How we spotted it: A Silicon Valley Bank phishing attempt
ID: 2f920b13-4ef1-540b-a7a1-d51176d016b8
STIX ID: report--2f920b13-4ef1-540b-a7a1-d51176d016b8
Feed Name: Expel Blog
Date Published: 2023-03-24
Date Updated: 2026-04-27
Author: Hiranya Mir; Jose Taleno; Christine Billie
Expel describes a phishing campaign that leverages the Silicon Valley Bank collapse to perpetrate payment counterparty fraud and harvest credentials: attackers sent spoofed emails (impersonating SVB/DocuSign), used malicious domains and a fake customer login page to capture account credentials, and aimed to redirect funds. The SOC detected the activity using a custom YARA rule, email header/SPF analysis, and IP checks, prioritized the alert for investigation, and expects more similar phishing attempts in the near term.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
