Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
4d ago
Jun 19th, 2026
Sublime Security
Observed IOC: Malicious sender domains
4d ago
Jun 19th, 2026
Sublime Security
Employee impersonation: Payroll fraud
5d ago
Jun 18th, 2026
Sublime Security
BEC/Fraud: Unsolicited business acquisition offer
5d ago
Jun 18th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
6d ago
Jun 17th, 2026
Sublime Security
Fake thread with suspicious indicators
6d ago
Jun 17th, 2026
Sublime Security
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
7d ago
Jun 16th, 2026
Sublime Security
Impersonation: Fake product discount promotion
7d ago
Jun 16th, 2026
Sublime Security
Body: Yellow highlighted text markers
7d ago
Jun 16th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
8d ago
Jun 15th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
8d ago
Jun 15th, 2026
Sublime Security
Credential phishing: Generic document sharing
8d ago
Jun 15th, 2026
Sublime Security
Observed IOC: Malicious sender root domains
11d ago
Jun 12th, 2026
Sublime Security
Scam soliciting employer review/rating
11d ago
Jun 12th, 2026
Sublime Security
Brand impersonation: Social Security Administration
12d ago
Jun 11th, 2026
Sublime Security
Brand impersonation: QuickBooks dispute notification
13d ago
Jun 10th, 2026
Sublime Security
Attachment: PDF with self-service platform links with self sender or blank recipients
13d ago
Jun 10th, 2026
Sublime Security
Attachment: PDF with fake invoice using suspicious font sizing
14d ago
Jun 9th, 2026
Sublime Security
Brand impersonation: Canada Revenue Agency
15d ago
Jun 8th, 2026
Sublime Security
Attachment: Canva PDF with susupicious author metadata
18d ago
Jun 5th, 2026
Sublime Security