Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
VIP Impersonation via Google Group relay with suspicious indicators
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
VIP impersonation with charitable donation fraud
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e
Service Abuse: ExactTarget with suspicious sender indicators
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-exacttarget-with-suspicious-sender-indicators-6154f197
Brand impersonation: SendGrid
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f
Headers: Outlook Express mailer
6d ago
Nov 6th, 2025
Sublime Security
/feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de
Vendor impersonation: Thread hijacking with typosquat domain
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Credential phishing: Generic document sharing
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Spam/fraud: Predatory journal/research paper request
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b
Job scam (unsolicited sender)
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/job-scam-unsolicited-sender-a37dc32d
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/advance-fee-fraud-aff-from-freemail-provider-or-suspicious-tld-6a5af373
Link: File sharing impersonation with suspicious language and sending patterns
12d ago
Oct 31st, 2025
Sublime Security
/feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041
Service abuse: SendThisFile with credential theft and financial language
16d ago
Oct 27th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-sendthisfile-with-credential-theft-and-financial-language-c1ebf25b
Brand impersonation: Internal Revenue Service
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-internal-revenue-service-3c63f8e9
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/html-bidirectional-bidi-html-override-with-right-to-left-obfuscation-f93940d2
Link: Apple App Store malicious ad manager themed apps from free email provider
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/link-apple-app-store-malicious-ad-manager-themed-apps-from-free-email-provider-9ce402c6
Service abuse: Google classroom solicitation
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92
Impersonation: Social Security Administration (SSA)
29d ago
Oct 14th, 2025
Sublime Security
/feeds/core/detection-rules/impersonation-social-security-administration-ssa-6196767e
Business Email Compromise: Request For Mobile Number Via Reply Thread Hijacking
1mo ago
Oct 10th, 2025
Sublime Security
/feeds/core/detection-rules/business-email-compromise-request-for-mobile-number-via-reply-thread-hijacking-0282f346
Brand impersonation: Aquent
1mo ago
Oct 9th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-aquent-5074459c