logo

How we spotted it: A Silicon Valley Bank phishing attempt

ID: 2f920b13-4ef1-540b-a7a1-d51176d016b8

STIX ID: report--2f920b13-4ef1-540b-a7a1-d51176d016b8

Feed Name: Expel Blog

Threat Score
50/100

Date Published: 2023-03-24

Date Updated: 2026-04-27

Author: Hiranya Mir; Jose Taleno; Christine Billie

...
...

Expel describes a phishing campaign that leverages the Silicon Valley Bank collapse to perpetrate payment counterparty fraud and harvest credentials: attackers sent spoofed emails (impersonating SVB/DocuSign), used malicious domains and a fake customer login page to capture account credentials, and aimed to redirect funds. The SOC detected the activity using a custom YARA rule, email header/SPF analysis, and IP checks, prioritized the alert for investigation, and expects more similar phishing attempts in the near term.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.