{
  "database": "Global Social Engineering Impact Database",
  "url": "https://global-social-engineering-impact-da.vercel.app",
  "license": "CC BY 4.0 — attribute to Netarx Social Engineering Incident Database",
  "exported": "2026-08-29T05:33:12.074Z",
  "count": 277,
  "schema": "https://global-social-engineering-impact-da.vercel.app/api/schema",
  "incidents": [
    {
      "title": "ReliaQuest blocks ShinyHunters vishing attack with device-trust controls",
      "date": "2026-08-24",
      "date_precision": "day",
      "victim_org": "ReliaQuest",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "ReliaQuest did not state whether synthetic voice was used on the calls.",
      "outcomes": [
        "Attempt Blocked",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No loss; no customer data was accessed.",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.",
      "how_it_worked": "The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.",
      "lessons": "Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "ReliaQuest confirms failed data-theft attack after ShinyHunters breach",
          "url": "https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"
    },
    {
      "slug": "2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ",
      "title": "Levi Strauss files 8-K after social engineering compromises three employee computers",
      "date": "2026-08-07",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Levi Strauss & Co.",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.",
      "how_it_worked": "Levi Strauss disclosed only that the vector was social engineering against employees, without naming the technique. The linkage Reuters drew to a crew running a five-week, 200-company spree matches the voice-phishing-plus-lookalike-portal pattern dominant through 2026, in which callers impersonating IT support harvest credentials and session tokens from individual staff. Access reached three endpoints and corporate data was taken before the company contained it. Levi Strauss activated incident response and engaged third-party specialists; consumer systems were reported unaffected.",
      "lessons": "Phishing-resistant MFA plus rapid session revocation limits a three-endpoint compromise to exactly that; the 8-K filing over three laptops shows how cheaply this vector reaches material-disclosure territory.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Levi Strauss discloses data breach after social engineering attack on employees",
          "url": "https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/",
          "publisher": "CyberInsider"
        },
        {
          "title": "Levi Strauss describes contained cyber incident, LEVI 8-K filing",
          "url": "https://www.stocktitan.net/sec-filings/LEVI/8-k-levi-strauss-co-reports-material-event-0f6321560e78.html",
          "publisher": "StockTitan (SEC filing)"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ"
    },
    {
      "title": "Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks",
      "date": "2026-08-06",
      "date_precision": "day",
      "victim_org": "Point72, Millennium Management, Two Sigma, Citadel and private-equity firms",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Help Desk Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.",
      "outcomes": [
        "Attempt Blocked",
        "Extortion",
        "Credential Theft"
      ],
      "loss_usd": 10600000,
      "loss_note": "Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.",
      "records_affected": null,
      "threat_actor": "UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon",
      "summary": "BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.",
      "how_it_worked": "Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.",
      "lessons": "Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group",
          "url": "https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at",
      "year": 2026,
      "loss_kind": "criminal_proceeds",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"
    },
    {
      "slug": "2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee",
      "title": "Brinks Home breached after Microsoft Entra vishing call to an employee",
      "date": "2026-07-13",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Brinks Home",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.",
      "how_it_worked": "The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.",
      "lessons": "Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "ShinyHunters claims Brinks Home breach, threatens to leak stolen data",
          "url": "https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Salesforce Hacks 2026: Everything We Know So Far",
          "url": "https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/",
          "publisher": "Salesforce Ben"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"
    },
    {
      "title": "Apollo Global Management breached by BlackFile callers posing as IT support",
      "date": "2026-07-06",
      "date_precision": "day",
      "victim_org": "Apollo Global Management",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Researchers described a large pool of human callers recruited for small fees rather than synthetic voice.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "Apollo did not disclose a figure; researchers said BlackFile typically opens around $3 million and settles under $1 million.",
      "records_affected": null,
      "threat_actor": "BlackFile (tracked by Google as UNC6671), part of The Com, operating the Redact, Pink, Helix and Falcon extortion brands",
      "summary": "Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.",
      "how_it_worked": "BlackFile industrialised the phone call. Researchers describe hundreds of callers, often low-level people recruited for a small fee or for standing within the group, dialling employees while impersonating internal IT support until one target complies. Volume replaces finesse: the crew averages about 1.5 new victims a day and has hit private equity firms, law firms, ratings agencies and medical technology companies. Once an identity is obtained the operators move into cloud platforms and collect data for extortion, escalating with threatening messages and swatting when victims resist.",
      "lessons": "Phishing-resistant MFA plus a strict no-credentials-over-the-phone policy blunts high-volume calling, and cloud data stores need export alerting because these crews steal rather than encrypt.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Apollo discloses data breach from ongoing wave of attacks hitting financial sector",
          "url": "https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/",
          "publisher": "CyberScoop"
        },
        {
          "title": "Details emerge on BlackFile's recent attacks on financial companies",
          "url": "https://cyberscoop.com/blackfile-cyberattacks-financial-sector/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"
    },
    {
      "slug": "2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai",
      "title": "RingCentral data on 1.6M accounts leaked after social engineering campaign",
      "date": "2026-07",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "RingCentral",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 1600000,
      "threat_actor": "ShinyHunters",
      "summary": "Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.",
      "how_it_worked": "RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.",
      "lessons": "Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "RingCentral data breach exposed info of 1.6 million accounts",
          "url": "https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "1.6 Million Likely Impacted by RingCentral Data Breach",
          "url": "https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai"
    },
    {
      "slug": "2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365",
      "title": "Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts",
      "date": "2026-07",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Corporate Microsoft 365 users across a dozen countries",
      "sector": "Other",
      "country": "Global",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Actors tracked as codemado, mail-argenta and saroula01",
      "summary": "French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.",
      "how_it_worked": "Two of the three crews ran reverse-proxy phishing: the victim received a link to a page that forwarded every keystroke to the real Microsoft login and returned the genuine responses, so the sign-in looked and behaved correctly while the operator captured the password and the resulting session cookie. The mail-argenta fork pre-filled the victim's email address and rewrote URLs to evade detection. The quietest and most successful operator instead abused Microsoft's legitimate device code flow, persuading targets to enter a short code on the real Microsoft site, which authorises the attacker's device without any fake page at all and defeats MFA including passkeys.",
      "lessons": "Device code flow should be disabled by conditional access policy where it is not needed, and long-lived session cookies should be cut short and rebound to device compliance.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365",
          "url": "https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365"
    },
    {
      "slug": "2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre",
      "title": "Armored Likho spear phishing targets government and power sector in three countries",
      "date": "2026-07",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Government agencies and electric power organisations in Russia, Brazil and Kazakhstan",
      "sector": "Government",
      "country": "Russia",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Espionage",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Armored Likho (overlaps with Eagle Werewolf)",
      "summary": "Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.",
      "how_it_worked": "The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.",
      "lessons": "Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer",
          "url": "https://thehackernews.com/2026/07/armored-likho-targets-government.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre"
    },
    {
      "slug": "2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag",
      "title": "FBI identifies North Korean remote IT worker employed by a US federal agency",
      "date": "2026-07",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Unnamed US federal agency",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Insider Access",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "DPRK remote IT worker programme",
      "summary": "FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.",
      "how_it_worked": "The DPRK remote IT worker programme wins access by being hired rather than by breaking in. Operatives apply for remote technical roles using stolen or fabricated identities, often with US-based facilitators who host company laptops, sit for identity checks, or lend a domestic address and bank account so that pay and equipment appear to land with a real person in the United States. Video interviews and onboarding checks are handled by the operative or the facilitator. Once employed the worker holds legitimate credentials and normal access, which is why detection typically comes from behavioural or payroll anomalies rather than security tooling.",
      "lessons": "Live identity proofing at hire and again at equipment issue, plus checks that payroll destinations and laptop network locations match the claimed residence, are what surface these placements.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "FBI investigating North Korean remote IT staffer working for US agency",
          "url": "https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/",
          "publisher": "Federal News Network"
        },
        {
          "title": "FBI finds North Korean IT worker inside federal agency",
          "url": "https://www.thestreet.com/employment/fbi-north-korean-remote-worker-insider-threat-2026",
          "publisher": "TheStreet"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag"
    },
    {
      "slug": "2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day",
      "title": "Lazarus pairs fake recruiter approaches with a Windows zero-day",
      "date": "2026-07",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Defence and aerospace organisations in Western Europe, India and South America",
      "sector": "Defense",
      "country": "Global",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Espionage",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Lazarus Group (North Korea)",
      "summary": "Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.",
      "how_it_worked": "Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.",
      "lessons": "Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Lazarus hackers pair fake job offers with Windows zero-day exploit",
          "url": "https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/",
          "publisher": "Help Net Security"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"
    },
    {
      "slug": "2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe",
      "title": "Abbott investigates ShinyHunters claim after mid-June vishing on employees",
      "date": "2026-06",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Abbott Laboratories (legacy Exact Sciences systems)",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.",
      "how_it_worked": "Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.",
      "lessons": "Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Abbott Investigating Cyberattack Claims From Two Threat Actors",
          "url": "https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/",
          "publisher": "HIPAA Journal"
        },
        {
          "title": "Abbott investigates after ShinyHunters claims massive data theft",
          "url": "https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft",
          "publisher": "Paubox"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"
    },
    {
      "title": "Quantum Health network breached after social engineering call to a user",
      "date": "2026-05-29",
      "date_precision": "day",
      "victim_org": "Quantum Health",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "No confirmation that synthetic voice was used on the call.",
      "outcomes": [
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.",
      "how_it_worked": "The intrusion started with a phone call rather than an email or an exploit. The caller persuaded a legitimate user to hand over the credentials needed to reach the network, and the attacker then held that access for roughly four days. Because the login was valid and used in a normal way, nothing surfaced until a network disruption on June 1 prompted investigation. HIPAA Journal noted that the tradecraft aligns with tactics commonly employed by the ShinyHunters threat group, though no ransomware operation claimed the incident.",
      "lessons": "Phishing-resistant MFA prevents a disclosed password from being usable, and impossible-travel or new-device alerts would have flagged the four-day window of unfamiliar access.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Vishing Attack on Quantum Health Network Exposed Patient Data",
          "url": "https://www.hipaajournal.com/quantum-health-precision-imaging-centers-heart-america-data-breaches/",
          "publisher": "The HIPAA Journal"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-quantum-health-network-breached-after-social-engineering-call-to-a-user",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-quantum-health-network-breached-after-social-engineering-call-to-a-user"
    },
    {
      "slug": "2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials",
      "title": "MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices",
      "date": "2026-05-06",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Multiple organisations in the United States and MENA (unnamed)",
      "sector": "Manufacturing",
      "country": "United States and Middle East / North Africa",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "MuddyWater (Seedworm), assessed as linked to Iran's Ministry of Intelligence and Security, operating behind Chaos ransomware branding",
      "summary": "Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.",
      "how_it_worked": "The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.",
      "lessons": "Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware",
          "url": "https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/",
          "publisher": "Rapid7 Labs"
        },
        {
          "title": "MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack",
          "url": "https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"
    },
    {
      "slug": "2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft",
      "title": "Cushman & Wakefield confirms vishing-triggered Salesforce data theft",
      "date": "2026-05",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Cushman & Wakefield",
      "sector": "Professional Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters; Qilin also claimed the victim",
      "summary": "Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.",
      "how_it_worked": "The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.",
      "lessons": "Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim",
          "url": "https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/",
          "publisher": "Cybernews"
        },
        {
          "title": "Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped",
          "url": "https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/",
          "publisher": "Breached.Company"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"
    },
    {
      "slug": "2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman",
      "title": "700+ education and tech sites hijacked to serve ClickFix paste-the-command lures",
      "date": "2026-05",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Visitors to 700+ compromised university and technology company websites",
      "sector": "Education",
      "country": "Global",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [
        "Tech Support Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.",
      "how_it_worked": "The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.",
      "lessons": "Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "700+ education and tech websites hijacked in huge ClickFix malware campaign",
          "url": "https://www.malwarebytes.com/blog/bugs/2026/05/700-education-and-tech-websites-hijacked-in-huge-clickfix-malware-campaign",
          "publisher": "Malwarebytes"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"
    },
    {
      "slug": "2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat",
      "title": "UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls",
      "date": "2026-05",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services",
      "sector": "Other",
      "country": "Global",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": 10600000,
      "loss_kind": "criminal_proceeds",
      "loss_note": "USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.",
      "records_affected": null,
      "threat_actor": "UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)",
      "summary": "Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.",
      "how_it_worked": "Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.",
      "lessons": "Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Vishing Extortion Group UNC6671 Rebrands After Making Millions",
          "url": "https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data",
          "url": "https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"
    },
    {
      "slug": "2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca",
      "title": "City of Aurora loses $1.1M after employee falls for bank impersonation call",
      "date": "2026-04-29",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "City of Aurora, Illinois",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 1100000,
      "loss_kind": "direct_loss",
      "loss_note": "USD, approximately $1.1 million taken from municipal payroll accounts. Recovery efforts ongoing with law enforcement and the bank; the city carries insurance covering losses of this type.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.",
      "how_it_worked": "The pretext was routine banking business and the identity impersonated was the city's own financial institution, the party a finance employee expects to hear from about account matters. Officials described these schemes as exploiting trust and manufacturing urgency, and the deception worked purely by phone; nothing was hacked. The employee supplied account credentials or verification details during the call, which the fraudster immediately used to authorise transfers out of city payroll accounts. Discovery came shortly after the payments cleared.",
      "lessons": "A hard rule that no banking detail or verification code is ever given on an inbound call, only on a callback to a number held on file, plus bank-side dual authorisation on outbound transfers.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Aurora lost nearly $1.1M from city bank accounts after employee fell for phone scam, officials say",
          "url": "https://www.nbcchicago.com/news/local/aurora-lost-1-1m-from-city-bank-accounts-after-employee-fell-for-phone-scam-officials-say/3939104/",
          "publisher": "NBC Chicago"
        },
        {
          "title": "'Social Engineering Fraud' Cost Aurora, Ill., Nearly $1.1M",
          "url": "https://www.govtech.com/security/social-engineering-fraud-cost-aurora-ill-nearly-1-1m",
          "publisher": "Government Technology"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca"
    },
    {
      "title": "ADT confirms breach after vishing attack on employee's Okta SSO account",
      "date": "2026-04-20",
      "date_precision": "day",
      "victim_org": "ADT",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Mandiant documented this actor set using AI voice agents in its vishing operations; AI use in the ADT call was not separately confirmed.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "ShinyHunters set an April 27, 2026 ransom deadline; no payment or loss figure was disclosed.",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.",
      "how_it_worked": "An operator called an ADT employee posing as internal support and used a plausible authentication pretext to route them to a company-branded fake sign-in page. The page relayed the credentials and one-time code to the real Okta login in real time, giving the attacker a live SSO session. Because Salesforce sat behind that same single sign-on, the session opened the CRM directly, and the attackers exported customer and prospect records in bulk before ADT terminated the intrusion. Extortion followed, with a leak deadline set three days after public confirmation.",
      "lessons": "Phishing-resistant passkeys bound to managed devices, plus export-volume alerting on the CRM, would have blocked both the credential relay and the bulk extraction.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "ADT confirms data breach after ShinyHunters leak threat",
          "url": "https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack",
          "url": "https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack",
          "publisher": "Rescana"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account"
    },
    {
      "slug": "2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi",
      "title": "Carnival confirms social engineering of an employee account exposed 6 million customers",
      "date": "2026-04-14",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Carnival Corporation",
      "sector": "Hospitality",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 5995277,
      "threat_actor": "ShinyHunters",
      "summary": "Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.",
      "how_it_worked": "Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.",
      "lessons": "Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Carnival Cruise confirms data breach affecting nearly 6 million people",
          "url": "https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Carnival Data Breach Exposed 6 Million People",
          "url": "https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach",
          "url": "https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach",
          "publisher": "Office of the Texas Attorney General"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"
    },
    {
      "title": "Kraken refuses extortion after two support insiders accessed client data",
      "date": "2026-04-13",
      "date_precision": "day",
      "victim_org": "Kraken",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI-generated media was reported in this case.",
      "outcomes": [
        "Extortion",
        "Insider Access",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "Kraken refused to pay and reported no funds at risk; no loss figure disclosed.",
      "records_affected": 2000,
      "threat_actor": null,
      "summary": "CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.",
      "how_it_worked": "The route in was people, not software. Criminals worked through members of Kraken's own customer support team to reach client support data, mirroring the bribery-of-support-agents pattern seen at Coinbase a year earlier. The stolen material was then repackaged as leverage: the extortionists produced video framed to look like live access to Kraken's internal systems and demanded payment to suppress it. Kraken said its systems were never breached and that the access was terminated, controls tightened, affected clients notified, and law enforcement engaged, with sufficient evidence to identify those responsible.",
      "lessons": "Scoped, justification-based access in support consoles plus insider-risk monitoring limits both what an insider can reach and how long it goes unnoticed.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Crypto exchange Kraken targeted in extortion attempt, but says there was no breach and no client funds at risk",
          "url": "https://www.coindesk.com/business/2026/04/13/crypto-exchange-kraken-targeted-in-extortion-attempt-but-says-there-was-no-breach-and-no-client-funds-at-risk",
          "publisher": "CoinDesk"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data"
    },
    {
      "title": "Six-month DPRK social engineering operation preceded $285M Drift Protocol theft",
      "date": "2026-04-01",
      "date_precision": "day",
      "victim_org": "Drift Protocol",
      "sector": "Cryptocurrency",
      "country": "Unknown",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Physical Pretexting",
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 285000000,
      "loss_note": "USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.",
      "records_affected": null,
      "threat_actor": "UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence",
      "summary": "Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.",
      "how_it_worked": "This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.",
      "lessons": "Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation",
          "url": "https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks",
          "url": "https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks",
          "publisher": "TRM Labs"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol",
      "year": 2026,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"
    },
    {
      "slug": "2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi",
      "title": "Charter Communications breach of 4.9M accounts began with an Entra vishing call",
      "date": "2026-04-01",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Charter Communications (Spectrum)",
      "sector": "Telecom",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 4900000,
      "threat_actor": "ShinyHunters",
      "summary": "ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.",
      "how_it_worked": "The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.",
      "lessons": "Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Charter Communications data breach affects 4.9 million accounts",
          "url": "https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Charter confirms Spectrum data breach after ShinyHunters claims hack",
          "url": "https://www.foxnews.com/tech/charter-breach-warning-customers-know",
          "publisher": "Fox News"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi"
    },
    {
      "slug": "2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account",
      "title": "Crunchyroll support tickets stolen via compromised BPO agent SSO account",
      "date": "2026-03-12",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Crunchyroll",
      "sector": "Media & Entertainment",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.",
      "how_it_worked": "The weak point was not Crunchyroll's own workforce but a third-party contact centre agent with standing access to the streaming service's ticketing system. The attacker said malware on the agent's machine captured their credentials, then used the resulting Okta session to authenticate into Zendesk as a legitimate support operator. Because helpdesk agents routinely open and read large numbers of tickets, bulk retrieval did not stand out immediately, and roughly 24 hours passed before access was cut. Some payment card details were exposed only where customers had typed them into tickets.",
      "lessons": "Outsourced agent identities need the same phishing-resistant MFA and device-health enforcement as employees, plus per-agent ticket access rate limits so no single account can enumerate the whole queue.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Crunchyroll probes breach after hacker claims to steal 6.8M users' data",
          "url": "https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/amp/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "1.2 million Crunchyroll users confirmed impacted by data breach",
          "url": "https://cyberinsider.com/1-2-million-crunchyroll-users-confirmed-impacted-by-data-breach/",
          "publisher": "CyberInsider"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"
    },
    {
      "title": "Identity protection firm Aura breached in vishing attack; ~900,000 records taken",
      "date": "2026-03",
      "date_precision": "month",
      "victim_org": "Aura",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "No confirmation that synthetic voice was used on the call that compromised the employee account.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": 900000,
      "threat_actor": "ShinyHunters",
      "summary": "Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.",
      "how_it_worked": "The attackers targeted a single employee account with a voice phishing call, the same pattern the group used against Okta and Microsoft Entra single sign-on accounts throughout early 2026: pose as internal IT, offer help with an authentication task, and capture credentials and a one-time code through a lookalike login page. The compromised account was live for only about an hour, but that was long enough to export a marketing database wholesale. The stolen combination of name, address, phone and email is itself high-quality raw material for follow-on phishing and vishing.",
      "lessons": "Short-lived access still enables bulk export; rate-limiting and alerting on large database exports would have caught the theft inside the one-hour window.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Aura data breach",
          "url": "https://en.wikipedia.org/wiki/Aura_data_breach",
          "publisher": "Wikipedia"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records"
    },
    {
      "slug": "2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a",
      "title": "Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month",
      "date": "2026-03",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Organisations across education, healthcare, finance, nonprofit and government",
      "sector": "Other",
      "country": "Global",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "QR Code Phishing"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Tycoon2FA phishing-as-a-service operators",
      "summary": "Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.",
      "how_it_worked": "Tycoon2FA industrialised adversary-in-the-middle credential theft for buyers with no technical skill. A subscriber picked a template and sent lures; when a recipient entered their password on the fake sign-in page, the platform relayed it live to the real Microsoft or Google service and captured the returned session cookie along with whatever MFA the user completed. That defeated SMS codes, one-time passcodes and push approvals alike, because the victim genuinely authenticated, just into the attacker's session. Domains were rotated every 24 to 72 hours on cheap generic TLDs using readable subdomains such as cloud, desktop and sharepoint.",
      "lessons": "Only origin-bound credentials such as FIDO2 passkeys break the relay; conditional access requiring a compliant managed device makes a stolen cookie useless from attacker infrastructure.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/",
          "publisher": "Microsoft Security Blog"
        },
        {
          "title": "Europol, Microsoft, TrendAI and Collaborators Halt Tycoon 2FA Operations",
          "url": "https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html",
          "publisher": "Trend Micro"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a"
    },
    {
      "slug": "2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors",
      "title": "Contagious Interview: fake developer job interviews deliver backdoors",
      "date": "2026-03",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Software developers at enterprise solution, media and communications firms",
      "sector": "Technology",
      "country": "Global",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Cryptocurrency Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.",
      "how_it_worked": "The pretext is a career opportunity, and the trust signal is the ordinary shape of a developer hiring process: a recruiter approach, a screening call, then a take-home coding exercise. The malicious step is disguised as the exercise itself, because cloning a repository and running it locally is exactly what a candidate is expected to do. Payloads fire automatically from task configuration files when the repository is opened in Visual Studio Code, so no obviously suspicious action is needed. The malware then harvests API tokens, cloud credentials, cryptocurrency wallets, password manager databases, private keys, source code and clipboard contents.",
      "lessons": "Candidate exercises and any unvetted repository should be run only in a disposable sandbox with no access to corporate credentials, wallets or password vaults.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Contagious Interview: Malware delivered through fake developer job interviews",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/",
          "publisher": "Microsoft Security Blog"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"
    },
    {
      "slug": "2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo",
      "title": "Figure Technology loses ~967,000 customer records after employee falls for SSO vishing",
      "date": "2026-02-19",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Figure Technology Solutions",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 967000,
      "threat_actor": "ShinyHunters",
      "summary": "Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.",
      "how_it_worked": "The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.",
      "lessons": "Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Nearly 1 Million User Records Compromised in Figure Data Breach",
          "url": "https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters",
          "url": "https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/",
          "publisher": "Cybernews"
        },
        {
          "title": "Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People",
          "url": "https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/",
          "publisher": "CPO Magazine"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"
    },
    {
      "slug": "2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod",
      "title": "CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes",
      "date": "2026-02-13",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "CarGurus",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.",
      "how_it_worked": "Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.",
      "lessons": "One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach",
          "url": "https://news.dealershipguy.com/p/cargurus-probes-cyberattack-shinyhunters-theft-1-7-million-records-data-breach-2026-02-23",
          "publisher": "Dealership Guy News"
        },
        {
          "title": "CarGurus Reported Data Breach",
          "url": "https://complyauto.com/cargurus-reported-data-breach/",
          "publisher": "ComplyAuto"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod"
    },
    {
      "title": "Optimizely confirms data breach after vishing attack on employees",
      "date": "2026-02-11",
      "date_precision": "day",
      "victim_org": "Optimizely",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Optimizely did not state whether synthetic voice was used on the calls.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed; the company said there was no disruption to business operations.",
      "records_affected": null,
      "threat_actor": "Likely ShinyHunters-affiliated",
      "summary": "Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.",
      "how_it_worked": "Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.",
      "lessons": "Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Ad tech firm Optimizely confirms data breach after vishing attack",
          "url": "https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees"
    },
    {
      "slug": "2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts",
      "title": "Hims & Hers support tickets stolen through compromised Okta SSO accounts",
      "date": "2026-02-04",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Hims & Hers Health",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.",
      "how_it_worked": "Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.",
      "lessons": "Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Hims & Hers warns of data breach after Zendesk support ticket breach",
          "url": "https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Telehealth Giant Hims & Hers Announces Data Breach",
          "url": "https://www.hipaajournal.com/him-hers-data-breach/",
          "publisher": "HIPAA Journal"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts"
    },
    {
      "title": "Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware",
      "date": "2026-02",
      "date_precision": "month",
      "victim_org": "An unnamed cryptocurrency company executive",
      "sector": "Cryptocurrency",
      "country": "Unknown",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Tech Support Scam",
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.",
      "records_affected": null,
      "threat_actor": "UNC1069 (DPRK), tracked by Mandiant since 2018",
      "summary": "Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.",
      "how_it_worked": "Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.",
      "lessons": "No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam",
          "url": "https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix",
          "publisher": "The Record (Recorded Future News)"
        },
        {
          "title": "North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms",
          "url": "https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"
    },
    {
      "title": "BlackFile extortion gang runs vishing campaign against retail and hospitality",
      "date": "2026-02",
      "date_precision": "month",
      "victim_org": "Multiple retail and hospitality organisations (unnamed)",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Physical Pretexting"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.",
      "records_affected": null,
      "threat_actor": "BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)",
      "summary": "BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.",
      "how_it_worked": "Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.",
      "lessons": "Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "New BlackFile extortion gang targets retail and hospitality orgs",
          "url": "https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "campaign",
      "slug": "2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"
    },
    {
      "title": "STAC4749 Teams vishing campaign led to Chaos ransomware in North America",
      "date": "2026-02",
      "date_precision": "month",
      "victim_org": "Dozens of North American organisations (unnamed)",
      "sector": "Manufacturing",
      "country": "Canada",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Tech Support Scam"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.",
      "outcomes": [
        "Ransomware Deployment",
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No ransom or loss totals were disclosed.",
      "records_affected": null,
      "threat_actor": "STAC4749, deploying Chaos ransomware",
      "summary": "Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.",
      "how_it_worked": "The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.",
      "lessons": "Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Microsoft Teams vishing attacks lead to Chaos ransomware attacks",
          "url": "https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america"
    },
    {
      "slug": "2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli",
      "title": "Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers",
      "date": "2026-02",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Odido (and subsidiary Ben)",
      "sector": "Telecom",
      "country": "Netherlands",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 6200000,
      "threat_actor": null,
      "summary": "Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.",
      "how_it_worked": "Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.",
      "lessons": "Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling",
          "url": "https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling",
          "publisher": "NOS"
        },
        {
          "title": "Major hack of Dutch telco Odido was a classic case of social engineering",
          "url": "https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/",
          "publisher": "Techzine"
        },
        {
          "title": "Odido data breach exposes personal info of 6.2 million customers",
          "url": "https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"
    },
    {
      "slug": "2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo",
      "title": "Odido: IT impersonation calls and MFA approval requests expose 6.2M customers",
      "date": "2026-02",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Odido",
      "sector": "Telecom",
      "country": "Netherlands",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 6200000,
      "threat_actor": null,
      "summary": "Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.",
      "how_it_worked": "The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.",
      "lessons": "Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Odido hackers pretended to be an IT employee to breach corporate system",
          "url": "https://cybernews.com/security/odido-hackers-phishing-attack/",
          "publisher": "Cybernews"
        },
        {
          "title": "Odido Salesforce Hack: Up to 6M Customers' Data at Risk",
          "url": "https://www.salesforceben.com/odido-salesforce-hack-up-to-6m-customers-data-at-risk/",
          "publisher": "Salesforce Ben"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo"
    },
    {
      "slug": "2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec",
      "title": "Dickinson Public Schools loses $4.92M to vendor-impersonation BEC",
      "date": "2026-02",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Dickinson Public Schools",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 4920000,
      "loss_kind": "direct_loss",
      "loss_note": "USD; two payments diverted from the district's restricted building fund. No recovery reported at time of disclosure.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.",
      "how_it_worked": "The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.",
      "lessons": "Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "North Dakota School District Loses $4.9M to Email Scam",
          "url": "https://www.govtech.com/education/k-12/north-dakota-school-district-loses-4-9m-to-email-scam",
          "publisher": "Government Technology"
        },
        {
          "title": "North Dakota school district loses nearly $5 million in sophisticated email scam",
          "url": "https://www.valleynewslive.com/2026/02/11/north-dakota-school-district-loses-nearly-5-million-sophisticated-email-scam/",
          "publisher": "Valley News Live"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"
    },
    {
      "slug": "2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill",
      "title": "Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records",
      "date": "2026-01-29",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Match Group (Match, Hinge, OkCupid)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 10000000,
      "threat_actor": "ShinyHunters",
      "summary": "ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.",
      "how_it_worked": "The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.",
      "lessons": "Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match",
          "url": "https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs",
          "url": "https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/",
          "publisher": "The Register"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill"
    },
    {
      "slug": "2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient",
      "title": "Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients",
      "date": "2026-01-20",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Xsolis",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 1396519,
      "threat_actor": null,
      "summary": "Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.",
      "how_it_worked": "Xsolis described the entry point as a targeted phishing attack against its own staff rather than an exploited vulnerability. The attacker reached an employee mailbox or account and, over roughly a two-day window before detection on 22 January, accessed and copied files holding protected health information belonging to patients of Xsolis's health system and payer customers. The company has not published the pretext used, the sender identity spoofed, or whether MFA was bypassed.",
      "lessons": "Phishing-resistant MFA on email and any admin console, plus data-loss monitoring on bulk file access to PHI repositories, is what converts a successful lure into a contained account compromise.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Phishing attack on healthcare firm Xsolis impacts 1.4 million people",
          "url": "https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/",
          "publisher": "Help Net Security"
        },
        {
          "title": "Xsolis Data Breach Affects 1.4M Individuals",
          "url": "https://www.hipaajournal.com/xsolis-data-breach/",
          "publisher": "HIPAA Journal"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient"
    },
    {
      "slug": "2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages",
      "title": "Starbucks employee data stolen via cloned Partner Central login pages",
      "date": "2026-01-19",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Starbucks",
      "sector": "Hospitality",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 900,
      "threat_actor": null,
      "summary": "Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.",
      "how_it_worked": "Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.",
      "lessons": "Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Starbucks Data Breach Impacts Employees",
          "url": "https://www.securityweek.com/starbucks-data-breach-impacts-employees/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Starbucks suffers data breach via employee portal clone sites",
          "url": "https://cyberinsider.com/starbucks-suffers-data-breach-via-employee-portal-clone-sites/",
          "publisher": "CyberInsider"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"
    },
    {
      "slug": "2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering",
      "title": "$282M in Bitcoin and Litecoin stolen from a holder via social engineering",
      "date": "2026-01-10",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Unnamed cryptocurrency holder",
      "sector": "Cryptocurrency",
      "country": "Unknown",
      "primary_vector": "Tech Support Scam",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 282000000,
      "loss_kind": "direct_loss",
      "loss_note": "USD value at time of theft of 1,459 BTC and 2.05 million LTC; no recovery reported.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.",
      "how_it_worked": "Reporting characterised the theft as a support-impersonation social engineering attack of the kind that has become the dominant loss driver in crypto: the attacker poses as an employee of a wallet or exchange provider, builds trust with the holder, and persuades them to hand over a seed phrase, sign a malicious transaction or surrender login details. The theft came days after hardware-wallet maker Ledger disclosed a breach exposing customer names and contact details, the kind of list that makes such calls credible. The victim has not been identified and the exact pretext was not published.",
      "lessons": "No legitimate wallet or exchange support agent ever needs a seed phrase or a remote-access session; large holdings belong behind multi-signature approval with an out-of-band co-signer.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Hacker steals $282 million crypto from a victim in social-engineering attack",
          "url": "https://www.coindesk.com/business/2026/01/16/hacker-steals-usd282-milion-in-hardware-wallet-social-engineering-attack",
          "publisher": "CoinDesk"
        },
        {
          "title": "Crypto User Loses $282 Million in Bitcoin and Litecoin to Social Engineering Scam",
          "url": "https://bravenewcoin.com/insights/crypto-user-loses-282-million-in-bitcoin-and-litecoin-to-social-engineering-scam",
          "publisher": "Brave New Coin"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"
    },
    {
      "title": "Betterment named among victims of the January 2026 real-time vishing wave",
      "date": "2026-01-09",
      "date_precision": "day",
      "victim_org": "Betterment",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "No synthetic voice was reported for this campaign; the calls were described as live operators.",
      "outcomes": [
        "Credential Theft",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": "Actors identifying themselves as ShinyHunters",
      "summary": "Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.",
      "how_it_worked": "The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.",
      "lessons": "Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "A new wave of 'vishing' attacks is breaking into SSO accounts in real time",
          "url": "https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav"
    },
    {
      "slug": "2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov",
      "title": "FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government",
      "date": "2026-01-08",
      "date_precision": "day",
      "year": 2026,
      "victim_org": "Think tanks, academic institutions and government entities",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "QR Code Phishing",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Kimsuky (APT43)",
      "summary": "The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.",
      "how_it_worked": "Kimsuky wrote emails in the voice of a diplomat or embassy employee inviting a policy expert to an event or a document review, and placed the link inside a QR code rather than as clickable text. Scanning moved the victim off the monitored corporate desktop onto a personal phone, where enterprise mail filtering and endpoint detection do not reach, and onto a spoofed Google or document-portal sign-in. The FBI noted these operations frequently end in session token theft and replay, which defeats multi-factor authentication because the attacker never faces the login challenge.",
      "lessons": "Treat QR codes in inbound mail as untrusted links and render them for inspection at the gateway; bind sessions to device posture so a stolen token cannot be replayed from unmanaged hardware.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing",
          "url": "https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "FBI FLASH AC-000001-MW, 08 January 2026",
          "url": "https://www.ic3.gov/CSA/2026/260108.pdf",
          "publisher": "FBI / IC3"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov"
    },
    {
      "title": "SoundCloud hit as real-time vishing kits drive browsers through SSO logins",
      "date": "2026-01",
      "date_precision": "month",
      "victim_org": "SoundCloud",
      "sector": "Media & Entertainment",
      "country": "Germany",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": 36000000,
      "threat_actor": "Actors identifying themselves as ShinyHunters",
      "summary": "A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.",
      "how_it_worked": "The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.",
      "lessons": "Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "A new wave of 'vishing' attacks is breaking into SSO accounts in real time",
          "url": "https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "incident",
      "slug": "2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"
    },
    {
      "title": "Okta SSO accounts targeted in vishing campaign against financial firms",
      "date": "2026-01",
      "date_precision": "month",
      "victim_org": "Multiple fintech, wealth management and advisory firms (unnamed)",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "Ransom demands were made by email; no aggregate figure was published for this wave.",
      "records_affected": null,
      "threat_actor": "ShinyHunters (signed some extortion demands)",
      "summary": "BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.",
      "how_it_worked": "Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.",
      "lessons": "Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Okta SSO accounts targeted in vishing-based data theft attacks",
          "url": "https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "campaign",
      "slug": "2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms",
      "year": 2026,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"
    },
    {
      "slug": "2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec",
      "title": "Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked",
      "date": "2026-01",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Crunchbase",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 2000000,
      "threat_actor": "ShinyHunters",
      "summary": "Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.",
      "how_it_worked": "The attackers called Crunchbase staff and posed as internal IT support, using a pretext about an account or access issue that required the employee to sign in while the caller stayed on the line. The employee entered Okta single sign-on credentials and read back the one-time code, which the caller replayed against the live Okta login within its validity window, producing an authenticated session under a legitimate staff identity. The trust signals abused were the routine familiarity of an IT support call and the employee's own genuine Okta prompt; the pressure was urgency framed as fixing a problem already affecting the employee's access.",
      "lessons": "Phishing-resistant, origin-bound authenticators remove the readable one-time code these calls depend on, and a standing rule that IT never requests codes by phone gives staff a clean refusal script.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Crunchbase Confirms Data Breach After Hacking Claims",
          "url": "https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs",
          "url": "https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/",
          "publisher": "The Register"
        },
        {
          "title": "ShinyHunters claims 2 Million Crunchbase records; company confirms breach",
          "url": "https://securityaffairs.com/187340/data-breach/shinyhunters-claims-2-million-crunchbase-records-company-confirms-breach.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec"
    },
    {
      "slug": "2026-shinyhunters-sso-vishing-campaign-hits-100-organizations",
      "title": "ShinyHunters SSO vishing campaign hits 100+ organizations",
      "date": "2026-01",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance",
      "sector": "Other",
      "country": "Global",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Help Desk Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters / Scattered LAPSUS$ Hunters",
      "summary": "Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.",
      "how_it_worked": "Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.",
      "lessons": "Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Over 100 Organizations Targeted in ShinyHunters Phishing Campaign",
          "url": "https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "A new wave of 'vishing' attacks is breaking into SSO accounts in real time",
          "url": "https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"
    },
    {
      "slug": "2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing",
      "title": "ShinyHunters claim 14M Panera Bread records after Entra SSO vishing",
      "date": "2026-01",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Panera Bread",
      "sector": "Hospitality",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.",
      "how_it_worked": "The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.",
      "lessons": "Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.",
      "confidence": "Alleged",
      "sources": [
        {
          "title": "ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach",
          "url": "https://www.techrepublic.com/article/news-panera-bread-data-breach/",
          "publisher": "TechRepublic"
        },
        {
          "title": "Over 100 Organizations Targeted in ShinyHunters Phishing Campaign",
          "url": "https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing"
    },
    {
      "slug": "2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands",
      "title": "CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands",
      "date": "2026-01",
      "date_precision": "month",
      "year": 2026,
      "victim_org": "Users of malicious Chrome extension impersonating uBlock Origin Lite",
      "sector": "Technology",
      "country": "Global",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [
        "Tech Support Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.",
      "how_it_worked": "The lure inverted the usual ClickFix pattern. Rather than a fake CAPTCHA, the attackers manufactured a real, visible fault: the installed extension broke the victim's browser, then presented a repair prompt that looked like a security notice. Because the user had genuinely just experienced a crash, the instruction to paste a command into a terminal read as a fix rather than an attack. Operators showed selectivity, deploying extra backdoors only where the compromised host was domain-joined, indicating they were filtering for enterprise environments worth returning to.",
      "lessons": "Blocking clipboard-to-shell execution patterns and restricting extension installation to an allowlist stops the paste step, which is the only point where the user's action is required.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "New ClickFix variant 'CrashFix' deploying Python Remote Access Trojan",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/",
          "publisher": "Microsoft Security Blog"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands"
    },
    {
      "title": "Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders",
      "date": "2025-11-20",
      "date_precision": "day",
      "victim_org": "AT&T and T-Mobile customers, including four Manhattan residents",
      "sector": "Telecom",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [
        "SIM Swap"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Insider Access"
      ],
      "loss_usd": 435000,
      "loss_note": "$435,000 stolen from four Manhattan residents, with additional victims identified in other jurisdictions. The indictment covers conduct from October 2021 through July 2022.",
      "records_affected": null,
      "threat_actor": "Eleven indicted defendants, including AT&T and T-Mobile retail employees Jadakiss Bonilla, Kendrah Vasquez, Amanda Rodado and Jared Moreland",
      "summary": "Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.",
      "how_it_worked": "Ringleaders identified targets and passed their account details to retail store employees on the inside. Rather than talk a rep into a fraudulent swap, the crew paid the reps directly: the store workers used their own authorised access to customer account information to execute the SIM swaps, and in some cases signed in under a coworker's credentials so the audit trail pointed at the wrong person. Once a victim's number was ported to a device the ring controlled, incoming SMS one-time passcodes and password-reset links let them take over bank and payment accounts and move money out through wire transfers and peer-to-peer payment apps before the victim understood why their handset had lost service.",
      "lessons": "Carriers need per-employee SIM-change rate monitoring, mandatory customer confirmation on a second channel, and credential controls that make shared or borrowed logins impossible, since insider swaps look identical to legitimate ones.",
      "confidence": "Alleged",
      "sources": [
        {
          "title": "D.A. Bragg Announces Indictment Of SIM-Swapping ID Theft Ring, Including AT&T And T-Mobile Employees",
          "url": "https://manhattanda.org/d-a-bragg-announces-indictment-of-sim-swapping-id-theft-ring-including-att-and-t-mobile-employees/",
          "publisher": "Manhattan District Attorney's Office"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside",
      "year": 2025,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside"
    },
    {
      "slug": "2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack",
      "title": "Harvard alumni and donor data stolen in phone-based phishing attack",
      "date": "2025-11-18",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Harvard University",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.",
      "how_it_worked": "The attacker telephoned someone with access to the advancement systems and, over the call, obtained what was needed to log in as that person. Harvard characterised the incident explicitly as a phone-based phishing attack on its Alumni Affairs and Development environment. Advancement offices are attractive because a small number of staff hold broad read access to donor records, and because fundraising work involves frequent legitimate calls from unfamiliar people, which normalises an unexpected voice asking for help. Once authenticated as the employee, the intruder queried and exported donor and alumni records before the university revoked the access and brought in outside responders.",
      "lessons": "Phishing-resistant MFA on advancement systems and a standing rule that credentials or one-time codes are never handled over the phone would have blocked the login.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Harvard University discloses data breach affecting alumni, donors",
          "url": "https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Harvard University reports data breach following voice phishing incident",
          "url": "https://www.paubox.com/blog/harvard-university-reports-data-breach-following-voice-phishing-incident",
          "publisher": "Paubox"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack"
    },
    {
      "slug": "2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack",
      "title": "US ransomware negotiators charged with running their own BlackCat attacks",
      "date": "2025-11-03",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "US medical device company, pharmaceutical firm, drone maker and other victims",
      "sector": "Professional Services",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Ransomware Deployment",
        "Extortion",
        "Insider Access"
      ],
      "loss_usd": 1274000,
      "loss_kind": "ransom_paid",
      "loss_note": "One victim, a Florida medical device company, paid about $1.27 million in bitcoin according to the indictment.",
      "records_affected": null,
      "threat_actor": "ALPHV / BlackCat affiliates",
      "summary": "US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.",
      "how_it_worked": "This was a trusted-insider abuse rather than an external deception. The defendants worked in roles that put them inside the ransomware economy, negotiating on behalf of victims and responding to intrusions, which gave them privileged knowledge of how victims behave, what they pay and how affiliates operate. Prosecutors alleged they used that position to run attacks of their own with the ALPHV/BlackCat toolkit and extort the companies. The trust abused was institutional: organisations hand incident responders and negotiators deep access and complete candour during a crisis, and the employers' own vetting did not surface the conduct until federal investigators did.",
      "lessons": "Firms handling victim data and ransom negotiations need separation of duties, monitored access to case material and periodic re-vetting of staff with that level of insight.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "DOJ accuses US ransomware negotiators of launching their own ransomware attacks",
          "url": "https://techcrunch.com/2025/11/03/doj-accuses-us-ransomware-negotiators-of-launching-their-own-ransomware-attacks/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Ransomware responders plead guilty to using ALPHV in attacks on US organizations",
          "url": "https://therecord.media/ransomware-responders-guilty-plea-using-alphv-blackcat-us-attacks",
          "publisher": "The Record"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack"
    },
    {
      "slug": "2025-princeton-advancement-database-breached-in-targeted-phishing-attack",
      "title": "Princeton advancement database breached in targeted phishing attack",
      "date": "2025-11",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Princeton University",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.",
      "how_it_worked": "The intrusion started with a targeted phishing approach aimed at a single staff member with advancement-system access rather than a mass campaign. The message and follow-up were crafted around university fundraising work, an area where staff routinely receive unfamiliar outreach about events, gifts and alumni records, which made the approach unremarkable. The trust signal abused was the appearance of legitimate internal or alumni-related correspondence; the pressure was ordinary work urgency rather than threats. Once the employee's session or credentials were captured, the attacker authenticated as them and queried the advancement database directly, exporting constituent records before the university detected the activity and cut off access.",
      "lessons": "Hardware-backed or passkey MFA for advancement staff, plus alerting on unusual bulk queries against constituent databases, would have contained the single compromised account.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Princeton Database Breached in Targeted Phishing Incident",
          "url": "https://paw.princeton.edu/article/princeton-database-breached-targeted-phishing-incident",
          "publisher": "Princeton Alumni Weekly"
        },
        {
          "title": "Cybersecurity incident information and FAQ",
          "url": "https://oit.princeton.edu/cybersecurity-incident-information-and-faq",
          "publisher": "Princeton University OIT"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-princeton-advancement-database-breached-in-targeted-phishing-attack"
    },
    {
      "slug": "2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c",
      "title": "Five plead guilty to helping North Korean IT workers infiltrate 136 US companies",
      "date": "2025-11",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "136 US companies (victims of the fake-worker scheme)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Insider Recruitment"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Insider Access"
      ],
      "loss_usd": 2200000,
      "loss_kind": "criminal_proceeds",
      "loss_note": "About $2.2 million in revenue generated for the North Korean government through the roles obtained; one defendant agreed to forfeit more than $1.4 million.",
      "records_affected": null,
      "threat_actor": "DPRK IT worker network",
      "summary": "The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.",
      "how_it_worked": "Three of the defendants let overseas workers use their real US identities to apply for and hold remote IT jobs, so background checks returned clean results for genuine Americans. Others hosted company-issued laptops at their homes and installed remote desktop software so workers abroad appeared to be sitting at a US desk. A fourth trafficked stolen and rented identities through a website marketed at overseas jobseekers. The deception targeted HR and IT onboarding rather than any technical control: the trust signals abused were verified identity documents, a US shipping address and a US-looking network origin, all of which onboarding processes treat as proof of presence.",
      "lessons": "Tie identity verification to a live check at onboarding and re-verify periodically; monitor corporate laptops for remote-control tooling and for logins whose network geography does not match the employee's stated location.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies",
          "url": "https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Ukrainian national pleads guilty in 'laptop farm' scheme that generated income for North Korean IT workers",
          "url": "https://www.justice.gov/usao-dc/pr/ukrainian-pleads-guilty-dc-laptop-farm-scheme-generated-income-north-korean-it-workers",
          "publisher": "US Department of Justice"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c"
    },
    {
      "slug": "2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text",
      "title": "Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams",
      "date": "2025-11",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Consumers and card issuers worldwide (Google plaintiff)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Credential Theft",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "Court filings and researchers cited estimates of many millions of compromised cards; no single verified loss figure was published.",
      "records_affected": null,
      "threat_actor": "Smishing Triad / 'Lighthouse' phishing-as-a-service",
      "summary": "In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.",
      "how_it_worked": "Victims received a text claiming an unpaid road toll, a stuck parcel or a suspended account, with a short deadline and a link to a convincing replica of the relevant agency or brand. Toll authorities and postal services were chosen because almost everyone plausibly has an outstanding interaction with one, and because the sums demanded were small enough not to warrant scrutiny. The site collected card details and then, critically, the one-time passcode sent by the bank, which let the operators load the stolen card into a mobile wallet on their own phone. The kit also spoofed sender identities and rotated domains to evade filtering.",
      "lessons": "Banks should refuse to provision cards into wallets on the strength of an SMS passcode alone, and consumers should reach toll and postal accounts only through an app or a typed-in official domain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Google Sues to Disrupt Chinese SMS Phishing Triad",
          "url": "https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "Google sues to dismantle Chinese phishing platform behind US toll scams",
          "url": "https://www.bleepingcomputer.com/news/security/google-sues-to-dismantle-chinese-phishing-platform-behind-us-toll-scams/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text"
    },
    {
      "slug": "2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering",
      "title": "University of Pennsylvania donor systems breached via social engineering",
      "date": "2025-10-31",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "University of Pennsylvania",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.",
