Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Formester with suspicious link behavior
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-formester-with-suspicious-link-behavior-e4b74fd4
Attachment: PDF generated with wkhtmltopdf tool and default title
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-generated-with-wkhtmltopdf-tool-and-default-title-64e6c8a8
Xero invoice abuse
16d ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/xero-invoice-abuse-6538c600
Business Email Compromise: Request for mobile number via reply thread hijacking
18d ago
Dec 15th, 2025
Sublime Security
/feeds/core/detection-rules/business-email-compromise-request-for-mobile-number-via-reply-thread-hijacking-0282f346
Attachment: Calendar file with invisible Unicode characters
18d ago
Dec 15th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-calendar-file-with-invisible-unicode-characters-050fceac
Scam: Piano giveaway
22d ago
Dec 11th, 2025
Sublime Security
/feeds/core/detection-rules/scam-piano-giveaway-1a91a203
Fake thread with suspicious indicators
24d ago
Dec 9th, 2025
Sublime Security
/feeds/core/detection-rules/fake-thread-with-suspicious-indicators-c2e18a57
Credential phishing: Generic document sharing
25d ago
Dec 8th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Suspicious request for financial information
27d ago
Dec 6th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d
Fraudulent order confirmation/shipping notification from Chinese sender domain
30d ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/fraudulent-order-confirmationshipping-notification-from-chinese-sender-domain-4392a14e
Service abuse: Roomsy with unrelated body content
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-roomsy-with-unrelated-body-content-18e08a5a
Link: URL scheme obfuscation via split HTML anchors
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-url-scheme-obfuscation-via-split-html-anchors-10375948
Brand impersonation: Purdue ePlanroom with suspicious links
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-purdue-eplanroom-with-suspicious-links-4db5b0b6
Reconnaissance: Short generic greeting message
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
Impersonation: Social Security Administration (SSA)
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/impersonation-social-security-administration-ssa-6196767e
Link abuse: Self-service creation platform link with suspicious recipient behavior
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-abuse-self-service-creation-platform-link-with-suspicious-recipient-behavior-384ad135
Brand impersonation: AARP
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-aarp-561a7f87
Body: Embedded email headers indicative of thread hijacking/abuse
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb
Attachment: Legal themed message or PDF with suspicious indicators
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
Link: Cryptocurrency fraud with suspicious links
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce