached Statements

Best regards,

[Impersonated Name]

[Impersonated Title]

[Impersonated Company Name]

[Impersonated Phone Numbers]


The information contained in this transmission may contain privileged and confidential information, including patient information protected by federal and state privacy laws. It is intended only for the use of the person(s) named above. If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, or duplication of this communication is strictly prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.

Evernote Fake Payment Receipt Credential Phishing Attack

Subject:
"
View Attached Payment
"
Attack Date:
May 4, 2022

This link-based attack impersonates Evernote and an external third party using a fake attachment, compromised external account, and a fake payment receipt theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
External Party - Other
Impersonated Brand:
Evernote
Attachment Type:
Language:
See Attack Details

EFT Payment Copy For [Recipient Email Address]


Payment Remittance on May 3, 2022
            ‍

DOWNLOAD                  

Attached is the payment copy for: EFTPymnt#0503

FileType :-  PDF/HTML                                
Pages    :-     2

Fake Payment Receipt Credential Phishing Attack

Subject:
"
COMPLETED: EFT-Payment Remittance on May 3, 2022
"
Attack Date:
May 3, 2022

This link-based attack uses a fake payment receipt theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],

Has payroll been completed? I received a new account today, what information would you need to update my direct deposit account?

Regards,
[Impersonated Employee Name].


Get Outlook for iOS

Employee Impersonation Payroll Diversion BEC Attack

Subject:
"
[Impersonated Employee Last Name] 03/05
"
Attack Date:
May 3, 2022

This text-based BEC attack impersonates an employee using a personalized email subject, display name spoofing, and a free webmail account to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Other
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Dear [Recipient Email Address] , 755748722657

Today 5/3/2022-21:25:12 Meta suspend your facebook account. [322306995]

How to fix a suspended account: [30328459073870]

Start Now

Ref: 146102106175

Facebook Suspended Account Credential Phishing Attack

Subject:
"
Account Suspended 5/3/2022-21:25:12
"
Attack Date:
May 3, 2022

This link-based attack impersonates Facebook using a free webmail account and a suspended account theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Facebook
Attachment Type:
Language:
See Attack Details

Whoops.. There are no results found.