      "how_it_worked": "Penn said the intrusion began with social engineering that tricked an individual into giving up login credentials, and reporting noted that some senior staff held exemptions from the university's multi-factor authentication requirement, which removed the backstop that would normally have blunted a stolen password. The pretext targeted people working in development and alumni relations, whose accounts unlock both donor databases and mass-email tooling. After authenticating, the attacker pulled constituent records and then used the same access to blast offensive messages to alumni and donors, converting a quiet data theft into a public humiliation and extortion play.",
      "lessons": "No MFA exemptions for executives or fundraising leadership, and separate authorisation for mass-email sending, would have limited both the theft and the follow-on abuse.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "University of Pennsylvania confirms hacker stole data during cyberattack",
          "url": "https://techcrunch.com/2025/11/05/university-of-pennsylvania-confirms-hacker-stole-data-during-cyberattack/",
          "publisher": "TechCrunch"
        },
        {
          "title": "University of Pennsylvania confirms data stolen in cyberattack",
          "url": "https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering"
    },
    {
      "title": "Prince Group chairman indicted over Cambodian forced-labour pig butchering compounds",
      "date": "2025-10-14",
      "date_precision": "day",
      "victim_org": "Global cryptocurrency investment fraud victims including US consumers (multi-victim campaign)",
      "sector": "Consumer",
      "country": "Cambodia",
      "primary_vector": "Romance / Investment Scam",
      "secondary_vectors": [
        "Fake Job Offer / Recruitment Lure",
        "Smishing (SMS)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The indictment does not attribute the schemes to AI tooling, though contemporaneous reporting on the sector describes AI-assisted personas.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 15000000000,
      "loss_note": "Approximately 127,271 bitcoin, worth roughly $15 billion at the time, were seized in what DOJ called its largest forfeiture action ever. This is the seizure value, not a per-victim loss total.",
      "records_affected": null,
      "threat_actor": "Chen Zhi and the Prince Holding Group (indicted)",
      "summary": "On 14 October 2025 the Department of Justice unsealed a wire fraud and money laundering conspiracy indictment in Brooklyn against Chen Zhi, founder and chairman of Cambodia's Prince Holding Group, and announced the seizure of approximately 127,271 bitcoin worth about $15 billion. Prosecutors said Prince Group ran dozens of forced-labour scam compounds across Cambodia, ringed with high walls and barbed wire, where trafficked workers were confined and made to run cryptocurrency investment fraud against victims worldwide. One Brooklyn-based network alone handled fraudulent transfers from over 250 New York victims.",
      "how_it_worked": "Workers inside the compounds contacted strangers through messaging apps and social media using fabricated personas, opening with an apparent wrong number or a friendly cold approach. Over weeks or months they built a personal relationship, often romantic, before introducing a cryptocurrency investment opportunity backed by a fake trading platform that displayed rising balances and permitted small early withdrawals to prove legitimacy. Victims were then pressed to deposit progressively larger sums, and any attempt to withdraw triggered demands for taxes or fees. The compound operators tracked which schemes ran from which rooms and logged the profits.",
      "lessons": "Banks and exchanges need behavioural interdiction for customers making escalating transfers to newly seen crypto addresses after prolonged online-only relationships, since the victim will defend the transaction when asked directly.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Chairman of Prince Group Indicted for Operating Cambodian Forced Labor Scam Compounds",
          "url": "https://www.justice.gov/opa/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged",
          "publisher": "U.S. Department of Justice"
        },
        {
          "title": "U.S. and U.K. Take Largest Action Ever Targeting Cybercriminal Networks in Southeast Asia",
          "url": "https://home.treasury.gov/news/press-releases/sb0278",
          "publisher": "U.S. Department of the Treasury"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri",
      "year": 2025,
      "loss_kind": "seizure",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-prince-group-chairman-indicted-over-cambodian-forced-labour-pig-butcheri"
    },
    {
      "slug": "2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments",
      "title": "US and UK charge Scattered Spider pair tied to $115M in ransom payments",
      "date": "2025-09-18",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "47 US organisations including healthcare, transport and technology firms",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Smishing (SMS)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Extortion",
        "Ransomware Deployment",
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": 115000000,
      "loss_kind": "aggregate",
      "loss_note": "US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.",
      "records_affected": null,
      "threat_actor": "Scattered Spider / UNC3944",
      "summary": "On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.",
      "how_it_worked": "The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.",
      "lessons": "Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Feds Tie 'Scattered Spider' Duo to $115M in Ransoms",
          "url": "https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "US government charges British teenager accused of at least 120 Scattered Spider hacks",
          "url": "https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/",
          "publisher": "TechCrunch"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"
    },
    {
      "slug": "2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se",
      "title": "Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service",
      "date": "2025-09-16",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Microsoft 365 customers in 94 countries, including US healthcare organisations",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.",
      "outcomes": [
        "Credential Theft",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 5000,
      "threat_actor": "Storm-2246 / RaccoonO365 (Nigeria-based operator named by Microsoft)",
      "summary": "Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.",
      "how_it_worked": "Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.",
      "lessons": "Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service",
          "url": "https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/",
          "publisher": "Microsoft On the Issues"
        },
        {
          "title": "Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service",
          "url": "https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"
    },
    {
      "title": "US sanctions Myanmar and Cambodia scam compound operators over forced-labour fraud",
      "date": "2025-09-08",
      "date_precision": "day",
      "victim_org": "US, European and Chinese scam victims (multi-victim campaign)",
      "sector": "Consumer",
      "country": "Myanmar and Cambodia",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Romance / Investment Scam",
        "Insider Recruitment"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The sanctions announcement does not characterise AI use in the compounds' scam operations.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft"
      ],
      "loss_usd": 10000000000,
      "loss_note": "Over $10 billion in losses to Americans was cited in connection with the announcement; this is a sector-wide aggregate, not a single-incident figure.",
      "records_affected": null,
      "threat_actor": "Shwe Kokko / Yatai International Holdings Group network and Cambodian casino operators",
      "summary": "On 8 September 2025 the US Treasury and State Department sanctioned operators of Southeast Asian scam compounds. Nine people and companies were targeted around the Shwe Kokko hub in Myanmar, including Saw Chit Thu and his Chit Linn Myaing entities, She Zhijiang and Yatai International Holdings Group. Four individuals and six entities tied to Cambodian casino operations in Sihanoukville and Bavet were also designated. In October 2025 Myanmar authorities detained over 2,000 suspects at KK Park, and in November 2025 arrested 346 foreign nationals at Shwe Kokko, seizing nearly 10,000 mobile phones.",
      "how_it_worked": "The compounds are staffed by recruitment fraud. Thousands of people are lured with fake job offers, typically advertised as customer service, translation or IT work at attractive salaries in Thailand or Cambodia, then transported across borders, held against their will and forced to run scams targeting people in the United States, Europe and China. Inside, workers follow scripted romance and investment playbooks against assigned target lists, with quotas enforced by violence. The compound model industrialises social engineering: the recruitment lure supplies the labour, and the labour supplies the volume of romance and investment approaches.",
      "lessons": "Because the front-line operators are themselves trafficking victims, effective controls sit upstream in sanctions, telecom and payment infrastructure rather than in prosecuting individual callers.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "US sanctions companies behind cyber scam centers in Cambodia, Myanmar",
          "url": "https://therecord.media/us-sanctions-companies-southeast-asia-scam-compounds",
          "publisher": "The Record (Recorded Future News)"
        },
        {
          "title": "Myanmar Military Arrests Hundreds in Raid on Thai-Border Scam Center",
          "url": "https://www.occrp.org/en/news/myanmar-military-arrests-hundreds-in-raid-on-thai-border-scam-center",
          "publisher": "OCCRP"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la",
      "year": 2025,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sanctions-myanmar-and-cambodia-scam-compound-operators-over-forced-la"
    },
    {
      "slug": "2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform",
      "title": "Stellantis confirms customer data stolen from Salesforce platform",
      "date": "2025-09",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Stellantis",
      "sector": "Manufacturing",
      "country": "Netherlands",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters / Scattered Lapsus$ Hunters (claimed)",
      "summary": "Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.",
      "how_it_worked": "The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.",
      "lessons": "Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Automaker giant Stellantis confirms data breach after Salesforce hack",
          "url": "https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Stellantis confirms data breach involving customers' contact information",
          "url": "https://www.engadget.com/big-tech/stellantis-confirms-data-breach-involving-customers-contact-information-194136744.html",
          "publisher": "Engadget"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform"
    },
    {
      "slug": "2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the",
      "title": "Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft",
      "date": "2025-09",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Kering (Gucci, Balenciaga, Alexander McQueen)",
      "sector": "Retail",
      "country": "France",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters",
      "summary": "Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.",
      "how_it_worked": "ShinyHunters told reporters the access came from the same telephone-based playbook it ran against dozens of consumer brands in 2025: a caller posing as internal IT or a SaaS vendor contacted staff with CRM access, cited a plausible support ticket, and guided them through granting a connected application permission in the customer-relationship platform. The identity impersonated was the victim's own IT function; the trust signal abused was a vendor-branded consent page that looked routine. No malware was deployed. Once approved by a human, the app was used to enumerate and export customer profiles, which were then used for private extortion demands.",
      "lessons": "Retail and luxury CRM tenants should treat third-party app consent as a privileged administrative action requiring a second approver and out-of-band caller verification.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Company that owns Gucci, Balenciaga, other brands confirms hack",
          "url": "https://techcrunch.com/2025/09/15/company-that-owns-gucci-balenciaga-other-brands-confirms-hack",
          "publisher": "TechCrunch"
        },
        {
          "title": "Gucci, Balenciaga, McQueen confirm breach, ShinyHunters claim 7.4M customers' data stolen",
          "url": "https://cybernews.com/news/gucci-balenciaga-kering-data-breach-7-million-customers-compromised-shiny-hunters/",
          "publisher": "Cybernews"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the"
    },
    {
      "title": "Workday discloses CRM breach after social engineering of employees",
      "date": "2025-08-06",
      "date_precision": "day",
      "victim_org": "Workday",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": "Not named by Workday; consistent with the ShinyHunters/UNC6040 Salesforce campaign",
      "summary": "Workday disclosed on August 18, 2025 that threat actors had accessed information held in its third-party customer relationship management platform following a social engineering attack. The exposed data was basic business contact information: names, email addresses and phone numbers. Workday said there was no indication of access to customer tenants or the data within them. The incident sat inside the broader 2025 wave of CRM-focused social engineering that also hit Allianz Life, Qantas and Hawaiian Airlines.",
      "how_it_worked": "Attackers in this campaign contacted employees by phone and text while posing as HR or IT personnel, and, in the pattern documented across this campaign though not confirmed by Workday, using a support pretext to obtain credentials and a multi-factor code or an approval for a malicious connected application. Because the approval came from a legitimate, authenticated employee session, nothing looked anomalous at the identity layer. The attackers then pulled contact records out of the CRM and, in related cases, contacted the victim organisation with extortion demands.",
      "lessons": "Third-party SaaS used by go-to-market teams needs the same phishing-resistant SSO and export monitoring as production, and staff need a standing rule that HR and IT never request credentials by phone or text.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Workday hit by social engineering data breach targeting its CRM platform",
          "url": "https://therecord.media/workday-social-engineering-data-breach",
          "publisher": "The Record (Recorded Future News)"
        },
        {
          "title": "Human resources firm Workday disclosed a data breach",
          "url": "https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-workday-discloses-crm-breach-after-social-engineering-of-employees",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-workday-discloses-crm-breach-after-social-engineering-of-employees"
    },
    {
      "title": "North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs",
      "date": "2025-08",
      "date_precision": "month",
      "victim_org": "US Fortune 500 technology companies employing fraudulent remote workers",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.",
      "outcomes": [
        "Insider Access",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "Salaries paid to fraudulent workers fund DPRK weapons programmes; amounts not quantified in this report",
      "records_affected": null,
      "threat_actor": "DPRK remote IT worker operations",
      "summary": "In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.",
      "how_it_worked": "The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.",
      "lessons": "Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Detecting and countering misuse of AI: August 2025",
          "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025",
          "publisher": "Anthropic"
        },
        {
          "title": "Anthropic threat intelligence report, August 2025 (PDF)",
          "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf",
          "publisher": "Anthropic"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"
    },
    {
      "title": "Claude Code used to automate extortion of at least 17 organisations",
      "date": "2025-08",
      "date_precision": "month",
      "victim_org": "At least 17 organisations across healthcare, emergency services, government and religious institutions",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Anthropic reported a single actor used Claude Code to automate reconnaissance and credential harvesting, decide what data to steal, analyse victims' finances to set ransom amounts, and generate psychologically targeted extortion notes and on-screen ransom displays.",
      "outcomes": [
        "Extortion",
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "Ransom demands sometimes exceeded US$500,000; amounts actually paid were not disclosed",
      "records_affected": null,
      "threat_actor": "Tracked by Anthropic as a single cybercriminal actor (reported as GTG-2002)",
      "summary": "Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.",
      "how_it_worked": "The coercive element was the extortion communication itself, which the model tailored to each organisation using the stolen data. Ransom notes referenced what had been taken and what its exposure would mean for that specific victim, whether patient confidentiality, emergency service continuity or congregational trust, so the threat was concrete rather than generic. Financial records were analysed to set a demand the victim could plausibly pay, which increases compliance relative to arbitrary figures. Alarming messages displayed on victims' own machines added immediacy, and the exfiltration-only model meant victims could not restore from backup to escape the leak threat.",
      "lessons": "Preventing exfiltration through egress monitoring and least-privilege data access matters more than backup strategy against leak-only extortion, and incident response plans should assume ransom demands will be precisely tuned to the organisation's finances.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Detecting and countering misuse of AI: August 2025",
          "url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025",
          "publisher": "Anthropic"
        },
        {
          "title": "Anthropic threat intelligence report, August 2025 (PDF)",
          "url": "https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf",
          "publisher": "Anthropic"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations"
    },
    {
      "slug": "2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf",
      "title": "Air France and KLM disclose breach of third-party customer service platform",
      "date": "2025-08",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Air France-KLM",
      "sector": "Transportation & Logistics",
      "country": "France",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters / UNC6040 (reported)",
      "summary": "Air France and KLM disclosed in August 2025 that attackers had accessed a third-party platform used for customer service, exposing names, contact details, Flying Blue loyalty numbers and the subject lines of customer emails. The airlines said no passwords, passport details or payment data were involved. Reporting linked the incident to the ShinyHunters-led Salesforce data-theft campaign.",
      "how_it_worked": "Attribution rests on security reporting rather than an airline statement naming the vector. In the wider campaign, operators cold-called contact-centre and support employees claiming to be the airline's IT department or the CRM vendor, established rapport using employee names and internal terminology, then asked the target to open the Salesforce connected-app page and enter a code supplied on the call. That single human action authorised an attacker-controlled application with data-export rights. The pretexts were mundane, such as fixing a slow application or completing a mandatory update, and the pressure came from the caller's implied authority rather than threats.",
      "lessons": "Contact centres are the softest CRM access point; caller-verification scripts plus admin-only OAuth consent are the controls that break this pattern.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Air France and KLM disclose data breaches impacting customers",
          "url": "https://www.bleepingcomputer.com/news/security/air-france-and-klm-disclose-data-breaches-impacting-customers/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Air France, KLM Say Hackers Accessed Customer Data",
          "url": "https://www.securityweek.com/air-france-klm-say-hackers-accessed-customer-data/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-air-france-and-klm-disclose-breach-of-third-party-customer-service-platf"
    },
    {
      "slug": "2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach",
      "title": "Chanel notifies US clients after third-party client-care database breach",
      "date": "2025-08",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Chanel",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters (reported)",
      "summary": "Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.",
      "how_it_worked": "Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.",
      "lessons": "Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Chanel Alerts Client of Third-Party Breach",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/chanel-alerts-third-party-breach",
          "publisher": "Dark Reading"
        },
        {
          "title": "Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora",
          "url": "https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/",
          "publisher": "CPO Magazine"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-chanel-notifies-us-clients-after-third-party-client-care-database-breach"
    },
    {
      "slug": "2025-pandora-warns-customers-after-third-party-platform-breach",
      "title": "Pandora warns customers after third-party platform breach",
      "date": "2025-08",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Pandora A/S",
      "sector": "Retail",
      "country": "Denmark",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters (reported)",
      "summary": "Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.",
      "how_it_worked": "Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.",
      "lessons": "Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Pandora and Chanel Customer Data Leaked in Third-Party Breaches",
          "url": "https://www.pymnts.com/cybersecurity/2025/pandora-and-chanel-customer-data-leaked-in-breach/",
          "publisher": "PYMNTS"
        },
        {
          "title": "Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora",
          "url": "https://www.cpomagazine.com/cyber-security/third-party-data-breach-hits-luxury-fashion-retailers-chanel-and-pandora/",
          "publisher": "CPO Magazine"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-pandora-warns-customers-after-third-party-platform-breach"
    },
    {
      "slug": "2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing",
      "title": "Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts",
      "date": "2025-08",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Cryptocurrency holders and companies targeted by the group",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Credential Phishing Portal",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Cryptocurrency Theft",
        "Credential Theft",
        "Identity Theft"
      ],
      "loss_usd": 13000000,
      "loss_kind": "direct_loss",
      "loss_note": "About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.",
      "records_affected": null,
      "threat_actor": "Scattered Spider",
      "summary": "A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.",
      "how_it_worked": "The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.",
      "lessons": "Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "SIM-Swapper, Scattered Spider Hacker Gets 10 Years",
          "url": "https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution",
          "url": "https://therecord.media/scattered-spider-affiliate-sentenced-10-years",
          "publisher": "The Record"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"
    },
    {
      "slug": "2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance",
      "title": "Interpol Operation Serengeti 2.0 nets 1,209 arrests over BEC and romance fraud",
      "date": "2025-08",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Approximately 88,000 victims across 18 African countries and the UK",
      "sector": "Other",
      "country": "Multiple",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Romance / Investment Scam",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft"
      ],
      "loss_usd": 485000000,
      "loss_kind": "aggregate",
      "loss_note": "Interpol put victim losses across the operation at about $485 million, with roughly $97.4 million recovered.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.",
      "how_it_worked": "The networks disrupted ran industrialised deception. Business email compromise crews compromised or spoofed corporate mailboxes, watched invoice threads, then sent payment-diversion instructions from an address one character off the real one, timed to arrive when a genuine payment was due. Romance and investment crews cultivated victims over weeks on dating and messaging apps before introducing fake trading platforms that displayed fabricated gains to encourage larger deposits. In both cases the trust signal abused was an established relationship, commercial or personal, and the pressure was a closing window: a supplier deadline, or a limited investment opportunity.",
      "lessons": "Verified callback to a previously known phone number before any change of bank details, and platform-level friction on first-time large transfers to new payees, cut the largest share of these losses.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "African authorities dismantle massive cybercrime and fraud networks, recover millions",
          "url": "https://www.interpol.int/en/News-and-Events/News/2025/African-authorities-dismantle-massive-cybercrime-and-fraud-networks-recover-millions",
          "publisher": "Interpol"
        },
        {
          "title": "Massive anti-cybercrime operation leads to over 1,200 arrests in Africa",
          "url": "https://www.bleepingcomputer.com/news/security/massive-anti-cybercrime-operation-leads-to-over-1-200-arrests-in-africa/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-interpol-operation-serengeti-2-0-nets-1-209-arrests-over-bec-and-romance"
    },
    {
      "slug": "2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ",
      "title": "TransUnion Salesforce-linked breach exposes 4.4 million Americans including full SSNs",
      "date": "2025-07-28",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "TransUnion",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Identity Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 4400000,
      "threat_actor": "ShinyHunters",
      "summary": "Credit bureau TransUnion disclosed a cyber incident involving a third-party application serving its US consumer support operations, which occurred on 28 July 2025 and was discovered two days later. BleepingComputer confirmed the data was taken from TransUnion's Salesforce tenant and placed the incident in the 2025 wave of Salesforce data theft attacks. More than 4.4 million people in the United States were affected, with names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Security numbers, support tickets and stored messages exposed; threat actors claimed 13 million records. TransUnion said no credit reports or core credit data were involved and offered 24 months of monitoring. ShinyHunters claimed the theft and shared samples with reporters.",
      "how_it_worked": "TransUnion has described the entry point only as a third-party application serving its consumer support operations and has not publicly confirmed a social engineering pretext. Reporting places the theft in the Salesforce campaign attributed to UNC6040 and ShinyHunters, in which callers impersonating internal IT support telephone employees, cite a routine integration or troubleshooting need, and talk the target through authorising an attacker-controlled connected application inside the genuine Salesforce authorisation screen. The abused trust signal is Salesforce's own real interface combined with a plausible internal support identity; the extraction that follows is automated and needs no further human involvement.",
      "lessons": "Restricting connected-app authorisation to a small set of administrators and alerting on any newly bound application or unusual bulk export from the CRM would have contained this class of intrusion at the moment of consent.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "TransUnion suffers data breach impacting over 4.4 million people",
          "url": "https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "TransUnion becomes latest victim in major wave of Salesforce-linked cyberattacks, 4.4M Americans affected",
          "url": "https://www.foxnews.com/tech/transunion-becomes-latest-victim-major-wave-salesforce-linked-cyberattacks-4-4m-americans-affected",
          "publisher": "Fox News"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-transunion-salesforce-linked-breach-exposes-4-4-million-americans-includ"
    },
    {
      "slug": "2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm",
      "title": "Cisco confirms vishing call gave attacker access to its third-party CRM instance",
      "date": "2025-07-24",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Cisco Systems",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters / UNC6040 (Salesforce vishing wave)",
      "summary": "Cisco disclosed in its own security advisory that on 24 July 2025 it discovered a voice-phishing attack against a Cisco representative had given an unauthorized actor access to a third-party cloud-based CRM instance. Basic Cisco.com account profile information was exported, including names, organisation names, addresses, Cisco-assigned user IDs, email addresses, phone numbers and account metadata. Cisco stated no confidential or proprietary customer information and no passwords were obtained, terminated the actor's access, notified data protection authorities, and re-educated staff on identifying vishing. In an update dated 3 October 2025 Cisco assessed later claims by the suspected actor and found no evidence of additional compromise.",
      "how_it_worked": "The attacker telephoned a Cisco representative and, using an internal-sounding pretext, persuaded them to authorise access to the company's instance of a third-party cloud CRM platform. This is the pattern Google's threat intelligence team documented as UNC6040: callers impersonate IT support and talk the target through granting a connected application or completing a sign-in that hands the caller an authenticated CRM session. The trust signals abused were a plausible internal support identity and the ordinariness of the request, and the abuse was quick and quiet enough that the export was complete before the account activity was identified.",
      "lessons": "Restricting who can authorise connected applications in the CRM, and requiring a call-back through a verified internal directory number before any access-granting action, closes the path a single persuaded employee opens.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Vishing Attack Impacting Third-Party CRM System",
          "url": "https://sec.cloudapps.cisco.com/security/center/resources/CRM-vishing",
          "publisher": "Cisco (company advisory)"
        },
        {
          "title": "Cisco discloses data breach impacting Cisco.com user accounts",
          "url": "https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-cisco-confirms-vishing-call-gave-attacker-access-to-its-third-party-crm"
    },
    {
      "slug": "2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished",
      "title": "Crypto exchange WOO X loses $14 million after staff member phished",
      "date": "2025-07-24",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "WOO X",
      "sector": "Cryptocurrency",
      "country": "Taiwan",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Cryptocurrency Theft",
        "Service Disruption"
      ],
      "loss_usd": 14000000,
      "loss_kind": "direct_loss",
      "loss_note": "Approximately $14 million in customer assets drained; WOO X said it would cover affected user balances from its own reserves.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.",
      "how_it_worked": "A single employee was targeted with a phishing lure that led to compromise of their machine and working credentials. From that foothold the attacker reached WOO X's development environment, which retained the ability to influence production withdrawal handling, and submitted malicious withdrawal requests that the platform processed as legitimate. The trust signal abused was the internal provenance of the requests: they came from an authenticated staff context inside the company's own tooling, so they did not look like an external attack. No exchange smart contract was exploited; the entire chain rested on one person being deceived into an action on their own device.",
      "lessons": "Separating development environments from anything that can move production funds, and requiring multi-party approval for withdrawals above a threshold, would have contained the compromised endpoint.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "July 24th - Security incident post-mortem",
          "url": "https://woox.io/blog/july-24th-security-incident-post-mortem",
          "publisher": "WOO X"
        },
        {
          "title": "Crypto Exchange WOO X Loses $14M After Team Member Falls for Phishing Attack",
          "url": "https://cryptonews.com/news/crypto-exchange-woo-x-loses-14m-after-team-member-falls-for-phishing-attack/",
          "publisher": "Cryptonews"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-crypto-exchange-woo-x-loses-14-million-after-staff-member-phished"
    },
    {
      "slug": "2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f",
      "title": "Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm",
      "date": "2025-07-24",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "More than 300 US companies (victims of the fake-worker scheme)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Insider Recruitment"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Insider Access"
      ],
      "loss_usd": 17000000,
      "loss_kind": "criminal_proceeds",
      "loss_note": "Approximately $17 million in wages and revenue generated for North Korea through the scheme; the defendant was ordered to forfeit roughly $284,000 and pay about $177,000 in restitution.",
      "records_affected": null,
      "threat_actor": "DPRK IT worker network",
      "summary": "A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.",
      "how_it_worked": "Overseas operatives applied for remote IT roles using stolen or borrowed US identities and forged documents, passing HR checks and video screening because the identity paperwork was genuine and the impersonation was rehearsed. Companies shipped corporate laptops to what they believed was the employee's US home address; in fact the machines were racked at the facilitator's house, where remote access software let workers in Asia operate them from apparently American IP addresses. The trust signals abused were a valid Social Security number, a plausible US address and a working corporate device. Payroll then flowed to US accounts before being laundered abroad.",
      "lessons": "Verify remote hires with live identity proofing tied to the device shipping address, and alert on remote-management software or geographic mismatch on corporate endpoints.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Arizona woman sentenced in $17M IT worker fraud scheme that illegally generated revenue for North Korea",
          "url": "https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north",
          "publisher": "US Department of Justice"
        },
        {
          "title": "Arizona woman sentenced to 8.5 years for running North Korean laptop farm",
          "url": "https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm",
          "publisher": "The Record"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f"
    },
    {
