
Summary
Detects inbound emails where the subject contains the phrase 'Offer to Purchase' (case-insensitive) and the body text includes the phrases 'private equity', 'acquiring companies', and 'discuss the opportunity' (case-insensitive). This targets BEC/fraud attempts that use unsolicited business-acquisition solicitations to engage targets in fraudulent financial dealings. Detection relies on content analysis of inbound network traffic or email payloads, requiring both subject and body signals to fire. Severity is set to medium to reflect financial risk and potential impact. false positives may occur with legitimate M&A communications or if attackers vary phrasing; consider augmenting with sender/reputation checks, domain filtering, and attachment analysis to reduce noise.
Categories
- Endpoint
- Network
- Web
- Application
- Other
Data Sources
- Network Traffic
Created: 2026-06-19