Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

Hi [Recipient First Name],


We are currently on an audit process and as a result of this, we are having delays with accounts reconciliations on all aging receivables.


Could you advise if we can expect payments this week on due invoices? Would appreciate you look into this and feed me back?


I’m happy to answer any questions you might have.


Have a great day!  


 

Thank you,


[Vendor Employee Name]

[Vendor Employee Title]

Vendor Impersonation Payment Inquiry BEC Attack

Subject:
"
Re: [Vendor Company Name] - Open Invoice
"
Attack Date:
June 27, 2022

This text-based BEC attack impersonates a vendor/supplier using a look-alike domain and a payment inquiry theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hello, good morning.


I need your help in updating my (Direct Deposit) details. Can I just send a voided check? My payroll portal isn't working,

Wishing you a wonderful day.


Sincerely, regards.

[Executive Name]

[Executive Title]

Executive Impersonation Payroll Diversion BEC Attack

Subject:
"
Changing The P-Stub..
"
Attack Date:
June 27, 2022

This text-based BEC attack impersonates an executive using a spoofed display name and a free webmail account to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],


Please find attached your remittance advice for [Vendor Company Name]. Payment will be in your account Friday.


[Vendor Company Name] BACS REMIT PAYMENT DOCUMENT.xlsx


This is system generated email, please do not reply.

Kind regards

[Vendor Employee Name]

Accounts Payable Manager


Sent Mon, Jun 27, 2022 5:49 PM

Fake Invoice Credential Phishing Attack

Subject:
"
Paid Invoice for [Vendor Company Name] 6/27/2022
"
Attack Date:
June 27, 2022

This link-based attack impersonates a vendor/supplier using an external compromised account and a fake invoice theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Dear [Recipient First Name],

Sending this as regards an update on my Bank details and would like to request that my Paycheck information be changed from it's current profile to the new account details. Can the change be effective for the current pay date?



Yours sincerely


[Executive Name]

Executive Impersonation Payroll Diversion BEC Attack

Subject:
"
Instant response!!
"
Attack Date:
June 27, 2022

This text-based BEC attack impersonates an executive using a spoofed email address, a matching malicious domain username, and a maliciously registered domain to divert payroll deposits to a fraudulent account.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payroll Diversion
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Good morning,


Please advise when we should expect to receive remittance for invoices due to [Vendor Company Name].


Thank you,

AR Team

Vendor Impersonation Payment Inquiry Credential Phishing Attack

Subject:
"
Aged Receivables Status
"
Attack Date:
June 27, 2022

This text-based attack impersonates a vendor/supplier using a look-alike domain, a spoofed display name, and a payment inquiry theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Credential Theft
Impersonated Party:
External Party - Vendor/Supplier
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Charged Payment For Order


Hi [Recipient First Name]


Your order has been fulfilled. Please contact our customer service department at the phone shown below.

Information Support

1 808 698 0408

 Information on Order


  Registered Email - [Recipient Email Address]

  Transaction Number - 5034327

  Order Number - iiHv-pIkDcb-EexVn



Product

SOLANA


Unit Price

801.5


Quantity

x1


Total Price

801.5

Total Invoice Paid $801.5


Your order will be shipped out within 24 hours after receiving your payment confirmation. You may choose to cancel the order at any time before we ship out. Please call us immediately if you wish to cancel the order.


We're available 24/7 1 808 698 0408

PayPal Fake Payment Receipt Fake Billing Scam

Subject:
"
[Recipient Name], here is your bill
"
Attack Date:
June 24, 2022

This text-based fake billing scam impersonates PayPal using a personalized email subject, a free webmail account, and a fake payment receipt theme.

No items found.
Type:
Fake Billing Scam
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Impersonated Party:
Impersonated Brand:
PayPal
Attachment Type:
Language:
See Attack Details

Are you available? Please confirm if an international wire payment can be processed to a consultant today. Let me know when you get this so i can provide details.


Best Regards,


[Executive First Name]

Executive Impersonation New Vendor Payment Fraud BEC Attack

Subject:
"
Oversea payment
"
Attack Date:
June 24, 2022

This text-based BEC attack impersonates an executive using a free webmail account, a spoofed display name, and a new vendor theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Bill to

Walmart customer


Invoice #

$899.69


Payment terms

Debit/credit


Amount due

$899.69


Issue date

June 23 2022


If you don’t recognize this order, please call immediately at +1- 801-363-0143.


Description

Product/service-name

iPhone 13 pro max 1tb


Amount

$899.69

Thank you for making your purchase from Walmart.

Your order id is XL667788.

Subtotal $899.69

Tax

misc.

Amount due $899.69


Note: This is an Auto-generated message please call us for any query or to cancel this order.

Customer Support: +1- 801-363-0143.

Walmart Fake Payment Receipt Fake Billing Scam

Subject:
"
CREDIT CARD PAYMENT INVOICE
"
Attack Date:
June 24, 2022

This text-based fake billing scam impersonates Walmart using an external compromised account and a fake payment receipt theme.

No items found.
Type:
Fake Billing Scam
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Impersonated Party:
Impersonated Brand:
Walmart
Attachment Type:
Language:
See Attack Details

Hey [Recipient First Name],


I am reaching out for the Aging Report Spreadsheet from your department to review all debtors. Once you find these, Please kindly send them as soon as possible . I need your prompt assistance on this.


I am looking forward to hearing from you soon.


Thanks.

[Executive Name]



Sent from my T-Mobile 4G LTE Device

Executive Impersonation Aging Report Theft BEC Attack

Subject:
"
Good Afternoon [Recipient First Name]
"
Attack Date:
June 24, 2022

This text-based BEC attack impersonates an executive using a spoofed email address, a personalized email subject, and a maliciously registered domain to request a copy of an aging report.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Aging Report Theft
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hi [Recipient First Name],



We hired a private contractor and we need to make a one-off payment for them. Can we set up a payment for this vendor today?



Regards,




[Executive First Name]

Executive Impersonation New Vendor Payment Fraud BEC Attack

Subject:
"
Payout Request
"
Attack Date:
June 23, 2022

This text-based BEC attack impersonates an executive using a maliciously registered domain, a spoofed display name, and a new vendor theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Whoops.. There are no results found.