      "title": "Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access",
      "date": "2025-07-22",
      "date_precision": "day",
      "victim_org": "Multiple businesses and critical infrastructure organisations (campaign)",
      "sector": "Healthcare",
      "country": "Multiple",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [
        "Tech Support Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported in the advisory.",
      "outcomes": [
        "Ransomware Deployment",
        "Extortion",
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure published; the advisory notes Interlock does not state an initial ransom amount in its notes.",
      "records_affected": null,
      "threat_actor": "Interlock ransomware group",
      "summary": "A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.",
      "how_it_worked": "Visitors to compromised but otherwise legitimate websites were served a page claiming they needed to prove they were human or fix a display problem. The page silently copied a command to the clipboard and instructed the user to open the Windows Run dialog, paste and press Enter, which executed PowerShell that fetched a remote access trojan. Because the victim types the command themselves, no download prompt or macro warning appears and email gateways are entirely bypassed. Interlock operators then used the foothold for credential theft with infostealers and keyloggers, lateral movement over RDP, data exfiltration to cloud storage, and double-extortion encryption of Windows and Linux systems.",
      "lessons": "Instrument and alert on PowerShell or mshta launched from explorer.exe via the Run dialog, and block clipboard-to-shell execution paths through application control; no legitimate CAPTCHA ever asks a user to run a command.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "#StopRansomware: Interlock (AA25-203A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a",
          "publisher": "CISA / FBI / HHS / MS-ISAC"
        },
        {
          "title": "#StopRansomware: Interlock (PDF)",
          "url": "https://www.ic3.gov/CSA/2025/250722.pdf",
          "publisher": "FBI Internet Crime Complaint Center"
        },
        {
          "title": "Feds Issue Interlock Ransomware Warning as Healthcare Attacks Spike",
          "url": "https://www.hipaajournal.com/interlock-ransomware-alert-2025/",
          "publisher": "HIPAA Journal"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce"
    },
    {
      "title": "Allianz Life's Salesforce CRM emptied after social engineering",
      "date": "2025-07-16",
      "date_precision": "day",
      "victim_org": "Allianz Life Insurance Company of North America",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": 1100000,
      "threat_actor": "ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas",
      "summary": "Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.",
      "how_it_worked": "Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.",
      "lessons": "Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Allianz Life security breach impacted 1.1 million customers",
          "url": "https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Allianz Life data breach exposed the data of most of its 1.4M customers",
          "url": "https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Social engineering attack obtains data on 'majority' of Allianz Life customers",
          "url": "https://therecord.media/allianz-life-social-engineering-data-breach",
          "publisher": "The Record (Recorded Future News)"
        },
        {
          "title": "Google Among Victims in Ongoing Salesforce Data Theft Campaign",
          "url": "https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"
    },
    {
      "title": "Qantas contact centre platform breached after help desk tricked into adding MFA",
      "date": "2025-07-01",
      "date_precision": "day",
      "victim_org": "Qantas Airways",
      "sector": "Transportation & Logistics",
      "country": "Australia",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.",
      "records_affected": 5700000,
      "threat_actor": "Scattered Spider / Muddled Libra (reported)",
      "summary": "Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.",
      "how_it_worked": "The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.",
      "lessons": "Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Qantas data breach impacted 5.7 million individuals",
          "url": "https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Qantas confirms customer data breach amid Scattered Spider attacks",
          "url": "https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Update on Qantas cyber incident: Wednesday 9 July 2025",
          "url": "https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025",
          "publisher": "Qantas Newsroom"
        },
        {
          "title": "Tech support scam caused massive data breach at Australian airline Qantas",
          "url": "https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267",
          "publisher": "The Register"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"
    },
    {
      "slug": "2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre",
      "title": "Fabricated telecom invoices deceive BlackRock's HPS unit into a $400M+ credit facility",
      "date": "2025-07",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "HPS Investment Partners (BlackRock)",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Business Email Compromise"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 400000000,
      "loss_kind": "direct_loss",
      "loss_note": "USD. HPS extended more than $400 million against the disputed receivables, part of roughly $430 million of loans, with BNP Paribas providing leverage on about half. HPS is pursuing recovery through Delaware court action and related bankruptcy proceedings, so the final unrecovered amount has not been published.",
      "records_affected": null,
      "threat_actor": "Bankim Brahmbhatt and affiliated telecom entities (alleged)",
      "summary": "HPS Investment Partners, the private credit unit BlackRock acquired in July 2025, discovered that receivables pledged as collateral by telecom entrepreneur Bankim Brahmbhatt's companies were fabricated. HPS had lent against purported invoices from major telecom carriers since 2020 and described the scheme in Delaware court filings as an extraordinarily brazen and widespread fraud. The U.S. Attorney's Office for the Eastern District of New York opened an investigation, reported publicly in November 2025.",
      "how_it_worked": "The borrower supplied invoices purporting to come from large international telecom carriers as collateral for a revolving credit facility, backed by supporting correspondence from email domains crafted to look like those carriers. Credit analysts and underwriters accepted the documents as third-party confirmation of real receivables, and the pattern held for roughly five years because each new drawdown was validated against the same fabricated paper trail. The deception unravelled only when an HPS analyst compared the email domains on the invoices against the real carriers' domains and found mismatches, then found the same discrepancy repeatedly across the portfolio.",
      "lessons": "Out-of-band verification of receivables directly with the named obligor, using contact details sourced independently rather than from the borrower's own documents, would have exposed the fabricated counterparties years earlier.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "US Probes Telecom Firms After BlackRock's HPS Uncovers Alleged $400M Fraud",
          "url": "https://www.usnews.com/news/top-news/articles/2025-11-17/us-probes-telecom-firms-after-blackrocks-hps-uncovers-alleged-400m-fraud-financial-times-reports",
          "publisher": "U.S. News / Reuters"
        },
        {
          "title": "How Fake Invoices Duped BlackRock Unit Into a $400 Million Loan (WSJ)",
          "url": "https://www.securitiesdocket.com/2026/02/11/how-fake-invoices-duped-blackrock-unit-into-a-400-million-loan-wsj/",
          "publisher": "Securities Docket / The Wall Street Journal"
        },
        {
          "title": "BlackRock Unit Flags Suspected $400 Million Fraud, Triggering U.S. Probe of Telecom Firms",
          "url": "https://finance.yahoo.com/news/blackrock-unit-flags-suspected-400-150656293.html",
          "publisher": "Yahoo Finance / Bloomberg"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-fabricated-telecom-invoices-deceive-blackrock-s-hps-unit-into-a-400m-cre"
    },
    {
      "slug": "2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft",
      "title": "LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave",
      "date": "2025-07",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)",
      "sector": "Retail",
      "country": "France",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters / UNC6040",
      "summary": "Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.",
      "how_it_worked": "The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.",
      "lessons": "Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH",
          "url": "https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches",
          "url": "https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"
    },
    {
      "slug": "2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d",
      "title": "Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware",
      "date": "2025-07",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "US retail, airline, transportation and insurance organisations",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Ransomware Deployment",
        "Data Breach",
        "Service Disruption",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "UNC3944 / Scattered Spider",
      "summary": "Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.",
      "how_it_worked": "Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.",
      "lessons": "Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure",
          "url": "https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Scattered Spider targets VMware ESXi using social engineering",
          "url": "https://securityaffairs.com/180466/cyber-crime/scattered-spider-targets-vmware-esxi-in-using-social-engineering/",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d"
    },
    {
      "title": "US sweep seizes 200 computers from North Korean IT worker laptop farms",
      "date": "2025-06-30",
      "date_precision": "day",
      "victim_org": "More than 100 US companies, including many Fortune 500 firms",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Insider Recruitment"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "DOJ described stolen and fraudulent identities; the announcement reviewed did not specify AI-generated personas.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Insider Access",
        "Espionage",
        "Cryptocurrency Theft"
      ],
      "loss_usd": null,
      "loss_note": "DOJ cited at least $3 million in victim-company losses for legal fees and remediation, more than $5 million in revenue in one Massachusetts scheme, roughly $915,000 in virtual currency stolen in a Georgia case, and a civil forfeiture action covering over $7.74 million in digital assets. US facilitators received at least $696,000.",
      "records_affected": null,
      "threat_actor": "DPRK remote IT worker networks and US-based facilitators (Zhenxing 'Danny' Wang, Kejia Wang and others)",
      "summary": "On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.",
      "how_it_worked": "North Korean workers obtained remote US employment using stolen and fabricated identities that cleared employer background checks. US-based facilitators supplied the American presence the scheme needed: they registered shell companies and fraudulent websites so the identities had verifiable employment history, received the employers' shipped laptops, and installed keyboard-video-mouse switches and remote access software so overseas operators could drive the machines as though sitting in front of them. From inside those employers the workers drew salaries routed to the DPRK, and in several cases went further, exfiltrating sensitive data including export-controlled military technology and stealing virtual currency from employer systems.",
      "lessons": "Employers need live identity proofing tied to the government ID at hire, verification that the issued device is physically where the employee claims to be, and alerting on KVM or remote-access hardware attached to corporate endpoints.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers",
          "url": "https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote",
          "publisher": "U.S. Department of Justice"
        },
        {
          "title": "U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms",
          "url": "https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms"
    },
    {
      "title": "Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector",
      "date": "2025-06-26",
      "date_precision": "day",
      "victim_org": "Hawaiian Airlines",
      "sector": "Transportation & Logistics",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI-generated media was reported in this intrusion.",
      "outcomes": [
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": "Scattered Spider (UNC3944 / Muddled Libra)",
      "summary": "Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.",
      "how_it_worked": "Scattered Spider's standard aviation playbook is to impersonate an employee or contractor in a call to the IT help desk and persuade the agent to reset credentials or enrol a new authenticator. The group also registers unauthorised devices against compromised accounts as a way of defeating multi-factor authentication, so that later logins look legitimate. Because airlines run large outsourced service desks covering shift workers and contractors around the clock, a caller claiming to be locked out mid-shift is a routine and hard-to-challenge request.",
      "lessons": "Strict, scripted caller-verification for account recovery and alerting on new device registrations against existing accounts are the controls that surface this pattern early.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Scattered Spider appears to pivot toward aviation sector",
          "url": "https://www.cybersecuritydive.com/news/scattered-spider-appears-to-pivot-toward-aviation-sector/751917/",
          "publisher": "Cybersecurity Dive"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector"
    },
    {
      "title": "DOJ moves to forfeit $225M in crypto traced to pig butchering victims",
      "date": "2025-06-18",
      "date_precision": "day",
      "victim_org": "US consumers (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Romance / Investment Scam",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Spear Phishing (Email)",
        "Tech Support Scam"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The forfeiture complaint focuses on the money laundering trail rather than the tooling used to create the scam personas.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Data Breach"
      ],
      "loss_usd": 19400000,
      "loss_note": "Over $225 million in USDT was targeted for forfeiture. DOJ identified 434 victims, of whom 60 named victims lost a combined $19.4 million; the $19.4M figure is used here as the confirmed victim loss.",
      "records_affected": 434,
      "threat_actor": null,
      "summary": "On 18 June 2025 the Department of Justice filed a civil forfeiture complaint seeking over $225 million in USDT laundered from international pig butchering investment scams, described at the time as its largest cryptocurrency seizure of that kind. The filing identified 434 victims, including 60 named victims who lost a combined $19.4 million. Among the traced funds were $3.3 million connected to Shan Hanes, the former Heartland Tri-State Bank chief executive whose $47.1 million embezzlement to pay scammers collapsed the Kansas bank in 2023.",
      "how_it_worked": "Victims were groomed online and induced to send tether to any of 93 deposit addresses controlled by the network. The proceeds were then split across up to 100 intermediary wallets to break the trail and to blend deposits from many victims, before consolidation into 22 primary exchange accounts and 122 further accounts linked by shared IP addresses and reused know-your-customer documents. The Heartland Tri-State case shows the depth of the psychological hold: a serving bank chief executive stole from his own bank, his church, an investment club and his daughter's college fund to keep feeding the scam, and received a 24-year sentence in August 2024.",
      "lessons": "The rule that a legitimate employer never requires an employee to deposit money to be paid is the whole control; payment providers should also flag consumer crypto purchases immediately preceding transfers to newly seen platforms.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "DOJ Ties Kansas Bank Collapse to $225 Million 'Pig Butchering' Seizure",
          "url": "https://www.coindesk.com/policy/2025/06/18/doj-ties-kansas-bank-collapse-to-225-million-pig-butchering-seizure",
          "publisher": "CoinDesk"
        },
        {
          "title": "New FTC Data Show Skyrocketing Consumer Reports About Game-Like Online Job Scams",
          "url": "https://www.ftc.gov/news-events/news/press-releases/2024/12/new-ftc-data-show-skyrocketing-consumer-reports-about-game-online-job-scams",
          "publisher": "Federal Trade Commission"
        },
        {
          "title": "FBI Releases Annual Internet Crime Report",
          "url": "https://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-report",
          "publisher": "Federal Bureau of Investigation"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims",
      "year": 2025,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-doj-moves-to-forfeit-225m-in-crypto-traced-to-pig-butchering-victims"
    },
    {
      "slug": "2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password",
      "title": "WestJet breach of 1.2 million passengers began with a help desk password reset",
      "date": "2025-06-13",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "WestJet",
      "sector": "Transportation & Logistics",
      "country": "Canada",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 1200000,
      "threat_actor": null,
      "summary": "Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.",
      "how_it_worked": "The attackers used social engineering to have an employee's password reset, then signed in to the corporate network through Citrix. The pretext was that of a legitimate employee locked out of their account, and the identity impersonated was a staff member whose details had been researched beforehand. The trust signal abused was the help desk's willingness to restore access on the strength of knowledge-based answers, and the pressure applied was a worker unable to do their job. From that foothold the intruders moved into the Windows domain and Microsoft cloud tenant and exfiltrated passenger records over several days before detection.",
      "lessons": "Identity-proofing at the service desk, using video verification or a manager-approved out-of-band challenge before any password or MFA reset, is the single control that would have stopped this.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "WestJet data breach exposes travel details of 1.2 million customers",
          "url": "https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Data breach at Canadian airline WestJet affects 1.2M passengers",
          "url": "https://techcrunch.com/2025/10/01/data-breach-at-canadian-airline-westjet-affects-1-2m-passengers/",
          "publisher": "TechCrunch"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password"
    },
    {
      "title": "Aflac breached in insurance-sector social engineering campaign; 22.6M affected",
      "date": "2025-06-12",
      "date_precision": "day",
      "victim_org": "Aflac",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No public reporting attributes AI-generated voice to the Aflac intrusion.",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed; Aflac offered 24 months of credit monitoring, identity theft and medical fraud protection.",
      "records_affected": 22650000,
      "threat_actor": "Not confirmed by Aflac; reporting points to Scattered Spider's 2025 insurance-sector campaign",
      "summary": "Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.",
      "how_it_worked": "Aflac has not published the intrusion mechanics beyond describing a sophisticated cybercrime group and an industry-wide campaign, so the vector here is characterised from the campaign rather than from Aflac's own disclosure. Google Threat Intelligence, warning insurers during the same weeks, told the sector to pay particular attention to social engineering attempts against help desks and call centres, the route the same crews had used against retail and hospitality: a phone call impersonating staff to obtain credential or MFA resets, then rapid data collection with no malware deployed.",
      "lessons": "Identity verification standards for help desks and call centres, applied to both employee and customer channels, is the control the sector was explicitly warned to strengthen.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Aflac discloses breach amidst Scattered Spider insurance attacks",
          "url": "https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "22M Affected by Aflac Data Breach",
          "url": "https://www.securityweek.com/22-million-affected-by-aflac-data-breach/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Aflac confirms June data breach affecting over 22 million customers",
          "url": "https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised",
          "url": "https://www.hipaajournal.com/aflac-data-breach/",
          "publisher": "The HIPAA Journal"
        },
        {
          "title": "3 key takeaways from the Scattered Spider attacks on insurance firms",
          "url": "https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff"
    },
    {
      "title": "UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app",
      "date": "2025-06-04",
      "date_precision": "day",
      "victim_org": "Approximately 20 Salesforce customer organisations, later including Google",
      "sector": "Other",
      "country": "Multiple",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure; extortion demands followed the intrusions by several months.",
      "records_affected": null,
      "threat_actor": "UNC6040, with extortion branded as ShinyHunters (UNC6240)",
      "summary": "Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.",
      "how_it_worked": "The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.",
      "lessons": "Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App",
          "url": "https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"
    },
    {
      "title": "BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware",
      "date": "2025-06",
      "date_precision": "month",
      "victim_org": "Employee of a cryptocurrency foundation (Web3 sector)",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "Amount stolen not disclosed",
      "records_affected": null,
      "threat_actor": "BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)",
      "summary": "In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.",
      "how_it_worked": "The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.",
      "lessons": "Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "North Korean hackers deepfake execs in Zoom call to spread Mac malware",
          "url": "https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware",
          "url": "https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"
    },
    {
      "title": "Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers",
      "date": "2025-06",
      "date_precision": "month",
      "victim_org": "US State Department; three foreign ministers, a US governor and a member of Congress",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "A State Department cable described an impostor using AI-generated voice and text to mimic Secretary of State Marco Rubio, leaving Signal voicemails for at least two targets.",
      "outcomes": [
        "Attempt Blocked",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.",
      "how_it_worked": "The impostor exploited the fact that senior diplomats routinely use Signal for informal contact, so a message from an account labelled with the Secretary's official email address fit the expected pattern. Rather than opening with a request, the actor left short voicemails in a cloned voice and sent texts inviting the target to continue the conversation on Signal, which builds familiarity before anything is asked. The trust signal was the combination of a recognisable voice and a display name resembling a state.gov address, neither of which is authenticated by the platform. Targets who engaged would then have been positioned for requests for information or for account access.",
      "lessons": "Display names and voices are not identity: diplomatic contact should be initiated or confirmed through embassy and ministry channels, and platforms used for official business need verified organisational identity.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Imposter used AI to pose as Marco Rubio and contact foreign ministers",
          "url": "https://feeds.bbci.co.uk/news/articles/crrqkyyjewno",
          "publisher": "BBC News"
        },
        {
          "title": "A Marco Rubio impostor is using AI voice to call high-level officials",
          "url": "https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/",
          "publisher": "The Washington Post"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore"
    },
    {
      "title": "Google's own Salesforce instance hit by UNC6040 IT-support vishing",
      "date": "2025-06",
      "date_precision": "month",
      "victim_org": "Google",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.",
      "records_affected": null,
      "threat_actor": "UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'",
      "summary": "Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.",
      "how_it_worked": "Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.",
      "lessons": "Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Salesforce customers duped by series of social-engineering attacks",
          "url": "https://cyberscoop.com/google-unc6040-salesforce-attacks/",
          "publisher": "CyberScoop"
        },
        {
          "title": "Google confirms Salesforce CRM breach, faces extortion threat",
          "url": "https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups",
          "url": "https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Google Among Victims in Ongoing Salesforce Data Theft Campaign",
          "url": "https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/",
          "publisher": "Infosecurity Magazine"
        },
        {
          "title": "ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications",
          "url": "https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications",
          "publisher": "EclecticIQ"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"
    },
    {
      "title": "Erie Insurance hit in Scattered Spider help desk campaign against insurers",
      "date": "2025-06",
      "date_precision": "month",
      "victim_org": "Erie Insurance",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI-generated voice or video was reported in connection with this intrusion.",
      "outcomes": [
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": "Scattered Spider (UNC3944)",
      "summary": "Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.",
      "how_it_worked": "The intrusion set relied on service-desk manipulation rather than exploitation. An operator called the help desk holding enough identifying information to impersonate a named employee, asked for an MFA enrolment link to be issued for a supposed new mobile device, and once that device was trusted, used self-service password reset to seize the account outright. Researchers noted the technique was effective across multiple insurers precisely because help desks follow an identical procedure no matter who calls, so a single credible pretext worked repeatedly.",
      "lessons": "Identity proofing that a caller cannot supply from public or previously breached data, such as manager callback or a live video ID check, is the control that breaks this chain.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "3 key takeaways from the Scattered Spider attacks on insurance firms",
          "url": "https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure"
    },
    {
      "title": "Philadelphia Insurance Companies disclosed breach in insurer-focused campaign",
      "date": "2025-06",
      "date_precision": "month",
      "victim_org": "Philadelphia Insurance Companies",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI-generated voice or video was reported in connection with this intrusion.",
      "outcomes": [
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": "Scattered Spider (UNC3944)",
      "summary": "Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.",
      "how_it_worked": "Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.",
      "lessons": "Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "3 key takeaways from the Scattered Spider attacks on insurance firms",
          "url": "https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"
    },
    {
      "slug": "2025-russian-state-linked-actors-phish-app-specific-passwords-from-academics",
      "title": "Russian state-linked actors phish app-specific passwords from academics and critics",
      "date": "2025-06",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Academics, journalists and Russia critics (individuals not named)",
      "sector": "Nonprofit",
      "country": "Multiple",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "UNC6293 (assessed linked to APT29 / Cozy Bear)",
      "summary": "Google Threat Intelligence and Citizen Lab jointly documented a campaign in June 2025 in which a Russian government-linked cluster tracked as UNC6293 persuaded targets to create Google application-specific passwords and hand them over. Victims included prominent academics and critics of Russia. The technique bypassed multi-factor authentication entirely and gave the attackers durable mailbox access.",
      "how_it_worked": "The operators impersonated US State Department officials and invited targets to private online consultations, sustaining polite, well-written correspondence over days or weeks and copying plausible-looking @state.gov addresses to make the exchange feel institutional. They then sent PDF instructions asking the target to generate a Google app-specific password, described as a way to join a secure State Department platform, and to send the sixteen-character string back. Because the victim generated it themselves inside their real Google account, nothing looked stolen and MFA was never challenged. The attackers used the password for ongoing, silent access to the mailbox.",
      "lessons": "Disable app-specific passwords for at-risk users, enrol them in Google's Advanced Protection Program, and treat any request to generate an account credential for a third party as a red flag regardless of who is asking.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Same Sea, New Phish: Russian Government-Linked Social Engineering Targets App-Specific Passwords",
          "url": "https://citizenlab.ca/research/russian-government-linked-social-engineering-targets-app-specific-passwords/",
          "publisher": "The Citizen Lab"
        },
        {
          "title": "Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign",
          "url": "https://thehackernews.com/2025/06/russian-apt29-exploits-gmail-app.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-russian-state-linked-actors-phish-app-specific-passwords-from-academics"
    },
    {
      "slug": "2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million",
      "title": "Farmers Insurance breach via Salesforce vishing wave affects 1.1 million customers",
      "date": "2025-05-29",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Farmers Insurance",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 1100000,
      "threat_actor": "ShinyHunters, working with UNC6040 / UNC6240",
      "summary": "Farmers Insurance told state attorneys general that an unauthorized actor accessed a third-party vendor's database on 29 May 2025; the vendor detected the activity the next day and blocked the actor. BleepingComputer identified the vendor as Salesforce and tied the intrusion to the campaign in which attackers used voice phishing to trick employees into linking malicious OAuth applications to their company Salesforce instances, then bulk-downloaded the connected databases. Approximately 1.1 million customers were affected, with names, addresses, dates of birth, driver's licence numbers and the last four digits of Social Security numbers exposed. Notifications began on 22 August 2025.",
      "how_it_worked": "In this campaign the caller poses as internal IT or a support desk and tells the employee that a routine tool needs to be connected to the company's Salesforce tenant. The employee is walked to Salesforce's legitimate connected-app authorisation page and given an eight-digit connection code supplied by the attacker, which they enter and approve. Because every screen the employee sees is a real Salesforce page, the trust signal is Salesforce's own interface, not a spoofed one. Approval binds an attacker-controlled data-extraction application to the tenant with the employee's permissions, after which records can be pulled in bulk without any further interaction.",
      "lessons": "Limiting the connected-app authorisation permission to a small admin group and blocking uninstalled or unapproved apps by default removes the single click that this pretext is engineered to obtain.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Farmers Insurance data breach impacts 1.1M people after Salesforce attack",
          "url": "https://www.bleepingcomputer.com/news/security/farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Farmers Insurance Data Breach Affects 1.1 Million Customers",
          "url": "https://www.secureworld.io/industry-news/farmers-insurance-data-breach",
          "publisher": "SecureWorld"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-farmers-insurance-breach-via-salesforce-vishing-wave-affects-1-1-million"
    },
    {
      "title": "3AM ransomware affiliate used email bombing plus spoofed IT support calls",
      "date": "2025-05-21",
      "date_precision": "day",
      "victim_org": "Unnamed Sophos client",
      "sector": "Other",
      "country": "Unknown",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "Sophos did not report AI-generated audio; the caller spoofed the victim's real IT department number.",
      "outcomes": [
        "Data Breach",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "No ransom or loss figure disclosed. 868 GB of data was exfiltrated but ransomware encryption was blocked.",
      "records_affected": null,
      "threat_actor": "3AM ransomware affiliate",
      "summary": "Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.",
      "how_it_worked": "The affiliate first buried a target employee under 24 unsolicited emails in three minutes, manufacturing an apparent IT emergency. While the inbox was still filling, an operator phoned the employee using a spoofed caller ID that matched the company's real IT department number, offered to fix the flood, and asked the employee to start a Microsoft Quick Assist remote session. The employee granted control, giving the attacker hands-on-keyboard access. The attackers then exfiltrated 868 GB to Backblaze cloud storage over nine days before attempting ransomware deployment.",
      "lessons": "A rule that IT never initiates remote-control sessions by inbound call, paired with blocking or alerting on Quick Assist use, breaks the email-bombing-plus-callback pattern.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "3AM ransomware uses spoofed IT calls, email bombing to breach networks",
          "url": "https://www.bleepingcomputer.com/news/security/3am-ransomware-uses-spoofed-it-calls-email-bombing-to-breach-networks/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call"
    },
    {
      "title": "UK 'safe account' bank and police impersonation drives £450.7M in APP fraud",
      "date": "2025-05-19",
      "date_precision": "day",
      "victim_org": "UK banking customers (multi-victim campaign)",
      "sector": "Financial Services",
      "country": "United Kingdom",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "UK Finance's 2024 reporting does not break out AI-enabled impersonation as a separate category.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "Losses are reported in sterling: £1.17 billion total fraud in 2024, of which £450.7 million was authorised push payment fraud (£365.7 million personal and £84.9 million non-personal) across under 186,000 cases. Safe account impersonation losses fell 16 percent and cases fell 32 percent year on year.",
