Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
PayPal invoice abuse
1d ago
Feb 11th, 2026
Sublime Security
/feeds/core/detection-rules/paypal-invoice-abuse-0ff7a0d4
Reconnaissance: Empty subject with mismatched reply-to from new sender
6d ago
Feb 6th, 2026
Sublime Security
/feeds/core/detection-rules/reconnaissance-empty-subject-with-mismatched-reply-to-from-new-sender-12f4bd45
Canva infrastructure abuse
6d ago
Feb 6th, 2026
Sublime Security
/feeds/core/detection-rules/canva-infrastructure-abuse-b69fdb5c
Credential phishing: Generic document sharing
7d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Attachment: Legal themed message or PDF with suspicious indicators
7d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
Attachment: PDF contains W9 or invoice YARA signatures
8d ago
Feb 4th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-contains-w9-or-invoice-yara-signatures-9a8e8a98
Suspicious display name: Gmail sender with engaging languages
9d ago
Feb 3rd, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-display-name-gmail-sender-with-engaging-languages-82ca0ff1
Impersonation: Executive using numbered local part
13d ago
Jan 30th, 2026
Sublime Security
/feeds/core/detection-rules/impersonation-executive-using-numbered-local-part-8e005a22
VIP impersonation with w2 request
14d ago
Jan 29th, 2026
Sublime Security
/feeds/core/detection-rules/vip-impersonation-with-w2-request-e7e73fad
Brand impersonation: Aramco
15d ago
Jan 28th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-aramco-96e87699
Reconnaissance: Hotel booking reply-to redirect
16d ago
Jan 27th, 2026
Sublime Security
/feeds/core/detection-rules/reconnaissance-hotel-booking-reply-to-redirect-08c36035
Reconnaissance: Short generic greeting message
16d ago
Jan 27th, 2026
Sublime Security
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
Attachment: Fake lawyer & sports agent identities
17d ago
Jan 26th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-fake-lawyer-and-sports-agent-identities-7d3a2478
Attachment: ICS file with meeting prefix
17d ago
Jan 26th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-ics-file-with-meeting-prefix-383a5810
Headers: Fake in-reply-to with wildcard sender and missing thread context
20d ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/headers-fake-in-reply-to-with-wildcard-sender-and-missing-thread-context-89da670a
Service abuse: Adobe legitimate domain with document approval language
20d ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4
BEC/Fraud: Romance scam
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/becfraud-romance-scam-0243cdaa
Brand impersonation: AuthentiSign
22d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-authentisign-445a8c8b
Attachment: Invoice and W-9 PDFs with suspicious creators
22d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/attachment-invoice-and-w-9-pdfs-with-suspicious-creators-305d6e32
Link: Self-sent message with quarterly document review request
22d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6