Attack Type: BEC/Fraud

Business Email Compromise (BEC) and fraud attacks rely on deception and social engineering. Instead of using links or attachments, attackers impersonate trusted figures like coworkers, executives, or vendors to trick you into sharing sensitive information or transferring funds. These attacks can bypass traditional security tools because the emails often seem harmless.
Expect fake invoices, urgent wire transfer requests, or a vendor asking you to update payment details. The first email is usually brief—just enough to start a conversation. The attacker might spoof a display name, reply to an old thread, or ask you to continue the conversation via personal email or phone. That is often the giveaway.
Even though these attacks may appear low-effort, the impact can be significant. They can lead to wire fraud, compliance violations, and damage to the organization's reputation. Organizations lose billions to BEC attacks each year.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Impersonation: SAM/SBA federal registration
19m ago
Aug 27th, 2026
Sublime Security
Brand impersonation: McAfee
1h ago
Aug 27th, 2026
Sublime Security
Service abuse: Kagoya.net-hosted domains sending English business lures
2h ago
Aug 27th, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
1d ago
Aug 26th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
2d ago
Aug 25th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
2d ago
Aug 25th, 2026
Sublime Security
Business Email Compromise: Request for mobile number via reply thread hijacking
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Sedgwick Claims
2d ago
Aug 25th, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
2d ago
Aug 25th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: AARP
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: United States Patent and Trademark Office
2d ago
Aug 25th, 2026
Sublime Security
Credential Phishing: Bitcoin portfolio confirmation
3d ago
Aug 24th, 2026
Sublime Security
VIP impersonation: Payment handoff with VIP display name authored fake threads
3d ago
Aug 24th, 2026
Sublime Security
Attachment: ICS calendar invite with financial lure and suspicious link
5d ago
Aug 22nd, 2026
Sublime Security
Body: AI-generated invoice template artifacts
5d ago
Aug 22nd, 2026
Sublime Security
Job scam with specific salary pattern
7d ago
Aug 20th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
7d ago
Aug 20th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
7d ago
Aug 20th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
7d ago
Aug 20th, 2026
Sublime Security