      "records_affected": 186000,
      "threat_actor": null,
      "summary": "UK Finance's 2025 annual fraud report recorded £1.17 billion in total UK fraud losses for 2024, including £450.7 million lost to authorised push payment fraud across under 186,000 cases, the lowest APP case volume since 2020. Within that, impersonation scams in which criminals pose as a bank or the police and tell the victim to move money to a so-called safe account saw losses fall 16 percent and case numbers fall 32 percent against 2023.",
      "how_it_worked": "A caller presents as the victim's bank fraud team or as police, often after a preparatory text or a spoofed caller ID matching the number on the back of the bank card. The victim is told their account has been compromised by a criminal, potentially an insider at the bank, and that the only way to protect the balance is to transfer it immediately to a new safe account which the caller supplies. Because the victim authorises the payment themselves, normal card fraud controls do not apply. The levers are institutional authority, fear of loss, and the instruction not to discuss it with branch staff who might be complicit.",
      "lessons": "No bank or police force ever asks a customer to move money to a safe account; confirmation of payee checks, in-app warnings at the point of transfer and mandatory delays on first-time large payees are the effective controls.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Fraud continues to pose a major threat with over £1 billion stolen in 2024",
          "url": "https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2025-press-release",
          "publisher": "UK Finance"
        },
        {
          "title": "Smishing: Package Tracking Text Scams",
          "url": "https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams",
          "publisher": "United States Postal Inspection Service"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-uk-safe-account-bank-and-police-impersonation-drives-450-7m-in-app-fraud"
    },
    {
      "title": "FBI warns of AI voice-cloning campaign impersonating senior US officials",
      "date": "2025-05-15",
      "date_precision": "day",
      "victim_org": "Current and former senior US federal and state officials and their contacts",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Credential Phishing Portal",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The FBI stated that malicious actors were sending AI-generated voice messages, alongside text messages, that purported to come from senior US officials.",
      "outcomes": [
        "Credential Theft",
        "Identity Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.",
      "how_it_worked": "The campaign traded on the recipient's relationship with a named senior official rather than on any technical exploit. An initial text or voicemail in a cloned voice established that the official was reaching out personally, which for a colleague or former colleague is unremarkable. Once a reply came, targets were invited to continue on a separate messaging platform, a request that reads as security-conscious in government circles, and the link supplied there led to a credential-harvesting page or a device-linking flow. Each successful compromise fed the next round, since messages arriving from a genuinely compromised official account carry far more weight than any spoof.",
      "lessons": "Officials and their contacts should verify unexpected outreach through a separately known number or channel, and adopt phishing-resistant authentication on personal accounts, which are typically the weak point rather than official systems.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Senior US Officials Impersonated in Malicious Messaging Campaign (PSA250515)",
          "url": "https://www.ic3.gov/PSA/2025/PSA250515",
          "publisher": "FBI Internet Crime Complaint Center"
        },
        {
          "title": "FBI warns senior US officials are being impersonated using texts, AI-based voice cloning",
          "url": "https://www.cybersecuritydive.com/news/fbi-us-officials-impersonated-text-ai-voice/748334/",
          "publisher": "Cybersecurity Dive"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials"
    },
    {
      "title": "Bribed overseas support agents leaked Coinbase data; $20M extortion refused",
      "date": "2025-05-15",
      "date_precision": "day",
      "victim_org": "Coinbase",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Help Desk Impersonation",
        "Tech Support Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported in Coinbase's disclosure.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Insider Access",
        "Cryptocurrency Theft",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "Coinbase refused the $20 million demand and instead established a $20 million reward fund for information leading to arrests. Aggregate customer losses from the resulting social engineering were not quantified in the disclosure.",
      "records_affected": 69461,
      "threat_actor": "Unattributed extortion group",
      "summary": "Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.",
      "how_it_worked": "The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.",
      "lessons": "Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Protecting Our Customers - Standing Up to Extortionists",
          "url": "https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists",
          "publisher": "Coinbase"
        },
        {
          "title": "Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails",
          "url": "https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Coinbase confirms insiders handed over data of 70K users",
          "url": "https://www.theregister.com/2025/05/21/coinbase_confirms_insider_breach_affects/",
          "publisher": "The Register"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-bribed-overseas-support-agents-leaked-coinbase-data-20m-extortion-refuse"
    },
    {
      "title": "Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft",
      "date": "2025-05-08",
      "date_precision": "day",
      "victim_org": "BitoPro",
      "sector": "Cryptocurrency",
      "country": "Taiwan",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 11500000,
      "loss_note": "About $11.5 million in suspicious withdrawals, disclosed publicly on June 3, 2025. BitoPro said reserves were sufficient and user functions were unaffected.",
      "records_affected": null,
      "threat_actor": "Lazarus Group (DPRK), attributed by BitoPro",
      "summary": "Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.",
      "how_it_worked": "BitoPro described the entry point only as social engineering against a cloud operations employee and did not disclose the specific channel or pretext used; the vector is recorded here as targeted phishing on that basis and the channel remains unconfirmed. Malware planted on the employee's device let the attackers hijack AWS session tokens, which sidestepped multi-factor authentication entirely because a live session had already satisfied it. Holding valid session tokens, they took control of BitoPro's cloud infrastructure and used their command server to inject scripts into the hot wallet system while a scheduled wallet upgrade and asset transfer was in progress. The malicious withdrawals were timed and shaped to mimic the legitimate migration traffic around them.",
      "lessons": "Binding cloud session tokens to device posture and network origin, so a stolen token is unusable elsewhere, plus freezing automated wallet operations during manual migrations, would have denied both halves of this attack.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "BitoPro exchange links Lazarus hackers to $11 million crypto heist",
          "url": "https://www.bleepingcomputer.com/news/security/bitopro-exchange-links-lazarus-hackers-to-11-million-crypto-heist/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hack",
          "url": "https://fortune.com/crypto/2025/06/03/taiwanese-crypto-exchange-bitopro-confirms-hack/",
          "publisher": "Fortune"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef",
      "year": 2025,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-social-engineering-of-a-cloud-ops-employee-preceded-bitopro-s-11-5m-thef"
    },
    {
      "title": "Harrods restricts internet access after intrusion attempts in UK retail wave",
      "date": "2025-05-01",
      "date_precision": "day",
      "victim_org": "Harrods",
      "sector": "Retail",
      "country": "United Kingdom",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Harrods disclosed no technical detail, so no assessment of AI involvement is possible.",
      "outcomes": [
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Harrods confirmed on 1 May 2025 that it had detected attempts to gain unauthorised access to some of its systems and had proactively restricted internet access at its sites while keeping stores and harrods.com open. It was the third major UK retailer targeted within a week, after Marks & Spencer and Co-op. Harrods did not disclose the intrusion method or confirm attacker attribution, and did not initially say whether customer data was affected. A separate third-party breach affecting Harrods customers surfaced in September 2025.",
      "how_it_worked": "Harrods has never described the mechanics, so the entry attempt is characterised here only by the campaign it belonged to. The wave that hit UK retail in April and May 2025 was driven by English-speaking crews who phoned retailer service desks impersonating staff to obtain password and MFA resets, then escalated inside the identity provider. Harrods' response, cutting external internet access at sites while investigating, is consistent with defending against credential-based lateral movement rather than a software exploit, but the company has confirmed nothing further.",
      "lessons": "Fast containment helped here, but the durable control against this campaign is out-of-band identity proofing before any help desk credential or MFA reset.",
      "confidence": "Alleged",
      "sources": [
        {
          "title": "Luxury department store Harrods suffered a cyberattack",
          "url": "https://securityaffairs.com/177330/cyber-crime/luxury-department-store-harrods-suffered-a-cyberattack.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Harrods alerts customers to new data breach linked to third-party provider",
          "url": "https://securityaffairs.com/182752/data-breach/harrods-alerts-customers-to-new-data-breach-linked-to-third-party-provider.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-harrods-restricts-internet-access-after-intrusion-attempts-in-uk-retail"
    },
    {
      "title": "AI voice impersonation of White House chief of staff Susie Wiles targets Republicans",
      "date": "2025-05",
      "date_precision": "month",
      "victim_org": "The White House; senators, governors and business executives contacted",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Officials cited by news reports believed the impersonator used AI to replicate Susie Wiles's voice on phone calls; the contact list appears to have come from her compromised personal phone.",
      "outcomes": [
        "Identity Theft",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In May 2025 an unknown person made calls and sent text messages impersonating White House chief of staff Susie Wiles to senior Republicans, including senators, governors and business executives. Reporting indicated the impersonator drew on contacts obtained from Wiles's hacked personal phone and, on calls, used what officials believed was an AI clone of her voice. Requests included a list of people who might be considered for presidential pardons and, in at least one case, a cash transfer. The FBI and the White House opened investigations.",
      "how_it_worked": "The attack started from a compromised personal phone, which supplied both the target list and the context needed to make each approach specific. Messages and calls appeared to come from someone recipients genuinely deal with, and the requests, a pardon shortlist or a favour involving money, are the kind of sensitive, informal business that plausibly happens by phone rather than through official channels precisely because it is delicate. The cloned voice removed the last check most recipients would apply. Suspicion emerged from content rather than technology: some recipients noticed the requests did not match how Wiles operates, and the messages came from an unfamiliar number.",
      "lessons": "Senior staff should keep official business off personal devices and pre-agree verification practices with frequent contacts, so that an unexpected request from a new number is confirmed before anyone acts.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "White House responds to attempts to impersonate Trump advisor Susie Wiles",
          "url": "https://www.newsweek.com/white-house-susie-wiles-trump-impersonate-fbi-2078802",
          "publisher": "Newsweek"
        },
        {
          "title": "Trump officials keep getting targeted by 'vishing'",
          "url": "https://time.com/7301176/impersonation-ai-voice-vishing-scam-rubio-wiles-trump-fbi-advice/",
          "publisher": "TIME"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-impersonation-of-white-house-chief-of-staff-susie-wiles-targets"
    },
    {
      "title": "Kraken advanced a North Korean fake job applicant to unmask his tradecraft",
      "date": "2025-05",
      "date_precision": "month",
      "victim_org": "Kraken (Payward, Inc.)",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "Kraken reported the candidate's primary ID appeared altered, likely using details from an identity theft case two years earlier, and that he switched between voices during interviews in a way consistent with real-time coaching. Kraken did not attribute either to AI.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "No loss. The candidate was never hired; Kraken advanced him through the process deliberately to collect intelligence.",
      "records_affected": null,
      "threat_actor": "DPRK-linked fake IT worker network",
      "summary": "Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.",
      "how_it_worked": "The infiltration relied on the fact that remote hiring verifies documents and video, not people. The candidate presented a resume and a government ID built from a stolen identity, joined interviews from remote colocated Mac desktops routed through VPNs to mask his real location and network, and appeared to be coached in real time, which produced audible shifts between voices. Kraken's team, already holding a partner-supplied list of email addresses tied to the group, matched his application address and let the process continue. In the final round Chief Security Officer Nick Percoco ran trap identity verification: asking him to confirm his location live, hold up his government ID, and recommend restaurants in the city he claimed to live in. He could not answer questions about his own city or citizenship.",
      "lessons": "Unscripted, locality-specific live verification during a video interview, cross-checked against threat-intel lists of known applicant identifiers, catches what document checks and reference calls cannot.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "How we identified a North Korean hacker who tried to get a job at Kraken",
          "url": "https://blog.kraken.com/news/how-we-identified-a-north-korean-hacker",
          "publisher": "Kraken"
        },
        {
          "title": "Kraken tells how it spotted North Korean hacker in job interview",
          "url": "https://cointelegraph.com/news/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview",
          "publisher": "Cointelegraph"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra"
    },
    {
      "title": "FBI warns Silent Ransom Group is callback-phishing US law firms",
      "date": "2025-05",
      "date_precision": "month",
      "victim_org": "US law firms and legal services organisations (campaign)",
      "sector": "Legal",
      "country": "United States",
      "primary_vector": "Callback Phishing (TOAD)",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Help Desk Impersonation",
        "Tech Support Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported in the FBI advisory.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure published; the group extorts victims after data theft without deploying encryption.",
      "records_affected": null,
      "threat_actor": "Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, UNC3753)",
      "summary": "The FBI issued a private industry notification in May 2025 warning that Silent Ransom Group, also known as Luna Moth, had been targeting US law firms for roughly two years using callback phishing and direct impersonation of IT staff. The group steals data and extorts victims without deploying ransomware. Law firms are attractive targets because of the volume of sensitive client material they hold.",
      "how_it_worked": "The primary lure is a telephone-oriented attack delivery email: a message claims a small subscription has been renewed and will be charged unless the recipient calls a number to cancel. There is no link or attachment, so the mail passes gateway filtering. When the victim calls, the operator, posing as support, directs them to a website and has them install a legitimate remote access utility such as Zoho Assist, Syncro, AnyDesk, SuperOps or Atera. The group has also skipped the email entirely and simply telephoned employees claiming to be the firm's own IT department with an after-hours maintenance request. Once connected, the operators escalate where possible, use tools such as WinSCP or Rclone to exfiltrate documents, then extort the firm by threatening publication on a leak site.",
      "lessons": "Application control that blocks unapproved remote access tools is the decisive check here, since the email carries no malicious payload for a gateway to catch; staff also need a verified internal number for IT so an unexpected support call can be refused.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "FBI warns of Luna Moth extortion attacks targeting law firms",
          "url": "https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign",
          "url": "https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "FBI warns of cybercriminals impersonating IT staff to breach law firms",
          "url": "https://www.floridabar.org/the-florida-bar-news/fbi-warns-of-cybercriminals-impersonating-it-staff-to-breach-law-firms/",
          "publisher": "The Florida Bar"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-silent-ransom-group-is-callback-phishing-us-law-firms"
    },
    {
      "title": "Binance and Kraken block bribery attempts aimed at support staff",
      "date": "2025-05",
      "date_precision": "month",
      "victim_org": "Binance and Kraken",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "Contact was made over Telegram; no AI-generated media was reported.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "No losses; both attempts were stopped before any customer data was exposed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In the weeks around the Coinbase insider breach, the same style of attack was attempted against Binance and Kraken. Bloomberg-sourced reporting said threat actors approached customer support staff at both exchanges over Telegram and offered bribes for system access and customer data. Both exchanges detected and blocked the approaches, and neither reported any user data exposure.",
      "how_it_worked": "Attackers contacted individual support agents directly on Telegram, offering cryptocurrency payment and supplying step-by-step instructions on how to retrieve and exfiltrate customer records, evade internal monitoring, and receive payment. The pitch targeted people rather than systems, on the assumption that a support agent with broad record access is cheaper to buy than a vulnerability is to find. Binance's monitoring flagged the suspicious communication patterns, including bribe-related keywords and outbound Telegram contact attempts, while both exchanges relied on data-access policies tightened in late 2024 to limit what any single agent could pull.",
      "lessons": "Access limits that make a single agent's data reach small, plus monitoring for recruitment-style contact and anomalous record retrieval, turn insider bribery into a detected event rather than a breach.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Social Engineering Plot Foiled at Binance and Kraken After Coinbase Breach Fallout",
          "url": "https://yellow.com/news/social-engineering-plot-foiled-at-binance-and-kraken-after-coinbase-breach-fallout",
          "publisher": "Yellow"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-binance-and-kraken-block-bribery-attempts-aimed-at-support-staff",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-binance-and-kraken-block-bribery-attempts-aimed-at-support-staff"
    },
    {
      "slug": "2025-adidas-customer-data-stolen-through-third-party-customer-service-provide",
      "title": "Adidas customer data stolen through third-party customer service provider",
      "date": "2025-05",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Adidas",
      "sector": "Retail",
      "country": "Germany",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "ShinyHunters / UNC6040 (reported)",
      "summary": "Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.",
      "how_it_worked": "Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.",
      "lessons": "Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider",
          "url": "https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider",
          "publisher": "Rescana"
        },
        {
          "title": "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH",
          "url": "https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"
    },
    {
      "title": "Marks & Spencer attack tied to social engineering of outsourced service desk",
      "date": "2025-04-22",
      "date_precision": "day",
      "victim_org": "Marks & Spencer Group plc",
      "sector": "Retail",
      "country": "United Kingdom",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Vishing (Voice Phishing)",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption",
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "M&S publicly guided to a hit of around £300 million to operating profit before mitigation; no USD figure is asserted here.",
      "records_affected": null,
      "threat_actor": "Scattered Spider, deploying DragonForce ransomware",
      "summary": "Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.",
      "how_it_worked": "Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.",
      "lessons": "Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "M&S hackers gained access through third-party Tata Consulting Services, sources say",
          "url": "https://cybernews.com/news/marks-spencer-hackers-used-employee-login-tsc-tata-consulting-scattered-spider/",
          "publisher": "Cybernews"
        },
        {
          "title": "M&S confirms month-long breach result of third-party vendor phishing attack",
          "url": "https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/",
          "publisher": "Cybernews"
        },
        {
          "title": "Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages",
          "url": "https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre",
          "url": "https://feeds.bbci.co.uk/news/articles/c4grn878712o",
          "publisher": "BBC News"
        },
        {
          "title": "Marks and Spencer confirms data breach after April cyber attack",
          "url": "https://securityaffairs.com/177784/data-breach/marks-and-spencer-confirms-data-breach-after-april-cyber-attack.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Marks & Spencer breach linked to Scattered Spider ransomware attack",
          "url": "https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de"
    },
    {
      "title": "North Korean operatives adopt real-time deepfakes to pass remote job interviews",
      "date": "2025-04",
      "date_precision": "month",
      "victim_org": "Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Deepfake Video Call",
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.",
      "outcomes": [
        "Attempt Blocked",
        "Insider Access"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "DPRK remote IT worker operations",
      "summary": "In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.",
      "how_it_worked": "The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.",
      "lessons": "Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation",
          "url": "https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/",
          "publisher": "Palo Alto Networks Unit 42"
        },
        {
          "title": "North Korean Operatives Use Deepfakes in IT Job Interviews",
          "url": "https://www.darkreading.com/remote-workforce/north-korean-operatives-deepfakes-it-job-interviews",
          "publisher": "Dark Reading"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int"
    },
    {
      "title": "Co-op loses £206m of revenue and 6.5 million members' data to DragonForce",
      "date": "2025-04",
      "date_precision": "month",
      "victim_org": "Co-operative Group",
      "sector": "Retail",
      "country": "United Kingdom",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Service Disruption",
        "Extortion"
      ],
      "loss_usd": 275000000,
      "loss_note": "Co-op reported a £206 million revenue loss, roughly $275 million, driven by weeks of food supply disruption.",
      "records_affected": 6500000,
      "threat_actor": "DragonForce, with Scattered Spider-aligned English-speaking affiliates; four people aged 17 to 20 were arrested by the UK NCA in July 2025",
      "summary": "The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.",
      "how_it_worked": "Co-op's account of the intrusion, given publicly by its leadership, is that the attackers impersonated an employee convincingly enough to have that employee's password reset, then used the re-issued credentials to enter the network. The Teams messages and follow-up phone calls to security staff show the same crew comfortable operating in the victim's own collaboration tools, negotiating and pressuring in real time. Co-op's decision to pull systems down aggressively contained the intrusion before encryption, which is why the damage landed as lost revenue and stolen data rather than ransomware.",
      "lessons": "Caller verification at the service desk, and separate approval paths for resets on high-privilege accounts, would have removed the single conversation that granted access.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Cyberattack on Co-op leaves shelves empty, data stolen, and $275M in lost revenue",
          "url": "https://securityaffairs.com/182713/security/cyberattack-on-co-op-leaves-shelves-empty-data-stolen-and-275m-in-lost-revenue.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "DragonForce group claims the theft of data after Co-op cyberattack",
          "url": "https://securityaffairs.com/177376/cyber-crime/dragonforce-group-claims-the-theft-of-data-after-co-op-cyberattack.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Data of all 6.5 million Co-op members stolen - CEO says she is 'incredibly sorry'",
          "url": "https://www.techradar.com/pro/security/data-of-all-6-5-million-coop-members-stolen-ceo-is-incredibly-sorry",
          "publisher": "TechRadar Pro"
        },
        {
          "title": "Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre",
          "url": "https://feeds.bbci.co.uk/news/articles/c4grn878712o",
          "publisher": "BBC News"
        },
        {
          "title": "Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages",
          "url": "https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce",
      "year": 2025,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce"
    },
    {
      "title": "Rippling sues Deel over a manager allegedly recruited as a corporate spy",
      "date": "2025-03-17",
      "date_precision": "day",
      "victim_org": "Rippling",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was alleged.",
      "outcomes": [
        "Insider Access",
        "Espionage",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure has been established. The complaint alleges payment to the employee laundered through an intermediary; the allegations are contested and litigation is ongoing.",
      "records_affected": null,
      "threat_actor": "Alleged: a Rippling employee acting on behalf of competitor Deel. Deel disputes the allegations; a related DOJ inquiry has been reported.",
      "summary": "On March 17, 2025 Rippling sued rival HR and payroll company Deel in the Northern District of California, alleging Deel cultivated a Rippling employee as a spy. The complaint says the employee searched Rippling systems for 'Deel' an average of 23 times a day over four months and accessed Slack channels more than 6,000 times without business justification, funnelling sales pipeline data, pricing, customer churn lists and employee contact details to Deel. Deel denies wrongdoing and the litigation continues.",
      "how_it_worked": "The alleged access was entirely legitimate on its face. A person in a management role at a Rippling affiliate used their normal credentials to run searches and read Slack channels, activity that generated no security alerts because none of it was unauthorised in a technical sense; the abuse was in volume and purpose. Rippling exposed it with a honeypot rather than a detection rule: it sent a letter to three Deel executives referencing a Slack channel called 'd-defectors' that existed but had never contained a single message. Within hours the employee searched for that never-used channel for the first time, which Rippling argues shows the letter's contents were relayed to him. He was confronted when court-appointed solicitors sought his phone.",
      "lessons": "Insider risk programmes need behavioural baselining on internal search and channel access, since a recruited insider's activity is authorised by definition and only its pattern gives it away.",
      "confidence": "Alleged",
      "sources": [
        {
          "title": "Lawsuit Alleges $12 Billion 'Unicorn' Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor",
          "url": "https://www.rippling.com/blog/lawsuit-alleges-12-billion-unicorn-deel-cultivated-spy-orchestrated-long-running-trade-secret-theft-corporate-espionage-against-competitor",
          "publisher": "Rippling"
        },
        {
          "title": "Rippling accuses competitor Deel of corporate espionage",
          "url": "https://www.hr-brew.com/stories/2025/03/20/rippling-deel-corporate-espionage",
          "publisher": "HR Brew"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy"
    },
    {
      "title": "25 Canadians charged over $21M grandparent scam targeting seniors in 40 states",
      "date": "2025-03-05",
      "date_precision": "day",
      "victim_org": "Elderly US residents in more than 40 states (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States and Canada",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Physical Pretexting"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The indictment describes live callers posing as grandchildren and lawyers; it does not allege voice cloning.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 21000000,
      "loss_note": "Over $21 million in losses, per the charging announcement.",
      "records_affected": null,
      "threat_actor": "Montreal-area call center network (25 Canadian nationals charged)",
      "summary": "On 5 March 2025 US authorities announced charges against 25 Canadian nationals over a grandparent scam run from call centers in and around Montreal that defrauded elderly people in more than 40 states of over $21 million. Twenty-three defendants were arrested on 4 March and two remained at large. Money was moved to Canada after cash pickups, sometimes through cryptocurrency, to obscure its source.",
      "how_it_worked": "Callers phoned elderly Americans and claimed to be a grandchild who had been arrested after a car crash and needed bail money immediately. A second conspirator came on the line posing as an attorney to lend procedural credibility, and told the victim a gag order forbade discussing the case with anyone, an instruction that isolates the target from the family members who would otherwise puncture the story. The emotional lever was fear for a grandchild in custody, layered with legal authority and enforced secrecy. Collection was in person: a conspirator posing as a bail bondsman came to the victim's home to take the cash.",
      "lessons": "A pre-agreed family code word and an absolute rule of hanging up and calling the relative back on a known number defeats this script, since the scam depends on the victim never independently verifying.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "25 Canadian nationals connected to nationwide multi-million dollar 'grandparent scam' charged in Vermont",
          "url": "https://www.ice.gov/news/releases/25-canadian-nationals-connected-nationwide-multi-million-dollar-grandparent-scam",
          "publisher": "U.S. Immigration and Customs Enforcement"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-25-canadians-charged-over-21m-grandparent-scam-targeting-seniors-in-40-s",
      "year": 2025,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-25-canadians-charged-over-21m-grandparent-scam-targeting-seniors-in-40-s"
    },
    {
      "slug": "2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509",
      "title": "Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients",
      "date": "2025-03-03",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Arizona Arthritis and Rheumatology Associates",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 5509,
      "threat_actor": null,
      "summary": "Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.",
      "how_it_worked": "Staff received phishing email designed to look like routine Microsoft 365 account or document notifications and entered their work credentials on an attacker-controlled sign-in page. The trust signals abused were the familiar Microsoft branding and the ordinary rhythm of clinic email, where staff process insurance, referral and scheduling messages all day and open unfamiliar attachments as a matter of course. With valid credentials the attacker signed into the mailboxes and had immediate access to months of patient correspondence. Because the access used legitimate credentials from a normal cloud client, nothing looked malicious until sign-in anomalies were reviewed.",
      "lessons": "Phishing-resistant MFA on clinical email accounts, plus conditional access blocking unfamiliar sign-in locations, would have made the harvested passwords useless.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents",
          "url": "https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/",
          "publisher": "HIPAA Journal"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509"
    },
    {
      "slug": "2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients",
      "title": "Monongalia Health System email phishing breach affects 4,895 patients",
      "date": "2025-03-03",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Monongalia Health System (Mon Health)",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 4895,
      "threat_actor": null,
      "summary": "West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.",
      "how_it_worked": "Employees were sent phishing messages that imitated routine internal or Microsoft 365 notifications and were induced to enter their work credentials on a lookalike sign-in page. Hospital email is a high-yield target because clinical and billing staff exchange large volumes of patient-identifying correspondence with outside parties, so an unexpected message about a shared document or account issue does not stand out. With the harvested credentials the attacker signed in as the employee and had access to the full mailbox history. The activity resembled normal user logins, which is why detection depended on account anomaly review rather than malware alerts.",
      "lessons": "Enforcing phishing-resistant MFA and automatically expiring or archiving mailbox contents containing PHI would have both blocked the login and limited what a single compromised account exposed.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents",
          "url": "https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/",
          "publisher": "HIPAA Journal"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients"
    },
    {
      "title": "Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO",
      "date": "2025-03",
      "date_precision": "month",
      "victim_org": "Unnamed multinational firm, Singapore office",
      "sector": "Other",
