Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF bid/proposal lure with credential theft indicators
3d ago
Mar 27th, 2026
Sublime Security
Body: PayApp transaction reference pattern
3d ago
Mar 27th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
4d ago
Mar 26th, 2026
Sublime Security
Lookalike sender domain (untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
VIP impersonation with urgent request (strict match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
VIP impersonation with BEC language (near match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
Brand Impersonation: Procore
10d ago
Mar 20th, 2026
Sublime Security
Attachment: PDF contains W9 or invoice YARA signatures
12d ago
Mar 18th, 2026
Sublime Security
Service abuse: Domains By Proxy sender
12d ago
Mar 18th, 2026
Sublime Security
Attachment: ICS with employee policy review lure
14d ago
Mar 16th, 2026
Sublime Security
Sender: IP address in local part
18d ago
Mar 12th, 2026
Sublime Security
VIP impersonation with w2 request with reply-to mismatch
18d ago
Mar 12th, 2026
Sublime Security
Brand impersonation: SendGrid
18d ago
Mar 12th, 2026
Sublime Security
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
19d ago
Mar 11th, 2026
Sublime Security
Brand impersonation: McAfee
19d ago
Mar 11th, 2026
Sublime Security
Impersonation: Legal firm with copyright infringement notice
20d ago
Mar 10th, 2026
Sublime Security
BEC/Fraud: Romance scam
21d ago
Mar 9th, 2026
Sublime Security
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
21d ago
Mar 9th, 2026
Sublime Security
Link: Google Drawings link from new sender
21d ago
Mar 9th, 2026
Sublime Security
Suspicious display name: Gmail sender with engaging language
24d ago
Mar 6th, 2026
Sublime Security