Describing attacks with crime script analysis

Published August 19, 2026

Cisco Talos shows how attackers write fake stories to trick people into sending money or data. They break down real email scams into simple steps so anyone can spot the tricks.

Report priority
Medium
Targets
Microsoft+1 more

How it works

Attackers craft fake but believable email stories to trick victims into sending money or data, using AI to automate and scale these scams.

What to do

Check if you've ever clicked a suspicious link or sent money after an urgent email asking for a quick transfer or login.

Never send money or log in after an unexpected email, even if it looks official. Verify requests in person or via a trusted phone call first.

Technical details

Affected software: Microsoft, WordPress

An attacker sends an email pretending to be your boss, asking you to transfer $50,000 to a new vendor. The email looks real, with the boss's name, a fake invoice, and a sense of urgency. You click the link to 'verify' the request, which takes you to a fake login page. If you enter your credentials, the attacker steals them and drains your account.

This is not a technical description of a specific vulnerability or exploit. Crime script analysis is a methodology for breaking down cyberattacks into human-readable narratives to identify weak points in attacker workflows, not a bug or flaw in software. It complements frameworks like MITRE ATT&CK by translating technical TTPs into actionable stories for non-technical stakeholders, helping defenders disrupt attacks at critical decision points. The technique was adapted from criminology and emphasizes situational requirements and attacker logic rather than code-level exploits.

References