      "country": "Singapore",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Business Email Compromise"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Singapore Police said deepfake technology was used to render the company's chief financial officer, chief executive and other officials during a Zoom video conference.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 499000,
      "loss_note": "Over US$499,000 transferred; funds recovered by Singapore and Hong Kong police within days",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.",
      "how_it_worked": "The approach opened on WhatsApp, a channel where an executive contact request feels informal but not alarming, and offered a business rationale, a confidential regional restructuring, that justified both secrecy and an unusual payment. The video conference supplied the decisive trust signal by putting the target in a room with the two most senior people in his reporting line plus other familiar faces. An outside lawyer and an NDA added procedural theatre that made the transaction look governed rather than improvised, while also formalising the instruction not to tell colleagues. Compliance was easy because the finance director was doing precisely his job, executing a payment approved by the CFO.",
      "lessons": "Payments authorised on a video call should still require callback verification to a directory-listed number and dual approval; the fast bank and police escalation here is what made recovery possible.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Singapore firm nearly lost $500,000 after deepfake video scam: police",
          "url": "https://www.hcamag.com/asia/specialisation/hr-technology/singapore-firm-nearly-lost-500000-after-deepfake-video-scam-police/531450",
          "publisher": "Human Resources Director Asia"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w",
      "year": 2025,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w"
    },
    {
      "title": "'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders",
      "date": "2025-03",
      "date_precision": "month",
      "victim_org": "Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully",
      "sector": "Cryptocurrency",
      "country": "Multiple",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Tech Support Scam"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The campaign used roughly 30 sock-puppet social media accounts and fabricated company websites; no confirmed use of AI-generated media was reported in the analyses reviewed.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "Security Alliance's incident log attributes millions of dollars of stolen funds to the group. No single confirmed per-victim figure was published in the reporting reviewed.",
      "records_affected": null,
      "threat_actor": "Elusive Comet, tracked by the Security Alliance and assessed as North Korea-linked",
      "summary": "From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.",
      "how_it_worked": "The lure was flattery with a business rationale: an investment conversation or an invitation onto a podcast, backed by around thirty sock-puppet accounts and fabricated corporate websites so that a quick check appeared to confirm the entity. On the call the attacker asked to screen share, then requested remote control. The critical trick was renaming their Zoom display name to 'Zoom' so that the permission prompt read as though it came from the application itself rather than from another participant. A victim clicking approve on what looked like a system dialog handed over interactive control of their machine, at which point infostealers or remote access trojans were installed and wallet material harvested. Tell-tale signs included consumer Zoom accounts used by supposed Bloomberg staff.",
      "lessons": "Disabling Zoom remote control at the account level, and treating any unsolicited investor or media approach that moves to screen control as hostile, removes the single click this campaign depends on.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "'Elusive Comet' Attackers Use Zoom to Swindle Victims",
          "url": "https://www.darkreading.com/remote-workforce/elusive-comet-zoom-victims",
          "publisher": "Dark Reading"
        },
        {
          "title": "North Korean Cryptocurrency Thieves Caught Hijacking Zoom 'Remote Control' Feature",
          "url": "https://www.securityweek.com/north-korean-cryptocurrency-thieves-caught-hijacking-zoom-remote-control-feature/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-elusive-comet-fake-vc-and-podcast-zoom-invites-drained-crypto-founders"
    },
    {
      "title": "Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI",
      "date": "2025-02-21",
      "date_precision": "day",
      "victim_org": "Bybit",
      "sector": "Cryptocurrency",
      "country": "United Arab Emirates",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": 1500000000,
      "loss_note": "Approximately 401,000 ETH and stETH, valued between roughly $1.4 billion and $1.5 billion at the time depending on the analysis. It is the largest cryptocurrency theft on record.",
      "records_affected": null,
      "threat_actor": "Lazarus Group / TraderTraitor (DPRK)",
      "summary": "On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.",
      "how_it_worked": "The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.",
      "lessons": "Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Lazarus hacked Bybit via breached Safe{Wallet} developer machine",
          "url": "https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "In-Depth Technical Analysis of the Bybit Hack",
          "url": "https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/",
          "publisher": "NCC Group"
        },
        {
          "title": "Sygnia's Investigation into the Bybit Hack: What We Know So Far",
          "url": "https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/",
          "publisher": "Sygnia"
        },
        {
          "title": "Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B Hack",
          "url": "https://www.coindesk.com/business/2025/02/26/bybit-and-safe-custody-blame-each-other-over-usd1-5b-hack",
          "publisher": "CoinDesk"
        },
        {
          "title": "How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist",
          "url": "https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa",
      "year": 2025,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa"
    },
    {
      "slug": "2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts",
      "title": "Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts",
      "date": "2025-02-13",
      "date_precision": "day",
      "year": 2025,
      "victim_org": "Multiple government, NGO, defence and energy organisations",
      "sector": "Government",
      "country": "Multiple",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Storm-2372 (assessed Russian-aligned)",
      "summary": "Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.",
      "how_it_worked": "The actor built rapport first, messaging targets over WhatsApp, Signal or Teams while posing as a prominent person relevant to the victim's work. It then sent what looked like an invitation to a Teams meeting or a document, containing a genuine Microsoft device code page and a code to type in. Because the sign-in page was real Microsoft infrastructure and the victim entered the code themselves, the flow looked entirely legitimate and MFA prompts appeared expected. Completing it issued the attacker valid access and refresh tokens for the victim's account, giving persistent mailbox and file access without ever handling a password.",
      "lessons": "Disable the device code authentication flow where it is not needed via Conditional Access, and train staff that a legitimate meeting invitation never requires typing a code into a separate sign-in page.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Storm-2372 conducts device code phishing campaign",
          "url": "https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",
          "publisher": "Microsoft Security"
        },
        {
          "title": "Phishing campaign targets Microsoft device-code authentication flows",
          "url": "https://www.cybersecuritydive.com/news/phishing-campaign-targets-microsoft-device-code-authentication-flows/740201/",
          "publisher": "Cybersecurity Dive"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts"
    },
    {
      "title": "AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman",
      "date": "2025-02",
      "date_precision": "month",
      "victim_org": "Massimo Moratti and other Italian business leaders",
      "sector": "Consumer",
      "country": "Italy",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Fraudsters used an AI-generated clone of Defence Minister Guido Crosetto's voice on phone calls, alongside accomplices posing as ministry staff.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 1000000,
      "loss_note": "Approx EUR 1 million paid by Massimo Moratti in two transfers; funds were traced to a Dutch bank account and frozen",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.",
      "how_it_worked": "The pretext was engineered for the target audience: a matter of national interest, secret by nature, in which wealthy patriots were being asked to advance funds the state would repay. Calls came first from someone presenting as a ministry official, which set the frame, and then from the minister himself in a recognisable synthetic voice, an escalation that made the request feel personally sanctioned at the highest level. The promise of Bank of Italy reimbursement reduced the perceived risk to a short-term loan. Secrecy and the lives of hostages supplied both urgency and a reason not to consult advisers, and payment was directed to a foreign account presented as an operational necessity.",
      "lessons": "Government officials do not solicit private funds by phone; any such request should be verified with the ministry's published switchboard before any transfer, and banks should challenge large first-time international transfers from personal accounts.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Police recover EUR 1M sent to deepfake scammers impersonating Italy's Defense Minister",
          "url": "https://cybernews.com/cybercrime/deepfake-scammers-dupe-italian-buinessman-1-million-police-recover-funds/",
          "publisher": "Cybernews"
        },
        {
          "title": "Fraudsters Allegedly Use AI-Generated Voice of Italian Defense Minister Guido Crosetto to Scam Business Leaders",
          "url": "https://incidentdatabase.ai/cite/927/",
          "publisher": "AI Incident Database"
        },
        {
          "title": "Guido Crosetto",
          "url": "https://en.wikipedia.org/wiki/Guido_Crosetto",
          "publisher": "Wikipedia"
        }
      ],
      "entry_type": "incident",
      "slug": "2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a",
      "year": 2025,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a"
    },
    {
      "title": "Hong Kong arrests 31 in second deepfake romance fraud ring targeting Southeast Asia",
      "date": "2025-01",
      "date_precision": "month",
      "victim_org": "Victims in Taiwan, Singapore and Malaysia",
      "sector": "Consumer",
      "country": "Hong Kong",
      "primary_vector": "Romance / Investment Scam",
      "secondary_vectors": [
        "Deepfake Video Call"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The syndicate combined photographs of attractive people scraped online with deepfake technology to create and sustain fictitious personas on dating apps.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft"
      ],
      "loss_usd": 4370000,
      "loss_note": "Over HK$34 million, approx US$4.37 million",
      "records_affected": null,
      "threat_actor": "Hong Kong-based fraud syndicate operating from Kowloon Bay",
      "summary": "Hong Kong police arrested 31 people on 2 and 3 January 2025 over a deepfake-enabled romance and investment fraud syndicate that operated from two premises in Kowloon Bay and took more than HK$34 million (about US$4.37 million) from victims in Taiwan, Singapore and Malaysia. Members were trained to approach targets on dating apps using online photographs of attractive people combined with deepfake technology. It was the second major deepfake fraud bust by Hong Kong authorities in three months.",
      "how_it_worked": "Recruits worked from scripts and training materials, opening on dating apps with fabricated female personas assembled from scraped photographs and rendered live with face-swapping software when a target asked for video proof. The romance was cultivated over weeks so that the eventual investment pitch arrived from someone the victim believed they knew personally rather than from a stranger. Targets in neighbouring jurisdictions were chosen partly because cross-border reporting and recovery are slower. Funds were routed into cryptocurrency, which made reversal difficult once the persona went dark.",
      "lessons": "Cross-border anti-fraud coordination and dating-platform detection of face-swap artefacts on live video are the two controls that materially shrink this model.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Hong Kong police arrest 31 over deepfakes used to scam victims in Singapore, Malaysia",
          "url": "https://www.scmp.com/news/hong-kong/law-and-crime/article/3293476/hong-kong-police-arrest-31-who-used-deepfakes-scam-victims-singapore-malaysia",
          "publisher": "South China Morning Post"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou",
      "year": 2025,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou"
    },
    {
      "slug": "2025-vc-firm-insight-partners-breached-through-social-engineering-attack",
      "title": "VC firm Insight Partners breached through social engineering attack",
      "date": "2025-01",
      "date_precision": "month",
      "year": 2025,
      "victim_org": "Insight Partners",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.",
      "how_it_worked": "Insight Partners stated publicly that the intrusion was the result of a social engineering attack rather than an exploited vulnerability. Investment firms are a high-value pretext environment: staff routinely exchange documents and wire instructions with founders, co-investors, lawyers and limited partners they have never met in person, so an approach from an unfamiliar sender referencing a live deal reads as normal. The attackers used that trust to obtain access to internal systems, then spent time collecting fund-level financial data, banking and tax details for individuals, and transaction records, before the activity was detected and remediated.",
      "lessons": "For deal-driven firms, phishing-resistant MFA plus verified out-of-band confirmation for any document or credential request from outside the firm is the control that matters.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Statement from Insight Partners on Cyber Incident",
          "url": "https://www.insightpartners.com/ideas/statement-from-insight-partners-on-cyber-incident/",
          "publisher": "Insight Partners"
        },
        {
          "title": "VC giant Insight Partners notifies staff and limited partners after data breach",
          "url": "https://techcrunch.com/2025/09/17/vc-giant-insight-partners-notifies-staff-and-limited-partners-after-data-breach/",
          "publisher": "TechCrunch"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-vc-firm-insight-partners-breached-through-social-engineering-attack"
    },
    {
      "title": "ClickFix fake-CAPTCHA social engineering floods the threat landscape",
      "date": "2025",
      "date_precision": "year",
      "victim_org": "Multiple organisations and consumers (technique)",
      "sector": "Other",
      "country": "Multiple",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [
        "Tech Support Scam",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Some ClickFix lure pages and follow-on infrastructure have been reported as AI-assisted in their construction, but Proofpoint's reporting does not confirm AI involvement in the technique itself.",
      "outcomes": [
        "Credential Theft",
        "Ransomware Deployment",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure; this entry documents a technique adopted across many criminal and state-linked actors rather than a single victim.",
      "records_affected": null,
      "threat_actor": "Multiple, including cybercriminal and state-aligned groups tracked by Proofpoint",
      "summary": "Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.",
      "how_it_worked": "The victim reaches a page, often through malvertising, a compromised site, a search result or an emailed link, that presents a plausible obstacle: 'verify you are human', 'this document failed to load, run the fix', or a fake Chrome update error. Instructions walk the user through pressing Windows+R, pressing Ctrl+V and pressing Enter. The clipboard has already been populated by JavaScript with a PowerShell or mshta command, frequently padded with whitespace so the malicious portion is scrolled out of view in the Run box. Executing it downloads and runs the payload under the user's own privileges, sidestepping email attachment scanning, macro blocking and download reputation checks entirely because the user is the delivery mechanism.",
      "lessons": "Disable or monitor the Run dialog through policy, alert on clipboard-sourced script execution, and train staff on the single unambiguous rule that no legitimate website ever asks you to paste a command into your operating system.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape",
          "url": "https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape",
          "publisher": "Proofpoint"
        },
        {
          "title": "Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware",
          "url": "https://securityonline.info/deceptive-captcha-clickfix-campaign-uses-clipboard-injection-to-deliver-malware/",
          "publisher": "SecurityOnline"
        },
        {
          "title": "Inside ClickFix: How Fake Prompts Took Over the Web",
          "url": "https://netlas.io/blog/fake_prompts/",
          "publisher": "Netlas"
        }
      ],
      "entry_type": "campaign",
      "slug": "2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape",
      "year": 2025,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape"
    },
    {
      "title": "FBI warns criminals are using generative AI to scale voice-clone and identity fraud",
      "date": "2024-12-03",
      "date_precision": "day",
      "victim_org": "US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Deepfake Video Call",
        "Romance / Investment Scam",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The entire advisory concerns criminal use of generative AI: AI text for phishing and fake profiles, AI images for fake IDs and personas, voice cloning to impersonate relatives and account holders, and real-time video synthesis to impersonate executives and authorities.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Extortion",
        "Cryptocurrency Theft"
      ],
      "loss_usd": null,
      "loss_note": "The advisory does not publish an aggregate loss figure for AI-enabled fraud.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.",
      "how_it_worked": "Voice cloning is the pivotal technique for consumer harm. A short sample of a person's speech, readily available from social media video, is enough to synthesise a distressed relative calling to say they have been in an accident or arrested and need money immediately. The lever is the recognisable voice of a loved one under duress, which suppresses verification instincts far more effectively than any script. The same technology is used to satisfy bank voice authentication as an account holder, and real-time video synthesis extends it to live calls impersonating executives or providing proof of legitimacy to a romance or investment target. AI translation also strips the grammatical errors that once exposed foreign operators.",
      "lessons": "The FBI's own recommendation is the practical control: agree a family or organisational verification code word in advance, and independently call back on a known number before acting on any urgent request.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud",
          "url": "https://www.ic3.gov/PSA/2024/PSA241203",
          "publisher": "FBI Internet Crime Complaint Center"
        }
      ],
      "entry_type": "benchmark",
      "slug": "2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide"
    },
    {
      "title": "Deepfake Elon Musk videos drive crypto investment scams against US consumers",
      "date": "2024-11",
      "date_precision": "month",
      "victim_org": "Multiple US consumers",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [
        "Romance / Investment Scam",
        "Deepfake Video Call"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Scammers generated AI video and voice of Elon Musk pitching cryptocurrency investment schemes and distributed them as ads and posts on Facebook and TikTok.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft"
      ],
      "loss_usd": null,
      "loss_note": "Individual victim Heidi Swan lost over US$10,000; Deloitte estimated generative AI contributed to more than US$12 billion in US fraud losses in 2023, projected to reach US$40 billion by 2027",
      "records_affected": null,
      "threat_actor": null,
      "summary": "By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.",
      "how_it_worked": "The lure ran on the credibility of a single very famous investor whose views on cryptocurrency are widely known, so a video of him endorsing a platform confirmed what many targets already half-believed. Distribution through paid social advertising delivered the content inside trusted feeds and let operators target older users with disposable savings. The synthetic Musk described a limited-time opportunity with outsized returns, and the follow-through moved victims onto a bogus exchange with a support representative who coached them through funding the account. Fabricated balance growth and, in some cases, small permitted withdrawals sustained belief and encouraged larger deposits until withdrawals were blocked.",
      "lessons": "Celebrity endorsement is never a basis for investing; platforms must verify advertiser identity and screen for synthetic likeness of public figures before ads run.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Deepfakes of Elon Musk are contributing to billions of dollars in fraud losses in the U.S.",
          "url": "https://www.cbsnews.com/texas/news/deepfakes-ai-fraud-elon-musk/",
          "publisher": "CBS News"
        },
        {
          "title": "Deepfake Elon Musk Videos Have Reportedly Contributed to Billions in Fraud",
          "url": "https://incidentdatabase.ai/cite/795/",
          "publisher": "AI Incident Database"
        }
      ],
      "entry_type": "campaign",
      "slug": "2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu"
    },
    {
      "title": "Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport",
      "date": "2024-10",
      "date_precision": "month",
      "victim_org": "Wiz",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Attackers built a voice clone of chief executive Assaf Rappaport from audio of a conference talk and sent synthetic voice messages to dozens of employees seeking their credentials.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.",
      "how_it_worked": "The attackers scaled a single cloned sample across dozens of recipients, betting that at least one employee would act on what sounded like a direct request from the chief executive. Voice messages rather than live calls removed the risk of interactive questions and let the same recording be reused, while the boss's authority supplied the pressure to comply quickly with a credential request. The flaw was in the source material: the only clean public audio was a conference keynote, so the clone inherited a projected, presentational tone that colleagues who hear Rappaport daily immediately found off. Employees compared notes and reported the messages rather than responding.",
      "lessons": "Credential requests should never be actionable from a voice message, and mass-distribution patterns across many employees should trigger automated correlation and alerting.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Wiz CEO says company was targeted with deepfake attack that used his voice",
          "url": "https://techcrunch.com/2024/10/28/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Hackers Sent a Deepfake of Wiz CEO to Dozens of Employees",
          "url": "https://www.entrepreneur.com/business-news/hackers-sent-a-deepfake-of-wiz-ceo-to-dozens-of-employees/482027",
          "publisher": "Entrepreneur"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa"
    },
    {
      "title": "Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring",
      "date": "2024-10",
      "date_precision": "month",
      "victim_org": "Men across Asia targeted through dating apps",
      "sector": "Consumer",
      "country": "Hong Kong",
      "primary_vector": "Romance / Investment Scam",
      "secondary_vectors": [
        "Deepfake Video Call"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Syndicate members used AI face-swapping to replace their own faces with those of attractive women during video calls with victims, sustaining the fiction of a relationship.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft"
      ],
      "loss_usd": 46000000,
      "loss_note": "HK$360 million, approx US$46 million",
      "records_affected": null,
      "threat_actor": "Hong Kong-based syndicate with reported triad links",
      "summary": "Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.",
      "how_it_worked": "Operators opened on dating apps with AI-generated or face-swapped profiles of attractive women and invested weeks in ordinary conversation, building an emotional bond before money was ever mentioned. Video calls were the decisive trust signal, because a target who has seen and spoken with the person on camera discounts warnings about catfishing. Once the relationship felt real, the persona introduced a cryptocurrency trading platform run by the syndicate, showing fabricated gains and letting small withdrawals succeed so the returns appeared genuine. Pressure came from a mixture of intimacy and fear of missing out, and the training documents seized by police show the manipulation was scripted, not improvised.",
      "lessons": "Reverse-image and liveness checks on dating profiles help, but the durable control is treating any investment platform introduced by an online romantic contact as fraudulent by default.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Hong Kong fraudsters use deepfake tech to swindle love-struck men out of HK$360 million",
          "url": "https://www.scmp.com/news/hong-kong/law-and-crime/article/3282345/hong-kong-fraudsters-use-deepfake-tech-swindle-love-struck-men-out-hk360-million",
          "publisher": "South China Morning Post"
        },
        {
          "title": "Police arrest 27 for deepfake love scams totaling $360m, seizes scam-training documents",
          "url": "https://www.thestandard.com.hk/news/article/221507/Police-arrest-27-for-deepfake-love-scams-totaling-360m-seizes-scam-training-documents",
          "publisher": "The Standard (Hong Kong)"
        }
      ],
      "entry_type": "campaign",
      "slug": "2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen",
      "year": 2024,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen"
    },
    {
      "title": "DPRK actor posing as a former contractor took $50M from Radiant Capital",
      "date": "2024-10",
      "date_precision": "month",
      "victim_org": "Radiant Capital",
      "sector": "Cryptocurrency",
      "country": "Unknown",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI-generated media was reported; the impersonation relied on a spoofed contractor domain and an existing working relationship.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 50000000,
      "loss_note": "Approximately $50 million, with stolen funds moved on October 24, 2024. Radiant Capital later wound down operations.",
      "records_affected": null,
      "threat_actor": "UNC4736 / Citrine Sleet (DPRK-nexus), assessed with high confidence by Mandiant",
      "summary": "Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.",
      "how_it_worked": "The pretext worked because the sender was someone the team already knew and the ask, review this document, was ordinary. The ZIP contained a decoy PDF that opened normally while a macOS backdoor installed behind it, and because the developer forwarded the file to colleagues for their input, the compromise multiplied across the signer group. With malware on multiple developer machines, the attackers manipulated what those machines displayed: front-end interfaces and simulation tools such as Tenderly showed benign transaction data while malicious transactions were being signed underneath. Radiant noted that traditional checks and simulations showed no obvious discrepancies, so the review process that should have caught the theft confirmed it instead.",
      "lessons": "Signing must happen on dedicated, hardened devices that do nothing else, with the transaction independently verified on separate hardware, because once the reviewer's endpoint is compromised, on-screen verification is worthless.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Radiant Capital says North Korea posed as ex-contractor to carry out $50M hack",
          "url": "https://cointelegraph.com/news/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack",
          "publisher": "Cointelegraph"
        },
        {
          "title": "Radiant Capital Says DPRK Actor Posed as Ex-Contractor to Pull Off $50 Million Hack",
          "url": "https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack",
          "publisher": "Decrypt"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital"
    },
    {
      "title": "Transport for London hit by Scattered Spider teens in a £29m intrusion",
      "date": "2024-09-01",
      "date_precision": "day",
      "victim_org": "Transport for London",
      "sector": "Transportation & Logistics",
      "country": "United Kingdom",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Service Disruption",
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": 39000000,
      "loss_note": "TfL put the cost at about £29 million (roughly $39 million); prosecutors said a complete shutdown could have caused up to £56 billion of economic damage.",
      "records_affected": null,
      "threat_actor": "Scattered Spider; Thalha Jubair and Owen Flowers were each sentenced to five and a half years in July 2026",
      "summary": "Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.",
      "how_it_worked": "TfL has not published the entry vector, and the prosecution described Scattered Spider's general reliance on phone, email and SMS social engineering rather than a specific script for this intrusion. What the response reveals is the assumption TfL made about the attackers' capability: the organisation judged that remote password resets could themselves be abused, and required roughly 27,000 staff to attend in person with identity documents to re-establish credentials. That is the signature countermeasure to help-desk impersonation, adopted precisely because remote identity proofing could no longer be trusted.",
      "lessons": "In-person or strongly verified credential re-issuance for staff, and phishing-resistant MFA for remote administrative access, are the controls TfL was forced to adopt reactively.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Transport for London (TfL) is dealing with an ongoing cyberattack",
          "url": "https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack",
          "url": "https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion",
      "year": 2024,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion"
    },
    {
      "title": "US Senator Ben Cardin targeted by deepfake Zoom call posing as Ukraine's ex-FM",
      "date": "2024-09",
      "date_precision": "month",
      "victim_org": "Office of US Senator Ben Cardin, Senate Foreign Relations Committee",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Senate security officials described the video call participant as an apparent deepfake of former Ukrainian foreign minister Dmytro Kuleba that matched his appearance and voice from prior encounters.",
      "outcomes": [
        "Attempt Blocked",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In September 2024 the office of Senator Ben Cardin, then chair of the Senate Foreign Relations Committee, received an email purporting to be from former Ukrainian foreign minister Dmytro Kuleba requesting a call. On the resulting Zoom call the person looked and sounded like Kuleba but began aggressively pressing Cardin for positions on politically charged issues, including long-range missile strikes into Russian territory and comments touching on US presidential candidates. Cardin's staff ended the call and the State Department confirmed it was not Kuleba. The Senate security office warned other offices about the attempt's sophistication.",
      "how_it_worked": "The pretext exploited a routine of the job: a foreign official Cardin had genuinely met requesting a follow-up video call on a live policy question. Because the identity was plausible and the scheduling followed normal staff channels, the meeting went ahead without independent verification through the State Department. On camera the deepfake supplied the visual and vocal confirmation staff expected. The impersonator then pushed for on-the-record statements that could be clipped and weaponised, applying pressure by demanding immediate answers. The tell was behavioural rather than technical: the real Kuleba would not badger a committee chair for soundbites, and the mismatch in conduct ended the call.",
      "lessons": "Legislative offices should route requests for meetings with foreign officials through the State Department or the relevant embassy for confirmation before a call is scheduled.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Ben Cardin targeted in apparent deepfake call with someone posing as Dmytro Kuleba",
          "url": "https://www.nbcnews.com/politics/congress/ben-cardin-targeted-apparent-deep-fake-call-dmytro-kuleba-rcna172776",
          "publisher": "NBC News"
        },
        {
          "title": "Elaborate Deepfake Operation Takes a Meeting With US Senator",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/elaborate-deepfake-operation-meeting-us-senator",
          "publisher": "Dark Reading"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-us-senator-ben-cardin-targeted-by-deepfake-zoom-call-posing-as-ukraine-s"
    },
    {
      "title": "Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin",
      "date": "2024-08-19",
      "date_precision": "day",
      "victim_org": "An individual Genesis creditor in Washington, D.C.",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Tech Support Scam",
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No voice cloning or synthetic media was reported; the callers used spoofed caller ID and live pretexting.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 243000000,
      "loss_note": "4,064 BTC, worth approximately $243 million at the time. More than $9 million was subsequently frozen and about $500,000 returned to the victim.",
      "records_affected": null,
      "threat_actor": "Malone Lam ('Greavys'), Jeandiel Serrano ('VersaceGod') and co-conspirators",
      "summary": "On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.",
      "how_it_worked": "The crew opened with a spoofed call presenting as Google support warning of unauthorised account access, which established urgency and a reason for the victim to accept further contact. A second set of callers then posed as Gemini support and walked the victim through resetting the two-factor authentication on the exchange account. Under the guise of remediation, they had the victim install AnyDesk and share their screen, at which point the attackers were able to see private keys held in the victim's Bitcoin Core wallet and to direct transfers to a wallet they controlled. Funds were then split across many wallets and pushed through more than fifteen exchanges. The crew's spending on cars, watches and designer goods exposed an address that let investigators freeze over $9 million.",
      "lessons": "No legitimate provider initiates a call asking you to reset MFA or install remote-desktop software; hanging up and calling back on a number obtained independently is the single control that defeats this entire sequence.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Police Arrest Two People Related to $243M Crypto Heist Targeting Genesis Creditor",
          "url": "https://www.coindesk.com/business/2024/09/19/police-arrests-two-people-related-to-243m-crypto-heist-targeting-genesis-creditor",
          "publisher": "CoinDesk"
        },
        {
          "title": "Hackers Posed as Google Support to Steal $243 Million in Crypto",
