Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
4d ago
May 29th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
4d ago
May 29th, 2026
Sublime Security
Service Abuse: HelloSign share with suspicious sender or document name
5d ago
May 28th, 2026
Sublime Security
Impersonation: Employee using fabricated identity in initial contact
5d ago
May 28th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
5d ago
May 28th, 2026
Sublime Security
Observed IOC: Malicious sender domains
6d ago
May 27th, 2026
Sublime Security
Brand Impersonation: Procore
7d ago
May 26th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
7d ago
May 26th, 2026
Sublime Security
Credential phishing: Generic document sharing
11d ago
May 22nd, 2026
Sublime Security
Brand Impersonation: Social Security Administration (SSA)
12d ago
May 21st, 2026
Sublime Security
Headers: X-Source-Auth mismatch with mismatched reply-to domain
12d ago
May 21st, 2026
Sublime Security
Impersonation: Legal firm with copyright infringement notice
12d ago
May 21st, 2026
Sublime Security
Fake thread with suspicious indicators
14d ago
May 19th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
15d ago
May 18th, 2026
Sublime Security
Scam: Fake estate sale offering welding equipment and tools
21d ago
May 12th, 2026
Sublime Security
Investor solicitation with organization targeting
25d ago
May 8th, 2026
Sublime Security
Suspicious newly registered reply-to domain with engaging financial or urgent language
27d ago
May 6th, 2026
Sublime Security
Service abuse: Payoneer callback scam
29d ago
May 4th, 2026
Sublime Security
PayPal invoice abuse
29d ago
May 4th, 2026
Sublime Security
Callback phishing via Zelle Service Abuse
29d ago
May 4th, 2026
Sublime Security