Skip to content
NetarxImpact Database

Global Social Engineering Impact Database

Worldwide losses to deepfakes, impersonation and the oldest exploit in the stack: convincing a human being.

You can patch a server. You cannot patch the person who answers the phone. This is a public, source-linked record of the breaches, frauds, thefts and ransomware that began with someone being persuaded, by a stranger, a familiar voice, or a face that was never in the room.

Estimated worldwide impact of social engineeringRe-baselined Aug 29, 2026
Money lost worldwide
$2,037,053,908,671
Every country, all time, in US dollars · $14,101 per second
People impacted worldwide
6,040,060,219
Affected persons and records, all time · 17.7 per second
What is in the catalogue

277 documented entries, every one linked to its source

See the full breakdown →
216
Discrete incidents
Plus 56 multi-victim campaigns
13%
Involve AI
24 confirmed, 10 suspected
47%
Ran over a live channel
Phone, video call or help desk, not just email
26
Attempts that were stopped
Cases where a control or a suspicious human caught it
Most common entry vector
Vishing (Voice Phishing)
54
Credential Phishing Portal
36
Business Email Compromise
32
Spear Phishing (Email)
28
Help Desk Impersonation
20
Vendor / Supply Chain Impersonation
15
Voice Clone / Audio Deepfake
11
Fake IT Worker Infiltration
10
Insider Recruitment
9
Documented in these entries
Money victims actually lost
$5.37B
People or records exposed
1.8B
Primary sources cited
577

Only 54 entries carry a comparable victim-loss figure, so this is a floor rather than a cost estimate. A further 31 entries publish a number that measures something else, such as an agency total, a seizure or lost revenue, and those are never added in.

Latest additions

Most recent entries

All 277 entries →
August 24, 2026·Technology

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · United States

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

Vishing (Voice Phishing)Attempt blocked
Confirmed1 source
August 7, 2026·Retail

Levi Strauss files 8-K after social engineering compromises three employee computers

Levi Strauss & Co. · United States

Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.

Vishing (Voice Phishing)
Confirmed2 sources
August 6, 2026·Financial Services

Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks

Point72, Millennium Management, Two Sigma, Citadel and private-equity firms · United States

BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.

Vishing (Voice Phishing)Attempt blocked
$10.6M criminal proceedsConfirmed1 source
July 13, 2026·Consumer

Brinks Home breached after Microsoft Entra vishing call to an employee

Brinks Home · United States

Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.

Vishing (Voice Phishing)
Confirmed2 sources
July 6, 2026·Financial Services

Apollo Global Management breached by BlackFile callers posing as IT support

Apollo Global Management · United States

Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.

Vishing (Voice Phishing)
Confirmed2 sources
July 2026·Technology

RingCentral data on 1.6M accounts leaked after social engineering campaign

RingCentral · United States

Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.

Vishing (Voice Phishing)
1.6M affectedConfirmed2 sources
The AI-enabled subset

24 entries where AI was confirmed in the attack

Cloned voices, live deepfaked faces on video calls, synthetic identities passing job interviews. The database tracks AI involvement as its own field so you can see how the share is moving, rather than assuming it.

Contribute

Report an incident

Anyone can submit. Nothing appears on the site automatically. An editor reviews every submission against its sources before it is published, and the entry is marked as a community contribution when it goes live.

Submit an incident
Machine access

Built to be read by AI

A filterable JSON API, an llms.txt manifest, schema.org JSON-LD on every entry, bulk CSV and JSON exports, and an MCP server so Claude and other agents can query the catalogue as a tool.

Global Social Engineering Impact Database · Entries summarise public reporting and are not legal findings. How this database is built