          "url": "https://hackread.com/hackers-posed-google-support-steal-243m-crypto/",
          "publisher": "Hackread"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-fake-google-and-gemini-support-calls-cost-a-genesis-creditor-243m-in-bit"
    },
    {
      "title": "Iran's APT42 phishes Israeli and US officials with think-tank impersonation",
      "date": "2024-08-14",
      "date_precision": "day",
      "victim_org": "Current and former Israeli and US government officials, diplomats and political campaign staff",
      "sector": "Government",
      "country": "Israel and United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "No monetary loss; the objective was intelligence collection.",
      "records_affected": null,
      "threat_actor": "APT42 / Charming Kitten (Iranian IRGC-linked)",
      "summary": "On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.",
      "how_it_worked": "APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.",
      "lessons": "High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Iranian backed group steps up phishing campaigns against Israel, U.S.",
          "url": "https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/",
          "publisher": "Google Threat Analysis Group"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat"
    },
    {
      "title": "Orion S.A. discloses $60 million loss from fraudulently induced wire transfers",
      "date": "2024-08-10",
      "date_precision": "day",
      "victim_org": "Orion S.A.",
      "sector": "Manufacturing",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "The company's SEC filing did not describe the impersonation technique or state whether AI-generated media was involved.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 60000000,
      "loss_note": "Approximately $60 million one-time pre-tax charge for unrecovered fraudulent transfers, per the company's Form 8-K. Orion said it would pursue recovery including through insurance.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Chemicals maker Orion S.A. disclosed in a Form 8-K filed August 12, 2024 that on August 10, 2024 it determined an employee who is not a named executive officer had been targeted by a criminal scheme resulting in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. The company expected to record a one-time pre-tax charge of roughly $60 million for unrecovered funds and said it would pursue recovery, including through available insurance.",
      "how_it_worked": "The disclosure describes the standard structure of a corporate payment-diversion fraud: a single employee inside the payments process was deceived into initiating a series of outbound wires rather than one large transfer, which keeps individual amounts within familiar approval bands and spreads them across banking cutoffs. The recipients were accounts controlled by unidentified third parties, consistent with mule networks that disperse funds quickly across jurisdictions. Orion identified the scheme after the transfers had been executed, concluded the loss was unrecoverable enough to book a $60 million charge, and reported that its systems and financial reporting controls were otherwise unaffected, indicating deception of a person rather than a technical compromise.",
      "lessons": "Payment initiation by a single employee is a structural weakness; enforced dual authorization plus out-of-band verification and velocity alerting on new beneficiaries would have interrupted the sequence.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Orion S.A. Form 8-K, Item 8.01 (filed August 12, 2024)",
          "url": "https://www.sec.gov/Archives/edgar/data/1609804/000095014224002170/eh240519238_8k.htm",
          "publisher": "U.S. Securities and Exchange Commission (EDGAR)"
        },
        {
          "title": "Scammers dupe chemical company into wiring $60 million",
          "url": "https://www.helpnetsecurity.com/2024/08/13/orion-fraudulent-wire-transfers-60-million/",
          "publisher": "Help Net Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-orion-s-a-discloses-60-million-loss-from-fraudulently-induced-wire-trans",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-orion-s-a-discloses-60-million-loss-from-fraudulently-induced-wire-trans"
    },
    {
      "slug": "2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5",
      "title": "Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients",
      "date": "2024-07-30",
      "date_precision": "day",
      "year": 2024,
      "victim_org": "Michigan Medicine (University of Michigan)",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "MFA Fatigue / Push Bombing",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 57891,
      "threat_actor": null,
      "summary": "Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.",
      "how_it_worked": "The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.",
      "lessons": "Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Michigan Medicine notifies patients of health information breach",
          "url": "https://www.michiganmedicine.org/news-release/michigan-medicine-notifies-patients-health-information-breach-3",
          "publisher": "Michigan Medicine"
        },
        {
          "title": "Michigan Medicine email breach exposes patient information",
          "url": "https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/michigan-medicine-email-breach-exposes-patient-information/",
          "publisher": "Becker's Hospital Review"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5"
    },
    {
      "title": "WazirX signers approved a spoofed transaction and lost $235M",
      "date": "2024-07-18",
      "date_precision": "day",
      "victim_org": "WazirX",
      "sector": "Cryptocurrency",
      "country": "India",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 234900000,
      "loss_note": "Approximately $234.9 million in ETH and ERC-20 tokens at the value on July 18, 2024. WazirX and custody provider Liminal publicly disagreed over which side's systems were compromised.",
      "records_affected": null,
      "threat_actor": "Lazarus Group (DPRK), per multiple third-party analyses",
      "summary": "Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.",
      "how_it_worked": "The signers were the target, and the deception was in what their screens showed them. Analyses of the incident found a discrepancy between how the transaction was rendered in the Liminal custody interface and the actual payload being signed: signers reviewed what appeared to be a routine, whitelisted transfer while the underlying data authorised a malicious contract upgrade. Three WazirX signers and the Liminal signer approved it, satisfying the four-of-six threshold. Because the approval was cryptographically valid, address whitelisting, hardware wallet storage and the multisig scheme itself all passed cleanly, and the attacker gained control to drain the remaining balance without needing any further key.",
      "lessons": "Signers need to verify transaction payloads on an independent, out-of-band device that renders the raw calldata, since any control that trusts the same interface the attacker can influence provides no assurance at all.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "2024 WazirX hack",
          "url": "https://en.wikipedia.org/wiki/2024_WazirX_hack",
          "publisher": "Wikipedia"
        },
        {
          "title": "Explained: The WazirX Hack (July 2024)",
          "url": "https://www.halborn.com/blog/post/explained-the-wazirx-hack-july-2024",
          "publisher": "Halborn"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m"
    },
    {
      "title": "KnowBe4 hired a North Korean fake IT worker who loaded malware on day one",
      "date": "2024-07-15",
      "date_precision": "day",
      "victim_org": "KnowBe4",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The candidate's profile photo was a stock image manipulated with AI to match a stolen US identity, and KnowBe4 described the persona as an AI deepfake that held up across four video interviews.",
      "outcomes": [
        "Attempt Blocked",
        "Insider Access"
      ],
      "loss_usd": null,
      "loss_note": "No loss occurred. KnowBe4 stated no data was accessed and no systems were compromised.",
      "records_affected": null,
      "threat_actor": "DPRK state-sponsored fake IT worker, confirmed with Mandiant and the FBI",
      "summary": "Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.",
      "how_it_worked": "The persona was assembled rather than invented: a real US person's identity supplied the details that background and reference checks validated, and a stock photograph enhanced with AI supplied a face consistent enough to survive four video calls. The shipping address was not a home but an IT mule laptop farm, so the corporate workstation arrived at a location that would keep it online in the US while the operative connected in by VPN from North Korea or nearby, working nights to match US hours. Within minutes of receipt the operative used a Raspberry Pi to download malware onto the workstation and began manipulating session history files. Challenged by the SOC, they claimed router troubleshooting, then went silent.",
      "lessons": "Live identity verification against the government ID during interviews, plus device shipment to a verified address and endpoint monitoring that treats day-one activity as high-risk, are what turned this into a contained incident rather than a breach.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "How a North Korean Fake IT Worker Tried to Infiltrate Us",
          "url": "https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us",
          "publisher": "KnowBe4"
        },
        {
          "title": "KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware",
          "url": "https://www.securityweek.com/knowbe4-hires-fake-north-korean-it-worker-catches-new-employee-planting-malware/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Cyber firm KnowBe4 hired a fake IT worker from North Korea",
          "url": "https://cyberscoop.com/cyber-firm-knowbe4-hired-a-fake-it-worker-from-north-korea/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on"
    },
    {
      "title": "Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question",
      "date": "2024-07",
      "date_precision": "month",
      "victim_org": "Ferrari",
      "sector": "Manufacturing",
      "country": "Italy",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The caller used a synthetic voice that reproduced chief executive Benedetto Vigna's southern Italian accent; the target noticed slightly mechanical intonation.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.",
      "how_it_worked": "The approach started on WhatsApp from an unfamiliar number, with the mismatch explained away by the claim that the deal was so sensitive it required a separate line, a pretext that turns a red flag into evidence of importance. The escalation to a voice call added the strongest trust signal available, the chief executive's distinctive accent and manner discussing an unannounced acquisition. Confidentiality supplied the reason not to consult anyone, and a currency hedge gave a technical, plausible-sounding financial action. The executive interrupted the frame by asking a shared-knowledge question with no public answer, which the synthetic caller could not handle.",
      "lessons": "A pre-agreed challenge based on shared private knowledge, or a codeword for executive payment requests, reliably breaks a voice clone that cannot improvise.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Ferrari narrowly dodges deepfake scam simulating deal-hungry CEO",
          "url": "https://www.spokesman.com/stories/2024/jul/26/ferrari-narrowly-dodges-deepfake-scam-simulating-d/",
          "publisher": "Bloomberg via The Spokesman-Review"
        },
        {
          "title": "Ferrari CEO Deepfake Shows Growing Threat of AI Scams Impersonating Executives",
          "url": "https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo",
          "publisher": "Bloomberg"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu"
    },
    {
      "title": "Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta",
      "date": "2024-05-15",
      "date_precision": "day",
      "victim_org": "Multiple organisations (campaign)",
      "sector": "Other",
      "country": "Multiple",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Tech Support Scam",
        "Callback Phishing (TOAD)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "Microsoft reported live human callers, not synthetic voice.",
      "outcomes": [
        "Ransomware Deployment",
        "Extortion",
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure published for the campaign.",
      "records_affected": null,
      "threat_actor": "Storm-1811, deploying Black Basta ransomware",
      "summary": "Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.",
      "how_it_worked": "The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.",
      "lessons": "Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Threat actors misusing Quick Assist in social engineering attacks leading to ransomware",
          "url": "https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/",
          "publisher": "Microsoft Security Blog"
        },
        {
          "title": "Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing",
          "url": "https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing",
          "publisher": "Sophos"
        },
        {
          "title": "Windows Quick Assist Anchors Black Basta Ransomware Gambit",
          "url": "https://www.darkreading.com/threat-intelligence/windows-quick-assist-anchors-black-basta-ransomware",
          "publisher": "Dark Reading"
        }
      ],
      "entry_type": "campaign",
      "slug": "2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"
    },
    {
      "slug": "2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou",
      "title": "Ascension ransomware attack began when an employee downloaded a malicious file",
      "date": "2024-05-08",
      "date_precision": "day",
      "year": 2024,
      "victim_org": "Ascension",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Watering Hole / Malvertising"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Ransomware Deployment",
        "Data Breach",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 5600000,
      "threat_actor": "Black Basta (reported)",
      "summary": "Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.",
      "how_it_worked": "A staff member downloaded a file to a work computer in the belief that it was legitimate, which is the form of compromise that has largely replaced the classic attachment: the user is looking for something, a document, an update, a utility, and takes delivery of malware from what appears to be an ordinary source. That single endpoint gave the operators their foothold in a health system spanning 140 hospitals, where the pressure to keep clinical systems continuously available works against aggressive segmentation. The attackers reached and exfiltrated data from seven servers before deploying encryption, forcing weeks of downtime procedures across the network.",
      "lessons": "Application allowlisting and blocking user-initiated downloads of executables on clinical endpoints, combined with segmentation, are what keep one mistaken download from stopping 140 hospitals.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Ascension hacked after employee downloaded malicious file",
          "url": "https://www.bleepingcomputer.com/news/security/ascension-hacked-after-employee-downloaded-malicious-file/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Ascension cyberattack exposes data from 5.6 million people",
          "url": "https://www.healthcaredive.com/news/ascension-cyberattack-data-breach-5-6-million/736167/",
          "publisher": "Healthcare Dive"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou"
    },
    {
      "title": "WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read",
      "date": "2024-05",
      "date_precision": "month",
      "victim_org": "WPP",
      "sector": "Media & Entertainment",
      "country": "United Kingdom",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Voice Clone / Audio Deepfake",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Attackers set up a WhatsApp account using a publicly available image of chief executive Mark Read, then ran a Microsoft Teams meeting using YouTube footage of him alongside an AI voice clone.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.",
      "how_it_worked": "The pretext was a new business opportunity that a chief executive might plausibly want to explore quietly with one trusted agency leader, which explained both the confidentiality and the unusual approach. The attackers assembled several weak trust signals into a convincing whole: a WhatsApp profile with Read's real photo, a Teams invite from an apparently senior source, video that showed his face and a synthetic voice on the line, and chat messages written in his persona. The technical staging papered over the gaps, with camera and audio problems used to explain why the video looked like recorded footage. The target was asked to move on money and personal information without touching normal corporate process.",
      "lessons": "Verifying meeting invitations through the corporate directory rather than a messaging-app contact, and refusing to progress financial arrangements outside standard process, are what stopped this.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "CEO of world's biggest ad firm targeted by deepfake scam",
          "url": "https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam",
          "publisher": "The Guardian"
        },
        {
          "title": "Scammers Reportedly Used AI Voice Clone and YouTube Footage to Impersonate WPP CEO",
          "url": "https://incidentdatabase.ai/cite/983/",
          "publisher": "AI Incident Database"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark"
    },
    {
      "title": "LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft",
      "date": "2024-05",
      "date_precision": "month",
      "victim_org": "DMM Bitcoin, via wallet software vendor Ginco",
      "sector": "Cryptocurrency",
      "country": "Japan",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported in the joint FBI, DC3 and NPA advisory.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": 308000000,
      "loss_note": "4,502.9 BTC, valued at approximately $308 million in the joint FBI/DC3/NPA advisory; Japanese reporting at the time cited roughly $305 million. DMM Bitcoin subsequently wound down, transferring assets to SBI VC Trade.",
      "records_affected": null,
      "threat_actor": "TraderTraitor (DPRK), per FBI, DC3 and Japan's National Police Agency",
      "summary": "Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.",
      "how_it_worked": "The recruiter pretext delivered a malicious Python script hosted on GitHub, framed as a pre-employment coding assessment. The Ginco employee copied the script into their own GitHub account to work on it, which handed the attacker access to session cookie data. Using those session cookies the attacker impersonated the employee and compromised Ginco's unencrypted internal communications system. From there they waited: in late May a DMM Bitcoin employee submitted a legitimate transaction request through Ginco's system, and the attacker altered it in flight so that the withdrawal, which carried valid authorisation from DMM's side, sent 4,502.9 BTC to attacker-controlled addresses.",
      "lessons": "Take-home coding tasks must be isolated from corporate identity and never touched by an account with production session access, and transaction requests should be verified against an independent channel between exchange and custody vendor before signing.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com",
          "url": "https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom",
          "publisher": "Federal Bureau of Investigation"
        },
        {
          "title": "FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin",
          "url": "https://cryptoslate.com/fbi-reveals-north-korea-used-linkedin-to-steal-305-million-from-japans-dmm-bitcoin/",
          "publisher": "CryptoSlate"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t"
    },
    {
      "title": "Unpaid toll smishing wave sweeps US states, FBI logs 2,000 reports in weeks",
      "date": "2024-04-12",
      "date_precision": "day",
      "victim_org": "US drivers and toll customers (multi-victim campaign)",
      "sector": "Transportation & Logistics",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The IC3 alert does not attribute the campaign to AI tooling.",
      "outcomes": [
        "Identity Theft",
        "Wire Fraud / Financial Loss",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "IC3 did not publish an aggregate loss figure for the toll smishing campaign.",
      "records_affected": 2000,
      "threat_actor": null,
      "summary": "On 12 April 2024 the FBI's Internet Crime Complaint Center issued an alert about a nationwide smishing campaign impersonating state toll services. IC3 had received more than 2,000 complaints since early March 2024 referencing toll collection texts from at least three states. The messages used consistent language and amounts across states, and pointed to fake websites impersonating legitimate tolling agencies with phone numbers varied by state.",
      "how_it_worked": "Recipients received a text stating that an outstanding toll amount of $12.51 had been noticed on their record and that visiting a link would settle the balance and avoid a $50 late fee. The lever is a small, plausible, low-stakes debt: the sum is too trivial to warrant checking with the tolling authority, and the late fee creates just enough urgency to act immediately. The linked site cloned the state tolling agency's branding and collected card details and personal information for payment fraud and identity theft. Attackers rotated the impersonated agency by recipient area code, so the message named a tolling authority the target plausibly uses.",
      "lessons": "Never transact from a link in an unsolicited text; navigate to the tolling agency independently. Carrier-level detection of newly registered look-alike tolling domains is the scalable control.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Smishing Scam Regarding Debt for Road Toll Services",
          "url": "https://www.ic3.gov/PSA/2024/PSA240412",
          "publisher": "FBI Internet Crime Complaint Center"
        }
      ],
      "entry_type": "campaign",
      "slug": "2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-unpaid-toll-smishing-wave-sweeps-us-states-fbi-logs-2-000-reports-in-wee"
    },
    {
      "title": "Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs",
      "date": "2024-04-01",
      "date_precision": "day",
      "victim_org": "Cisco Duo (via an unnamed telephony supplier)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.",
      "how_it_worked": "The attack did not target Duo at all; it targeted the intermediary that physically delivers Duo's SMS one-time codes, an organisation most Duo customers had never heard of. A single employee's credentials were enough to reach the message log store. The stolen data is second-order ammunition rather than direct access: knowing which phone number belongs to which enterprise user, on which carrier, and when they authenticate, is precisely what a SIM-swap or help-desk-impersonation crew needs to build a convincing call and to time it against a real login.",
      "lessons": "Move off SMS as an MFA channel where possible, and require phishing-resistant authentication and log-access controls from downstream communications suppliers.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Cisco Duo warns telephony supplier data breach exposed MFA SMS logs",
          "url": "https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs"
    },
    {
      "title": "LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO",
      "date": "2024-04",
      "date_precision": "month",
      "victim_org": "LastPass",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Smishing (SMS)",
        "Business Email Compromise"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.",
      "how_it_worked": "The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.",
      "lessons": "A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Attempted Audio Deepfake Call Targets LastPass Employee",
          "url": "https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee",
          "publisher": "LastPass"
        },
        {
          "title": "LastPass: Hackers targeted employee in failed deepfake CEO call",
          "url": "https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "LastPass employee targeted via an audio deepfake call",
          "url": "https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"
    },
    {
      "title": "Munchables loses $62.5M to a developer it hired who was linked to North Korea",
      "date": "2024-03-26",
      "date_precision": "day",
      "victim_org": "Munchables (NFT game on Blast)",
      "sector": "Cryptocurrency",
      "country": "Unknown",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Insider Access"
      ],
      "loss_usd": 62500000,
      "loss_note": "About $62.5 million in ether at the time of the exploit. All funds were recovered after the developer surrendered the private keys without a ransom being paid.",
      "records_affected": null,
      "threat_actor": "A developer using the GitHub handle 'Werewolves0493', assessed by investigator ZachXBT as North Korea-linked",
      "summary": "Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.",
      "how_it_worked": "This was infiltration rather than intrusion: the attacker was hired. Working as a Munchables developer with contract-deployment privileges, they positioned control of stored user funds ahead of a scheduled contract upgrade, then transferred those funds to themselves before the upgrade landed, so the movement looked like part of routine deployment activity. ZachXBT's analysis of GitHub commit timing and cross-referenced accounts suggested the developer was part of a cluster of DPRK-linked personas that had recommended one another into crypto projects, meaning the vetting failure compounded across multiple hires. Recovery came from negotiation, not from any control the project held.",
      "lessons": "Live identity verification, tied to independently corroborated employment history, is the gate for anyone who will hold deployment or upgrade keys, and no single developer should be able to move user funds without multi-party approval.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Munchables Exploited for $62M, North Korea-Linked Exploiter Returns Private Keys to Web 3 Firm",
          "url": "https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member",
          "publisher": "CoinDesk"
        },
        {
          "title": "Explained: The Munchables Hack (March 2024)",
          "url": "https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024",
          "publisher": "Halborn"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k"
    },
    {
      "slug": "2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200",
      "title": "Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected",
      "date": "2024-02-19",
      "date_precision": "day",
      "year": 2024,
      "victim_org": "Los Angeles County Department of Public Health",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 200000,
      "threat_actor": null,
      "summary": "The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.",
      "how_it_worked": "A phishing email circulated through the department and 53 separate employees entered their credentials on the attacker's page within roughly 24 hours, which shows the message was well matched to the environment rather than obviously fraudulent. With valid log-ins the attacker read the contents of those mailboxes, which in a county public health agency contain case correspondence carrying patient names, diagnoses, prescriptions and benefit identifiers. The department responded by disabling accounts, resetting devices, blocking the phishing sites and quarantining the messages, but by then two days of mailbox access across dozens of accounts had already occurred.",
      "lessons": "Phishing-resistant MFA across county staff accounts would have made the harvested passwords useless, and rapid cross-department alerting would have cut the exposure window.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "200,000 Impacted by Data Breach at Los Angeles County Public Health Agency",
          "url": "https://www.securityweek.com/200000-impacted-by-data-breach-at-los-angeles-county-public-health-agency/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Los Angeles Public Health Department Discloses Large Data Breach",
          "url": "https://www.infosecurity-magazine.com/news/los-angeles-health-data-breach/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200"
    },
    {
      "title": "Arup Hong Kong office loses about $25 million in deepfake video call scam",
      "date": "2024-02",
      "date_precision": "month",
      "victim_org": "Arup Group (Hong Kong office)",
      "sector": "Professional Services",
      "country": "Hong Kong",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Business Email Compromise",
        "Voice Clone / Audio Deepfake",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 25000000,
      "loss_note": "HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.",
      "how_it_worked": "The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.",
      "lessons": "High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Deepfaked video conference call makes employee send $25 million to scammers",
          "url": "https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/",
          "publisher": "Help Net Security"
        },
        {
          "title": "Arup Group (fraud incident section)",
          "url": "https://en.wikipedia.org/wiki/Arup_Group",
          "publisher": "Wikipedia"
        },
        {
          "title": "Business Email Compromise: Virtual Meeting Platforms",
          "url": "https://www.ic3.gov/PSA/2022/PSA220216",
          "publisher": "FBI IC3"
        },
        {
          "title": "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee",
          "url": "https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk",
          "publisher": "CNN"
        },
        {
          "title": "'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting",
          "url": "https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage",
          "publisher": "South China Morning Post"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam",
      "year": 2024,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"
    },
    {
      "title": "SIM swap of the SEC's X account posted a fake Bitcoin ETF approval",
      "date": "2024-01-09",
      "date_precision": "day",
      "victim_org": "U.S. Securities and Exchange Commission",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Physical Pretexting"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported; the impersonation used a physically printed counterfeit ID card.",
      "outcomes": [
        "Identity Theft",
        "Service Disruption",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "No direct loss to the SEC was published. The fake post moved bitcoin roughly $1,000 higher, then more than $2,000 lower once the SEC disclosed the compromise. Council was paid about $50,000 in bitcoin for performing SIM swaps and was ordered to forfeit that amount.",
      "records_affected": null,
      "threat_actor": "Eric Council Jr. and co-conspirators",
      "summary": "On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.",
      "how_it_worked": "Council printed a counterfeit identification card on a portable card printer using personal details supplied by co-conspirators, then walked into an AT&T store in Huntsville, Alabama and asked for a replacement SIM for the number tied to the @SECgov account. Store staff issued it against the fake document. He activated the SIM in a newly purchased iPhone, received the password-reset code for the X account, and passed it to the conspirators, who posted the fabricated ETF approval. Bitcoin moved over $1,000 within minutes. The FBI later found fake-ID templates and searches about FBI investigations at his residence.",
      "lessons": "High-consequence institutional social accounts should be secured with hardware security keys rather than SMS-based recovery, and carrier retail ID checks need document-authentication technology rather than visual inspection.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Alabama Man Sentenced in Hack of SEC X Account that Spiked the Value of Bitcoin",
          "url": "https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin",
          "publisher": "U.S. Department of Justice"
        },
        {
          "title": "Hacker pleads guilty to SIM swap attack on US SEC X account",
          "url": "https://www.bleepingcomputer.com/news/security/hacker-pleads-guilty-to-sim-swap-attack-on-us-sec-x-account/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval"
    },
    {
      "title": "AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads",
      "date": "2024-01",
      "date_precision": "month",
      "victim_org": "Multiple US consumers; brands Taylor Swift and Le Creuset impersonated",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [
        "Voice Clone / Audio Deepfake",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "The ads paired authentic images of the singer with a synthesised clone of her voice; a Carnegie Mellon researcher confirmed the audio was fabricated while the photographs were genuine.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "Individual victims reported paying small shipping fees and supplying card details; aggregate loss not published",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.",
      "how_it_worked": "The scam borrowed two trusted identities at once, a celebrity with an unusually devoted fanbase and a premium cookware brand that plausibly runs promotions. Distribution came through paid social ads, so the content arrived inside a feed the target already trusted rather than in an unsolicited message. The cloned voice narrating a personal-sounding offer supplied the authenticity that still images alone would not, and the giveaway framing made urgency natural: a limited number of free sets meant acting immediately. The small shipping fee was the conversion step, low enough to feel harmless while capturing card data and personal details.",
      "lessons": "Consumers should verify giveaways on the brand's own site, and ad platforms need celebrity-likeness and synthetic-voice detection in advertiser review rather than post-hoc takedown.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "The Taylor Swift Le Creuset cookware giveaway is fake",
          "url": "https://www.today.com/food/news/taylor-swift-le-creuset-cookware-giveaway-fake-rcna133325",
          "publisher": "TODAY / NBC News"
        },
        {
          "title": "AI-generated ads using Taylor Swift's likeness dupe fans with fake Le Creuset giveaway",
          "url": "https://cbsnews.com/news/taylor-swift-le-creuset-ai-generated-ads",
          "publisher": "CBS News"
        }
      ],
      "entry_type": "campaign",
      "slug": "2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads"
    },
    {
      "title": "AI-cloned Biden robocall told New Hampshire voters to skip the primary",
      "date": "2024-01",
      "date_precision": "month",
      "victim_org": "New Hampshire primary voters",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Political consultant Steve Kramer admitted commissioning an AI-cloned voice of President Biden for the robocall; the FCC's enforcement action describes the recording as AI-generated.",
      "outcomes": [
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "FCC proposed a US$6 million forfeiture against Kramer; carrier Lingo Telecom settled for US$1 million",
      "records_affected": null,
      "threat_actor": "Steven Kramer (political consultant)",
      "summary": "On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.",
      "how_it_worked": "The channel was an ordinary automated phone call with spoofed caller ID, arriving in the last hours before an election when voters have little time to check anything. The trust signal was the president's recognisable voice delivering a message in his own idiom, addressed to Democratic voters as if from the campaign itself. The persuasion was framed not as suppression but as helpful strategy, telling recipients their vote mattered more in November, which gave the instruction an internally consistent rationale. Because the medium is one-way and the timing left no room for correction, targets had no natural opportunity to verify before the primary took place.",
