Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Social Security Administration
6h ago
Sep 16th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
22h ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
1d ago
Sep 15th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Sep 14th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
2d ago
Sep 14th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
2d ago
Sep 14th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
5d ago
Sep 11th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
5d ago
Sep 11th, 2026
Sublime Security
Attachment: XLS with legal confidentiality disclaimer
6d ago
Sep 10th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
6d ago
Sep 10th, 2026
Sublime Security
Attachment: PDF with dub.sh shortened link
7d ago
Sep 9th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
8d ago
Sep 8th, 2026
Sublime Security
BEC: Wealth management lure from newly registered domain
8d ago
Sep 8th, 2026
Sublime Security
Link: Display text is 'unsb'
8d ago
Sep 8th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious UID domain
12d ago
Sep 4th, 2026
Sublime Security
Attachment: Word document with hyperlink and fraud language
12d ago
Sep 4th, 2026
Sublime Security
Brand impersonation: AARP
12d ago
Sep 4th, 2026
Sublime Security