1Trusted-account compromise Compromised third-party vendor mailbox[3]Evidence dated May 12, 2026 Leading vector in Beazley’s Q1 response cases | An attacker gains control of a real supplier or service-provider mailbox, studies an existing relationship, and sends a request from the legitimate account or thread. | Invoice or bank-detail diversion that inherits the vendor’s real domain, signature, history, and business context. | Vendor payment changes; unusual reply-to or sending patterns; new inbox rules; anomalous vendor sign-ins; requests that resist callback to a known number. |
2Look-alike identity Typosquatted vendor domain and credential lure[3]Evidence dated May 12, 2026 Recurring vendor-impersonation path | A near-match domain impersonates a known vendor and delivers a malicious attachment, credential-harvest page, or altered payment instruction. | Credential theft, account takeover, or direct payment diversion without first compromising the real vendor. | Newly registered look-alike domains; character substitutions; reply-to mismatch; altered remittance details; attachment-to-login chains. |
3Reverse-proxy token theft AiTM phishing lure and session takeover[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026 Confirmed campaign technique; also observed in response cases | A PDF or link moves the victim through CAPTCHA and redirect stages to a proxy in front of the real Microsoft sign-in page. The victim completes ordinary authentication and MFA through the proxy. | The proxy captures the authenticated session token, enabling mailbox access without requiring the attacker to repeat the MFA challenge. | Compliance-themed PDFs; CAPTCHA-to-login chains; unfamiliar session properties; token replay; impossible travel; mailbox searches, rules, or messages after the sign-in. |
4Conversational trust entry Authenticated, link-free role-mailbox outreach[7]Evidence dated Jul 23, 2026 Confirmed high-scale June campaign | Python-generated messages sent through Amazon SES pass SPF and DKIM, contain no link or attachment, and target accounts-receivable, HR, payroll, and other role mailboxes. | A reply opens a trusted conversation that can progress from aging-report or customer-data collection to payroll or payment diversion. | New senders asking for aging reports, employee data, or availability; tracking pixels; unusual bulk outreach; role mailboxes replying outside an approved workflow. |
5Conversational BEC Generic availability check followed by financial request[4][7]First cited source Apr 30, 2026 · Latest cited source Jul 23, 2026 Dominant initial-contact pattern in Microsoft telemetry | A short message asks whether the recipient is available, at a desk, or able to complete a task; the attacker withholds the financial request until the recipient responds. | Gift-card purchase, wire transfer, payroll change, sensitive-document release, or a pivot into a longer impersonation exchange. | Short executive or vendor availability messages; secrecy or urgency after the first reply; abrupt moves to personal email, gift cards, payroll, or payment. |
6Process-language social engineering Routine finance-workflow credential lure[11]Evidence dated Jul 15, 2026 Dominant language class in Cofense’s Q1 2026 finance-phishing observations | The subject and message resemble ordinary remittance advice, invoice review, settlement, procurement, contract, e-signature, or vendor-follow-up work instead of using obvious pressure language. | The recipient opens a credential-harvest page, releases a document, or continues a payment conversation because the request looks like normal operational traffic. | First-seen counterparties; unexpected remittance or review links; business-process references the recipient cannot independently validate; changes to payment, settlement, or document-sharing workflows. |
7Device-fingerprinted delivery Platform-aware adaptive phishing[14]Evidence dated Jul 1, 2026 Observed Cofense Intelligence campaign pattern | A link collects browser, operating-system, language, time-zone, screen, and location information before selecting the next page or payload. | The same infrastructure can deliver credential phishing to one device and a remote-access tool to another, increasing campaign reach and complicating siloed detection. | Multi-stage redirects; user-agent or Cloudflare gating; the same lure producing different outcomes by device; shared domains or paths across email, identity, endpoint, and mobile telemetry. |
8Credential theft Commodity credential-phishing kit[3]Evidence dated May 12, 2026 Less common than vendor impersonation in Beazley’s case mix | A familiar cloud-login, document, voicemail, or security-alert lure sends the user to a credential-harvesting page operated through a reusable phishing kit. | Mailbox or SaaS account takeover that supports reconnaissance, internal impersonation, persistence, and later payment fraud. | New credential-collection domains; cloned login pages; password reuse; unfamiliar sign-ins; new MFA methods, OAuth grants, or forwarding rules. |
9Identity impersonation without account compromise Executive or display-name impersonation[1][3][5]First cited source May 12, 2026 · Latest cited source Jul 8, 2026 Observed but less common in Beazley’s response cases | The attacker uses an executive’s name, role, signature, and situational context from a free-webmail or deceptive sender address without controlling the real account. | Urgent gift-card, payroll, invoice, wire, cryptocurrency, or sensitive-data request that exploits authority rather than technical access. | Display-name/address mismatch; personal-mail senders; secrecy; urgency; bypassed approval steps; requests that move conversation off the corporate channel. |
10Delivery infrastructure Free-webmail impersonation and malicious-domain delivery[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026 72% free-webmail share in two time-bounded datasets | Attackers use disposable or aged consumer-mail accounts, or newly registered domains, to deliver impersonation and payment lures at low cost. | Direct fraud conversation, credential harvesting, or a first-stage message that identifies responsive targets. | Consumer-mail senders claiming to be executives or vendors; first-seen domains; domain age; sender/reply-to mismatch; repeated language or wallet/account reuse. |