Attack Vault
The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.
This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.
Salut [Recipient First Name]
Bonjour, Pourriez-vous me répondre par e-mail ? J'aurai besoin de votre aide. Je ne connais pas ton emploi du temps pour aujourd'hui,
Merci et Cordialement,
[Executive Name]
[Executive Title]
Sent from my mobile device.
French Executive Impersonation Gift Card Request BEC Attack
This text-based French-language BEC attack impersonates an executive using a spoofed display name and a free webmail account to request the purchase of gift cards.
Hola [Recipient First Name]
Cambié de banco y me gustaría cambiar los detalles de mi cuenta de Salario. ¿Puede este cambio entrar en vigencia antes de la fecha de pago actual?
Saludos
[Executive Name]
Spanish Executive Impersonation Payroll Diversion BEC Attack
This text-based Spanish-language BEC attack impersonates an executive using a spoofed display name and a free webmail account to divert payroll deposits to a fraudulent account.
Hello [Recipient First Name],
We are having a current review in our accounting system.
Can you sort all our receivables by their due date to estimate the bad debts expense and should be arranged into columns such as: Current, 1-30 days past due, 31-60 days past due, 61-90+ days past due.
Also include their various emails and phone numbers in an excel sheet, please kindly attend to this request as soon as possible and let me know when you can send it over.
I await your response.
Thank You,
[Executive First Name].
Executive Impersonation Aging Report Compromise BEC Attack
This text-based BEC attack impersonates an executive using a spoofed display name and a maliciously registered domain to request a copy of an aging report.
Hallo [Recipient First Name]
Ik ben van bank veranderd en wil de gegevens van mijn salarisrekening wijzigen. Kan deze wijziging van kracht worden vóór de huidige salarisdatum?
vriendelijke groeten
[Impersonated Employee Name]
Dutch Employee Impersonation Payroll Diversion BEC Attack
This text-based Dutch-language BEC attack impersonates an employee using a spoofed display name and a free webmail account to divert payroll deposits to a fraudulent account.
Hola [Recipient First Name]
Avísame cuando estés disponible. Hay algo que necesito que hagas. Voy a ir a una reunión ahora con llamadas telefónicas limitadas, así que solo responda mi correo electrónico con su número de WhatsApp y espere mi mensaje de texto.
Saludos cordiales
Spanish Executive Impersonation Gift Card Request BEC Attack
This text-based Spanish-language BEC attack impersonates an executive using a WhatsApp number request, a spoofed display name, and a free webmail account to request the purchase of gift cards.
--
Sėnd me yòur phone numbėr, I neėd to get sòmething done.
[Executive Name]
Chief Executive Officer
Thànks
Executive Impersonation Gift Card Request BEC Attack
This text-based BEC attack impersonates an executive using a foreign character substitution, a cell phone number request, a spoofed display name, and a free webmail account to request the purchase of gift cards.
Hello,
I hope you’re well. I am reaching out to you regarding Invoice #329. This is a reminder that payment was due on May 6th, and is now two weeks overdue. Please send payment as soon as possible.
As per my company’s payment terms, you will be charged a late fee of 2% per month for invoices 30-days overdue. I have attached the invoice to this email for your reference.
Please let me know if you have any questions.
Kind Regards,
[Vendor Employee Name]
Accounts
[Vendor Company Name]
[Vendor Address]
Vendor Impersonation Overdue Payment BEC Attack
This text-based BEC attack impersonates a vendor/supplier using a look-alike domain, a spoofed display name, and an overdue payment theme to request a fraudulent payment.
[Recipient First Name],
We need to pay a remittance to McDermott Will & Emery LLP for our overdue invoice. Peter from McDermott Will & Emery would contact you regarding the unpaid invoice for processing asap.
Have you heard from him yet? Please get back to me asap
Best Regards
[Executive Name]
Executive Impersonation Overdue Payment Payment Fraud BEC Attack
This text-based BEC attack impersonates an executive using a spoofed display name, a free webmail account, and an overdue payment theme to request a fraudulent payment.
To, [Recipient Name]
Address: [Recipient Address]
Email: [Recipient Email Address]
This is last chance for you, to hold this Case File you must submit a minimum payment of $300.00
You can email us on below address for any query or payment mode;
acsdebtsettlementdepartment.us@gmail.com
This Legal Proceeding will be issued on your Docket Number DL-20731642 with one of Cash Advance Inc. Company to let you know that after making calls on your phone number, we were unable to reach out to you. So, the account's department of Cash Advance has decided to mark this case as a Flat Refusal and press Legal Charges against you.
CASE NO: FGTM-98524L2
Amount Outstanding: $1210.86
We have sent you this warning notification about legal proceedings of March 8, 2015, but you failed to respond on time now. If you failed to respond in next 4 HOURS, we will register this case in court. Consider this as a final warning. And we will be Emailing/ Fax this issue to your current employer to make sure they take strict against you. Your salary wages will we garnished.
Do revert if you want to get rid of these legal consequences and make payment arrangement today or else, we will be proceeding legally against you and this notification will also be sent to your current employer. The opportunity to take care of this voluntarily is quickly coming to an end. I regret to advise that unless payment is received before end of this week this invoice will be passed over to our legal authority. This could seriously affect your credit rating, so I urge you contact us immediately to make payment or arrange an alternative before this date.
Legal Matter Extortion Attack
This text-based extortion attack uses a maliciously registered domain and a legal matter theme to demand a payment.
Password Assistance
Hello,
We received a request to change the password associated with the username [Recipient Email Address],
If you are not requested this code please connect on +1 (423) 415-0818
Please provide below mentioned code with your Email address to verify
845321
We take your account security very seriously. We will never ask you to disclose or
Verify your email password. If you receive a suspicious email with a link to update your account information,
do not click on the link instead. Report the email to our technical support for investigation.
Thanks & Regards,
Email Support Team
+1 (423) 415-0818
Suspicious Account Activity Malware Attack
This text-based attack uses a free webmail account and a suspicious account activity theme to deliver malware.