Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
13h ago
Aug 6th, 2026
Sublime Security
BEC: Tax document request
23h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Evernote link
2d ago
Aug 5th, 2026
Sublime Security
Link: Mismatched free file host links with document lure
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
HTML: Template placeholders or recipient email in element class attributes
2d ago
Aug 5th, 2026
Sublime Security
AnonymousFox indicators
2d ago
Aug 5th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
4d ago
Aug 3rd, 2026
Sublime Security
Spam: Large financial amount mention from newly registered sender domain
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Canada Revenue Agency
6d ago
Aug 1st, 2026
Sublime Security
Service abuse: Adobe share containing newly observed email address domain
7d ago
Jul 31st, 2026
Sublime Security
Attachment: EML with Sharepoint link likely unrelated to sender
9d ago
Jul 29th, 2026
Sublime Security
Link: Hotel booking spoofed display URL
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
9d ago
Jul 29th, 2026
Sublime Security
Body: Yellow highlighted text markers
10d ago
Jul 28th, 2026
Sublime Security
Link: Compromised WordPress site redirecting to suspicious root domain
11d ago
Jul 27th, 2026
Sublime Security
Credential phishing: Personalized document signing request
11d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Internal Revenue Service
11d ago
Jul 27th, 2026
Sublime Security