Tactic or Technique: Impersonation: Employee

Employee impersonation is a tactic where attackers pose as someone inside your organization, like a coworker, manager, or contractor, to get you to take action. These messages often look like theyโ€™re coming from a trusted internal contact by using spoofed display names, freemail accounts, or lookalike domains.
The emails are usually short and urgent. You might see what looks like a request from your manager to send a wire transfer, from IT asking you to verify your login, or from HR sharing a document. Attackers often research your org chart, titles, or communication habits to make the message feel more believable.
If you respond, the consequences can be serious. You might send sensitive data, move money to the wrong account, or open a file that installs malware. These attacks work because they feel familiar, and the sender looks like someone you normally trust.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: HR impersonation with suspicious domain indicators and credential theft
2d ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Credential phishing: Generic document sharing
3d ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-generic-document-sharing-9f0e1d2c
Impersonation: Internal corporate services
17d ago
Nov 18th, 2025
Sublime Security
/feeds/core/detection-rules/impersonation-internal-corporate-services-3cd04f33
Suspicious request for financial information
18d ago
Nov 17th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d
VIP Impersonation via Google Group relay with suspicious indicators
23d ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
VIP impersonation with charitable donation fraud
23d ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-with-charitable-donation-fraud-35a56b8e
Headers: System account impersonation with empty sender address
2mo ago
Oct 1st, 2025
Sublime Security
/feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953
Link: SharePoint filename matches org name
2mo ago
Sep 26th, 2025
Sublime Security
/feeds/core/detection-rules/link-sharepoint-filename-matches-org-name-cb954726
Sharepoint link likely unrelated to sender
2mo ago
Sep 19th, 2025
Sublime Security
/feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489
Canva infrastructure abuse
3mo ago
Sep 5th, 2025
Sublime Security
/feeds/core/detection-rules/canva-infrastructure-abuse-b69fdb5c
Service Abuse: Box file sharing with credential phishing intent
3mo ago
Sep 4th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-box-file-sharing-with-credential-phishing-intent-5bd0cb25
Employee impersonation: Payroll fraud
4mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/employee-impersonation-payroll-fraud-2beb7d85
Benefits enrollment impersonation
4mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/benefits-enrollment-impersonation-5a6eb5a8
Xero invoice abuse
4mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/xero-invoice-abuse-6538c600
Impersonation: Human Resources with link or attachment and engaging language
4mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/impersonation-human-resources-with-link-or-attachment-and-engaging-language-8c95a6a8
Suspicious attachment with unscannable Cloudflare link
4mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-attachment-with-unscannable-cloudflare-link-00f92b6f
Attachment with VBA macros from employee impersonation (unsolicited)
4mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-with-vba-macros-from-employee-impersonation-unsolicited-9b262123
BEC: Employee impersonation with subject manipulation
4mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/bec-employee-impersonation-with-subject-manipulation-9adfc77b
Employee impersonation with urgent request (untrusted sender)
4mo ago
Jul 8th, 2025
Sublime Security
/feeds/core/detection-rules/employee-impersonation-with-urgent-request-untrusted-sender-1ce9a146