Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Fake investment outreach from suspicious TLD
38m ago
Oct 6th, 2026
Sublime Security
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Oct 4th, 2026
Sublime Security
Evasion: Suspicious use of Unicode tag characters
2d ago
Oct 4th, 2026
Sublime Security
Attachment: Suspicious use of Unicode tag characters in ICS File
2d ago
Oct 4th, 2026
Sublime Security
Body: Bid solicitation PDF lure
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: Google Authenticator
4d ago
Oct 2nd, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
4d ago
Oct 2nd, 2026
Sublime Security
Attachment: Fictitious invoice using LinkedIn's address
5d ago
Oct 1st, 2026
Sublime Security
Attachment: ICS calendar file with suspicious UID domain
7d ago
Sep 29th, 2026
Sublime Security
Link: Compromised WordPress site redirecting to suspicious root domain
7d ago
Sep 29th, 2026
Sublime Security
Link: Newly registered domain in reference lure
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Oversized guest-list calendar invite with voicemail lure
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with BEC intent
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Oversized guest-list calendar invite with purchase order lure
8d ago
Sep 28th, 2026
Sublime Security