Global Social Engineering Impact Database
Worldwide losses to deepfakes, impersonation and the oldest exploit in the stack: convincing a human being.
You can patch a server. You cannot patch the person who answers the phone. This is a public, source-linked record of the breaches, frauds, thefts and ransomware that began with someone being persuaded, by a stranger, a familiar voice, or a face that was never in the room.
277 documented entries, every one linked to its source
- Money victims actually lost
- $5.37B
- People or records exposed
- 1.8B
- Primary sources cited
- 577
Only 54 entries carry a comparable victim-loss figure, so this is a floor rather than a cost estimate. A further 31 entries publish a number that measures something else, such as an agency total, a seizure or lost revenue, and those are never added in.
Most recent entries
ReliaQuest blocks ShinyHunters vishing attack with device-trust controls
ReliaQuest · United States
Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.
Levi Strauss files 8-K after social engineering compromises three employee computers
Levi Strauss & Co. · United States
Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.
Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks
Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States
BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.
Brinks Home breached after Microsoft Entra vishing call to an employee
Brinks Home · United States
Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.
Apollo Global Management breached by BlackFile callers posing as IT support
Apollo Global Management · United States
Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.
RingCentral data on 1.6M accounts leaked after social engineering campaign
RingCentral · United States
Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.
24 entries where AI was confirmed in the attack
Cloned voices, live deepfaked faces on video calls, synthetic identities passing job interviews. The database tracks AI involvement as its own field so you can see how the share is moving, rather than assuming it.
Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware
An unnamed cryptocurrency company executive · Unknown
Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service
Microsoft 365 customers in 94 countries, including US healthcare organisations · United States
North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs
US Fortune 500 technology companies employing fraudulent remote workers · United States
Report an incident
Anyone can submit. Nothing appears on the site automatically. An editor reviews every submission against its sources before it is published, and the entry is marked as a community contribution when it goes live.
Submit an incidentGlobal Social Engineering Impact Database · Entries summarise public reporting and are not legal findings. How this database is built