Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS calendar file with suspicious UID domain
4d ago
Sep 4th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
4d ago
Sep 4th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
4d ago
Sep 4th, 2026
Sublime Security
Attachment: Word document with hyperlink and fraud language
4d ago
Sep 4th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
4d ago
Sep 4th, 2026
Sublime Security
Brand impersonation: AARP
4d ago
Sep 4th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
4d ago
Sep 4th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
5d ago
Sep 3rd, 2026
Sublime Security
Attachment: PDF RFP lure
5d ago
Sep 3rd, 2026
Sublime Security
Brand impersonation: Deloitte LLC domain in CC
6d ago
Sep 2nd, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
6d ago
Sep 2nd, 2026
Sublime Security
Attachment: Fake research internship offer
7d ago
Sep 1st, 2026
Sublime Security
Attachment: ICS calendar invite with financial lure and suspicious link
8d ago
Aug 31st, 2026
Sublime Security
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
8d ago
Aug 31st, 2026
Sublime Security
Evasion: Variation selectors in subject line
11d ago
Aug 28th, 2026
Sublime Security
Link: Recently registered .vu domain in lure
11d ago
Aug 28th, 2026
Sublime Security
Observed IOC: Malicious sender domains
11d ago
Aug 28th, 2026
Sublime Security
Credential Phishing: Bitcoin portfolio confirmation
12d ago
Aug 27th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
12d ago
Aug 27th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
12d ago
Aug 27th, 2026
Sublime Security