      "lessons": "Carriers enforcing STIR/SHAKEN caller-ID attestation on upstream customers, plus rapid election-authority rebuttal channels, are the practical controls; voters should treat any voting instruction by phone as unverified.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "FCC Proposes $6 Million Fine For Illegal Robocalls That Used Deepfake AI Voice",
          "url": "https://docs.fcc.gov/public/attachments/DOC-402762A1.pdf",
          "publisher": "US Federal Communications Commission"
        },
        {
          "title": "Criminal charges and FCC fines issued for deepfake Biden robocalls",
          "url": "https://www.npr.org/2024/05/23/nx-s1-4977582/fcc-ai-deepfake-robocall-biden-new-hampshire-political-operative",
          "publisher": "NPR"
        }
      ],
      "entry_type": "incident",
      "slug": "2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary",
      "year": 2024,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary"
    },
    {
      "title": "FBI IC3 reports $2.77 billion in BEC losses for 2024 (context baseline)",
      "date": "2024",
      "date_precision": "year",
      "victim_org": "Aggregate: U.S. and international BEC victims reporting to FBI IC3",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The IC3 annual report does not break out AI-enabled BEC as a separate category; separate FBI PSAs have documented deepfake audio and virtual-meeting impersonation used in BEC.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 2770151146,
      "loss_note": "2024 IC3 Annual Report: 21,442 BEC complaints and $2,770,151,146 in adjusted losses. Cumulatively, IC3 recorded 277,918 BEC incidents and roughly $50.9 billion in exposed losses globally from October 2013 through December 2022.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "The FBI Internet Crime Complaint Center's 2024 annual report recorded 21,442 business email compromise complaints with adjusted losses of $2,770,151,146, keeping BEC among the costliest reported cybercrime categories. A separate IC3 public service announcement in June 2023 put cumulative global BEC exposure at approximately $50.9 billion across 277,918 incidents between October 2013 and December 2022, and reported that real estate-sector BEC losses reached $446.1 million in 2022, up 72 percent from 2020.",
      "how_it_worked": "IC3 describes a consistent mechanism across reported cases: criminals compromise or spoof an email account belonging to an executive, employee, vendor or transaction professional, monitor correspondence to identify a pending payment, and then send instructions substituting attacker-controlled bank details. Real estate closings are heavily targeted because buyers, sellers, attorneys, title companies and agents all exchange payment instructions under time pressure. Funds increasingly route to cryptocurrency exchanges and third-party payment processors, with Hong Kong, China, the United Kingdom, Mexico and Singapore among leading destinations. IC3's Recovery Asset Team initiates the Financial Fraud Kill Chain, and most kill-chain requests involve BEC.",
      "lessons": "Reporting a diverted wire to IC3 and the originating bank within 24 to 72 hours is the highest-value response control, and pre-transaction verification of wire instructions is the highest-value prevention control.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "2024 Internet Crime Report",
          "url": "https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf",
          "publisher": "FBI Internet Crime Complaint Center"
        },
        {
          "title": "Business Email Compromise: The $50 Billion Scam",
          "url": "https://www.ic3.gov/PSA/2023/PSA230609",
          "publisher": "FBI Internet Crime Complaint Center"
        }
      ],
      "entry_type": "benchmark",
      "slug": "2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline",
      "year": 2024,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-ic3-reports-2-77-billion-in-bec-losses-for-2024-context-baseline"
    },
    {
      "title": "Ledger Connect Kit poisoned after a former employee's npm account was phished",
      "date": "2023-12-14",
      "date_precision": "day",
      "victim_org": "Ledger SAS",
      "sector": "Cryptocurrency",
      "country": "France",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Supply Chain Compromise",
        "Cryptocurrency Theft",
        "Credential Theft"
      ],
      "loss_usd": 600000,
      "loss_note": "Commonly reported as roughly $600,000 drained; CoinDesk cited an on-chain figure of about $484,000 in the immediate aftermath. Ledger said proceeds were split 85/15 between the attacker and the Angel Drainer service.",
      "records_affected": null,
      "threat_actor": "Operator using the Angel Drainer drainer-as-a-service",
      "summary": "On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.",
      "how_it_worked": "The former employee's access to Ledger's internal systems had been revoked at offboarding, but their npmjs publishing rights had not been manually removed. A phishing attack captured a valid session token rather than a password, which sidestepped the account's 2FA entirely and let the attacker publish new Connect Kit versions. Those versions injected the Angel Drainer script into any decentralised application that loaded the library, prompting users to sign transactions that transferred their assets to the attacker. Ledger shipped a clean version within about 40 minutes of learning of the compromise, but CDN caching kept the poisoned file reachable for roughly five hours in total.",
      "lessons": "Offboarding must enumerate and revoke package-registry and other third-party publishing rights, and releases to public package registries should require hardware-key-backed signing plus a second approver rather than a single session.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Security Incident Report",
          "url": "https://www.ledger.com/blog/security-incident-report",
          "publisher": "Ledger"
        },
        {
          "title": "Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft",
          "url": "https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code",
          "url": "https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code",
          "publisher": "CoinDesk"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph",
      "year": 2023,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph"
    },
    {
      "title": "Arizona laptop farm placed North Korean IT workers at 309 US companies",
      "date": "2023-10",
      "date_precision": "month",
      "victim_org": "309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake IT Worker Infiltration",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "The DOJ case documents describe stolen real identities rather than AI-generated personas; no AI use was specified in the sentencing reporting.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft",
        "Insider Access"
      ],
      "loss_usd": 17000000,
      "loss_note": "The scheme generated approximately $17 million in revenue for the North Korean government. Chapman was ordered to forfeit $284,555.92 intended for North Korea and to pay a $176,850 fine.",
      "records_affected": 68,
      "threat_actor": "DPRK IT worker network, facilitated by Christina Marie Chapman",
      "summary": "From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.",
      "how_it_worked": "North Korean operatives applied for remote IT roles under the identities of real Americans, clearing background checks because the identities were genuine. When each employer shipped a work laptop to the address on file, that address was Chapman's house. She installed remote access software on each machine and kept them running so the workers could connect daily and appear on the employer's network from a US residential IP on US business hours. Chapman also received the direct-deposit wages, forged payroll checks and filed tax returns in the stolen names before moving the money overseas. Employers saw nothing anomalous because the device, the network location and the paperwork were all genuinely American.",
      "lessons": "Verifying that a shipped device is actually in the hands of the person hired, through live video identity checks at onboarding and device-location attestation, is what breaks the laptop farm model.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Arizona woman sentenced to 8.5 years for running North Korean laptop farm",
          "url": "https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm",
          "publisher": "The Record (Recorded Future News)"
        },
        {
          "title": "Arizona woman imprisoned for $17M North Korean remote workers scheme",
          "url": "https://www.upi.com/Top_News/US/2025/07/24/chapman-north-korea-remote-workers-fraud/7551753396658/",
          "publisher": "UPI"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies",
      "year": 2023,
      "loss_kind": "criminal_proceeds",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies"
    },
    {
      "title": "FBI 'Phantom Hacker' alert: three-persona scam drains seniors' life savings",
      "date": "2023-09-29",
      "date_precision": "day",
      "victim_org": "US senior citizens (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Tech Support Scam",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Callback Phishing (TOAD)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "The advisory does not describe AI-generated voice or content in this campaign.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft"
      ],
      "loss_usd": 542000000,
      "loss_note": "IC3 received 19,000 tech support scam complaints between January and June 2023 with estimated victim losses over $542 million; nearly half of victims were over 60 and accounted for 66 percent of losses.",
      "records_affected": 19000,
      "threat_actor": null,
      "summary": "On 29 September 2023 the FBI's Internet Crime Complaint Center warned about the Phantom Hacker scam, an evolved tech support fraud that layers three impersonated personas to move a victim's entire savings. IC3 logged 19,000 tech support complaints in the first half of 2023 with losses above $542 million, with people over 60 making up nearly half of victims and 66 percent of losses. By August 2023 losses had already exceeded the whole of 2022 by 40 percent.",
      "how_it_worked": "Phase one is a supposed technology company representative reaching the victim by call, text, email or pop-up, who obtains remote access, shows fabricated virus scan results and reviews the victim's financial accounts to find the largest balance, then warns that the institution's fraud department will be in touch. Phase two is a caller posing as that bank or brokerage saying a foreign hacker has accessed the accounts and the money must be moved to a safe government account by wire, cash or cryptocurrency, with instructions to keep it confidential. Phase three is a purported Federal Reserve or government employee, sometimes sending official-looking letterhead, who confirms the story and presses the victim to complete the transfer.",
      "lessons": "The confidentiality instruction is the diagnostic tell; bank staff trained to treat customer secrecy plus urgent large outbound transfers as a scam indicator, and mandatory cooling-off holds, break the chain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "'Phantom Hacker' Scams Target Senior Citizens and Result in Victims Losing their Life Savings",
          "url": "https://www.ic3.gov/PSA/2023/PSA230929",
          "publisher": "FBI Internet Crime Complaint Center"
        }
      ],
      "entry_type": "campaign",
      "slug": "2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings",
      "year": 2023,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-fbi-phantom-hacker-alert-three-persona-scam-drains-seniors-life-savings"
    },
    {
      "title": "MGM Resorts shut down for ten days after a help desk social engineering call",
      "date": "2023-09-11",
      "date_precision": "day",
      "victim_org": "MGM Resorts International",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or voice cloning was reported; the reported method was a live human call using details gathered from public professional profiles.",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption",
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": 110000000,
      "loss_note": "MGM reported roughly $100 million of negative impact to Las Vegas and regional operations' adjusted property earnings plus under $10 million of one-time costs; a $45 million class settlement covering this and an earlier breach was approved later.",
      "records_affected": null,
      "threat_actor": "Scattered Spider, an affiliate of ALPHV/BlackCat",
      "summary": "MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.",
      "how_it_worked": "MGM has never published the entry point, but the widely reported account, consistent with the CISA advisory and Okta's contemporaneous warning, is that the crew identified an MGM employee from a public professional profile, gathered enough personal and organisational detail to pass as them, and phoned the IT help desk to obtain a credential and MFA reset in a call reported to have lasted about ten minutes. With a legitimate identity re-issued to them, the actors escalated inside the identity provider and, after exfiltration, deployed ransomware against virtualisation infrastructure.",
      "lessons": "High-privilege credential and MFA resets should never be grantable on a single inbound phone call; out-of-band verification with a known manager or video identity check would have cost the caller the whole operation.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Ransomware attack on MGM Resorts costs $110 Million",
          "url": "https://securityaffairs.com/152077/cyber-crime/mgm-resorts-ransomware-attack.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "MGM Resorts confirms hackers stole customers' personal data during cyberattack",
          "url": "https://techcrunch.com/2023/10/06/mgm-resorts-admits-hackers-stole-customers-personal-data-cyberattack/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Scattered Spider (AA23-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
          "publisher": "CISA / FBI"
        },
        {
          "title": "A full timeline of the MGM Resorts cyber attack",
          "url": "https://www.cshub.com/attacks/news/a-full-timeline-of-the-mgm-resorts-cyber-attack",
          "publisher": "Cyber Security Hub"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering",
      "year": 2023,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering"
    },
    {
      "title": "Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee",
      "date": "2023-08-27",
      "date_precision": "day",
      "victim_org": "Retool",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Voice Clone / Audio Deepfake",
        "Vishing (Voice Phishing)",
        "Help Desk Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Retool stated the caller used a deepfaked voice imitating a specific member of its IT team, whom the target employee knew. This is one of the earliest well-documented uses of voice cloning in a corporate intrusion.",
      "outcomes": [
        "Data Breach",
        "Cryptocurrency Theft",
        "Credential Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_note": "Retool reported no loss of its own; downstream, cryptocurrency customer Fortress Trust separately reported a theft of roughly $15 million tied to the compromise, a figure attributed to Fortress Trust rather than confirmed by Retool.",
      "records_affected": 27,
      "threat_actor": null,
      "summary": "Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.",
      "how_it_worked": "The employee received a text claiming to be from Retool IT about a payroll and healthcare enrolment issue, with a link to a page cloning the company's internal identity portal. After the employee submitted credentials and an MFA code, the attacker phoned them; the voice was a deepfake of a specific IT team member the employee recognised, and the caller was familiar with office layout, colleagues and internal processes. During the call the employee provided an additional MFA code, which let the attacker add their own device to the employee's Okta account. From there they reached the employee's Google account, where Authenticator's cloud sync had backed up OTP seeds, and used those to pivot into internal admin systems and alter customer accounts.",
      "lessons": "Voice is no longer an identity proof; hardware security keys plus a policy that MFA codes are never read aloud, and disabling authenticator cloud sync on enterprise accounts, close both halves of this chain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Retool blames breach on Google Authenticator MFA cloud sync feature",
          "url": "https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients",
          "url": "https://thehackernews.com/2023/09/retool-falls-victim-to-sms-based.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks",
          "url": "https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "When MFA isn't actually MFA",
          "url": "https://retool.com/blog/mfa-isnt-mfa",
          "publisher": "Retool"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp"
    },
    {
      "slug": "2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da",
      "title": "SIM swap of a Kroll employee exposes FTX, BlockFi and Genesis claimant data",
      "date": "2023-08-19",
      "date_precision": "day",
      "year": 2023,
      "victim_org": "Kroll",
      "sector": "Professional Services",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Risk advisory firm Kroll disclosed that on 19 August 2023 an attacker transferred a Kroll employee's T-Mobile phone number to a device under their control without Kroll's or the employee's authorisation. Using that number the attacker accessed files containing personal information of bankruptcy claimants of FTX, BlockFi and Genesis, for which Kroll acted as claims agent. Affected claimants were notified and warned about follow-on phishing.",
      "how_it_worked": "The attacker convinced T-Mobile to port a Kroll employee's number to a SIM they controlled, a transfer carried out by a mobile carrier representative acting on a fraudulent request. Once the number was theirs, SMS-based authentication codes for the employee's accounts arrived on the attacker's device, letting them reset access and reach the claimant files Kroll held as bankruptcy administrator. The victims were bankrupt crypto platforms' creditors, a population whose names and contact details are immediately monetisable through targeted phishing about their claims, and several such phishing waves followed the breach.",
      "lessons": "Remove SMS from the authentication path entirely for staff handling sensitive data, and place carrier-level port-out locks on corporate mobile numbers.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Kroll Employee SIM-Swapped for Crypto Investor Data",
          "url": "https://krebsonsecurity.com/2023/08/kroll-employee-sim-swapped-for-crypto-investor-data/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "T-Mobile SIM-swapping attack on Kroll employee caused crypto platform data breach",
          "url": "https://therecord.media/sim-swap-attack-caused-crypto-breach",
          "publisher": "The Record"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-sim-swap-of-a-kroll-employee-exposes-ftx-blockfi-and-genesis-claimant-da"
    },
    {
      "title": "Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered",
      "date": "2023-08-18",
      "date_precision": "day",
      "victim_org": "Caesars Entertainment",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 15000000,
      "loss_note": "Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.",
      "records_affected": null,
      "threat_actor": "Scattered Spider, reportedly working with ALPHV/BlackCat",
      "summary": "Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.",
      "how_it_worked": "Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.",
      "lessons": "Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Caesars Entertainment says social-engineering attack behind August breach",
          "url": "https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/",
          "publisher": "Cybersecurity Dive"
        },
        {
          "title": "Scattered Spider (AA23-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
          "publisher": "CISA / FBI"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially",
      "year": 2023,
      "loss_kind": "ransom_paid",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"
    },
    {
      "title": "Clorox attack traced to help desk agents resetting passwords without verification",
      "date": "2023-08-11",
      "date_precision": "day",
      "victim_org": "The Clorox Company",
      "sector": "Manufacturing",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported; the complaint describes live phone calls.",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption",
        "Data Breach",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 380000000,
      "loss_note": "$380 million is the total damages Clorox sought in its 2025 lawsuit against Cognizant, including about $49 million in direct remediation costs; it is a litigation claim, not an adjudicated loss.",
      "records_affected": null,
      "threat_actor": "Scattered Spider",
      "summary": "Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.",
      "how_it_worked": "According to the complaint, the attacker called the Cognizant-run service desk multiple times claiming to be a Clorox employee and asked for a password reset. The agent reset the credential and the multifactor enrolment without confirming the caller's identity, and transcripts quoted in the filing show no verification step took place. The attacker used the same technique against a Clorox IT security employee, which yielded privileged network access. From there the intrusion progressed to network-wide disruption; Clorox took systems offline, reverted to manual order processing, and saw sales and shipments fall for months afterwards.",
      "lessons": "Outsourced service desks need contractually mandated, auditable identity proofing before any credential or MFA reset, with higher-assurance checks for accounts holding privileged access.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit",
          "url": "https://www.bleepingcomputer.com/news/security/hackers-fooled-cognizant-help-desk-says-clorox-in-380m-cyberattack-lawsuit/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack",
          "url": "https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor",
          "publisher": "The Record"
        },
        {
          "title": "Clorox files $380 million suit blaming Cognizant for 2023 cyberattack",
          "url": "https://www.cybersecuritydive.com/news/clorox-380-million-suit-cognizant-cyberattack/753837/",
          "publisher": "Cybersecurity Dive"
        },
        {
          "title": "$380M lawsuit: intruder got Clorox's passwords from Cognizant simply by asking",
          "url": "https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/",
          "publisher": "The Register"
        },
        {
          "title": "Clorox estimates the costs of the August cyberattack will exceed $49 Million",
          "url": "https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver",
      "year": 2023,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver"
    },
    {
      "title": "Okta warns of a coordinated campaign against US customers' IT service desks",
      "date": "2023-08",
      "date_precision": "month",
      "victim_org": "Multiple US-based Okta customer organizations",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported in Okta's advisory.",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Insider Access"
      ],
      "loss_usd": null,
      "loss_note": "Okta did not name victims or quantify losses in this advisory.",
      "records_affected": null,
      "threat_actor": "Actor consistent with Scattered Spider / Muddled Libra (unnamed in the advisory)",
      "summary": "Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.",
      "how_it_worked": "The caller arrived already holding something: either the password to a privileged account or the ability to manipulate delegated authentication. That partial knowledge is what makes the help desk call succeed, because the agent hears a caller who knows their own username, manager and internal jargon, and treats an MFA reset as routine. Once the factors were reset the actor enrolled their own, signed in from anonymising proxies on unfamiliar devices, escalated to Super Administrator and stood up a second identity provider so they could impersonate arbitrary users through federation.",
      "lessons": "Identity-proofing the caller out of band, such as manager attestation or video verification, plus admin-console policies that require phishing-resistant factors and known devices, breaks the reset-to-takeover chain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Cross-Tenant Impersonation: Prevention and Detection",
          "url": "https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/",
          "publisher": "Okta Security"
        },
        {
          "title": "Scattered Spider (AA23-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
          "publisher": "CISA / FBI"
        }
      ],
      "entry_type": "campaign",
      "slug": "2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des"
    },
    {
      "title": "QR code phishing campaign targets a major US energy company's Microsoft logins",
      "date": "2023-08",
      "date_precision": "month",
      "victim_org": "Unnamed major US energy company (plus manufacturing, insurance, technology and financial targets)",
      "sector": "Energy & Utilities",
      "country": "United States",
      "primary_vector": "QR Code Phishing",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Credential Theft",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure; Cofense reported the campaign volume rather than confirmed compromises.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Cofense reported a phishing campaign running from May to August 2023 that used QR codes embedded in PNG and PDF attachments to steal Microsoft credentials. More than 1,000 malicious emails were observed, of which roughly 29 percent were directed at a single large US energy company, with the remainder spread across manufacturing, insurance, technology and financial services. The campaign grew sharply from May onward.",
      "how_it_worked": "Emails spoofed Microsoft security notifications and told recipients they had to update account security relating to two-factor or multifactor authentication. Rather than a clickable link, the message carried a QR code inside an image or PDF attachment, which defeated URL scanning in email gateways because the destination was encoded in pixels. Scanning the code moved the victim onto a personal mobile phone, typically outside corporate device management and web filtering, where a credential harvesting page imitating Microsoft sign-in captured the username and password. Attackers also used redirects through legitimate services such as Bing to further obscure the final destination.",
      "lessons": "Email security needs to decode QR images rather than only parse hyperlinks, and enrolling users in phishing-resistant authentication means a credential captured on an unmanaged phone is not enough to sign in.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Major Energy Company Targeted in Large QR Code Campaign",
          "url": "https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign",
          "publisher": "Cofense"
        },
        {
          "title": "QR Code Phishing Campaign Targets Top US Energy Company",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company",
          "publisher": "Dark Reading"
        },
        {
          "title": "Phishing campaign used QR codes to target large energy company",
          "url": "https://therecord.media/phishing-campaign-used-qr-codes-to-target-energy-firm",
          "publisher": "The Record"
        }
      ],
      "entry_type": "campaign",
      "slug": "2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-qr-code-phishing-campaign-targets-a-major-us-energy-company-s-microsoft"
    },
    {
      "slug": "2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro",
      "title": "EvilProxy phishing kit used in 120,000 emails to hijack executives' Microsoft 365 accounts",
      "date": "2023-08",
      "date_precision": "month",
      "year": 2023,
      "victim_org": "More than 100 organisations worldwide (Proofpoint-tracked campaign)",
      "sector": "Technology",
      "country": "Global",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Business Email Compromise"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Proofpoint reported in August 2023 on a campaign running since March 2023 that sent about 120,000 phishing emails to more than 100 organisations worldwide using the EvilProxy reverse-proxy phishing kit. The operators focused on senior staff: of the accounts successfully taken over, a substantial share belonged to vice presidents and C-level executives. Attackers who succeeded added their own multi-factor authentication method to retain persistent access.",
      "how_it_worked": "Emails impersonated widely trusted services such as Adobe, DocuSign and Concur, and pushed recipients through redirect chains to an EvilProxy page that relayed the real Microsoft 365 log-in. Victims entered their password and completed their genuine MFA challenge, and the proxy captured the resulting session cookie, so MFA provided no protection. The campaign filtered its own traffic, screening out non-target regions and security-research infrastructure, and deliberately concentrated on executives whose mailboxes carry payment authority and confidential deal information. Successful intrusions were consolidated by enrolling an attacker-controlled MFA method, converting a one-time theft into durable access.",
      "lessons": "Phishing-resistant FIDO2 credentials for high-value roles, and alerting whenever a new MFA method is registered on an executive account, are the controls that matter here.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "EvilProxy Phishing Used for Cloud Account Takeover Campaign",
          "url": "https://www.proofpoint.com/us/blog/email-and-cloud-threats/cloud-account-takeover-campaign-leveraging-evilproxy-targets-top-level",
          "publisher": "Proofpoint"
        },
        {
          "title": "EvilProxy phishing campaign targets 120,000 Microsoft 365 users",
          "url": "https://www.bleepingcomputer.com/news/security/evilproxy-phishing-campaign-targets-120-000-microsoft-365-users/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-evilproxy-phishing-kit-used-in-120-000-emails-to-hijack-executives-micro"
    },
    {
      "title": "Fake recruiter's coding test cost payment processor CoinsPaid $37M",
      "date": "2023-07-22",
      "date_precision": "day",
      "victim_org": "CoinsPaid",
      "sector": "Cryptocurrency",
      "country": "Estonia",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 37000000,
      "loss_note": "CoinsPaid reported losses of over $37 million; company funds rather than customer funds bore the loss. Most of the proceeds were moved through SwftSwap.",
      "records_affected": null,
      "threat_actor": "Lazarus Group (DPRK), suspected by CoinsPaid",
      "summary": "Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.",
      "how_it_worked": "After direct infrastructure attacks failed, the operators changed target from the network to a person. Fake recruiters approached a CoinsPaid engineer over messaging and professional platforms with an offer well above market rate, then moved the conversation to an interview process. The 'technical task' the candidate was asked to run as part of that process was the payload. Running it on their working machine gave the attackers a foothold with the employee's credentials and access, from which they reached the infrastructure that authorised outbound transfers and drained more than $37 million. CoinsPaid noted the transaction patterns closely mirrored other Lazarus operations from the same period.",
      "lessons": "Job-application code and take-home assessments must only ever run in a disposable, network-isolated VM, and recruiters approaching engineers with outsized offers should be treated as an active threat indicator, not an HR event.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "CoinsPaid claims North Korean hacking group used fake job interview to steal $37M",
          "url": "https://cointelegraph.com/news/coinspaid-claims-north-korean-hacking-group-fake-job-interview-theft",
          "publisher": "Cointelegraph"
        },
        {
          "title": "The CoinsPaid Hack Explained",
          "url": "https://coinspaid.com/company-updates/the-coinspaid-hack-explained/",
          "publisher": "CoinsPaid"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m",
      "year": 2023,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m"
    },
    {
      "slug": "2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d",
      "title": "Dragos intrusion began with the hijacked personal email of an employee due to start work",
      "date": "2023-05-08",
      "date_precision": "day",
      "year": 2023,
      "victim_org": "Dragos",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "No ransom paid; Dragos refused to engage with the extortion attempt.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Industrial cybersecurity firm Dragos disclosed on 10 May 2023 that a criminal group had compromised the personal email address of a newly hired sales employee before their start date and used it to impersonate them through the onboarding process. The attacker reached SharePoint resources and the company's contract management system, and viewed a report containing customer IP addresses. Ransomware deployment failed, and the group turned to extortion, messaging Dragos executives and referencing family members. Dragos did not pay.",
      "how_it_worked": "The attacker targeted the gap that exists before a new hire's first day, when the person has an accepted offer but no corporate identity yet. Having taken over the recruit's personal email, the criminal completed the onboarding steps in their name, receiving credentials and access as the company believed it was equipping its own new starter. That produced legitimate access to onboarding-tier resources including SharePoint and a contract system. When ransomware deployment failed, the group escalated to personal pressure, contacting executives' private accounts and naming relatives to force negotiation. Dragos's SIEM alerts surfaced the activity and the account was blocked.",
      "lessons": "Onboarding must verify identity through a channel independent of the address on the offer letter, and new-hire accounts should start with minimal access under heightened monitoring.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Deconstructing a Cybersecurity Event",
          "url": "https://www.dragos.com/blog/deconstructing-a-cybersecurity-event",
          "publisher": "Dragos"
        },
        {
          "title": "Cybersecurity firm Dragos discloses cybersecurity incident, extortion attempt",
          "url": "https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-dragos-intrusion-began-with-the-hijacked-personal-email-of-an-employee-d"
    },
    {
      "title": "Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked",
      "date": "2023-05",
      "date_precision": "month",
      "victim_org": "Bart Stephens, co-founder of Blockchain Capital",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Identity Theft",
        "Attempt Blocked"
      ],
      "loss_usd": 6300000,
      "loss_note": "$6.3 million in bitcoin, ether and other tokens per the civil complaint. A further attempted theft of about $14 million from a cold storage wallet was stopped. Roughly half the stolen funds were routed through mixers.",
      "records_affected": null,
      "threat_actor": "Unidentified attacker sued as 'Jane Doe'",
      "summary": "Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.",
      "how_it_worked": "The attacker assembled Stephens's personal details from public sources and dark web data, then used them to pass the identity checks at his mobile carrier, change the account password, order a new handset and port his private cell number to a SIM in that device. Holding the number, the attacker triggered password resets across Stephens's digital wallets and satisfied the SMS second factor on each one, then systematically moved assets out. The one transfer that failed was the cold storage withdrawal, which generated a notification seen by a colleague at the firm who acted before it settled.",
      "lessons": "Removing SMS as a recovery or second factor for any wallet, and routing large withdrawals through a mandatory second-person approval with a time delay, are the two controls that separated the $6.3 million loss from the $14 million save.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Blockchain Capital's Bart Stephens Lost $6.3 Million In SIM-Swap Crypto Hack",
          "url": "https://www.forbes.com/sites/iainmartin/2023/08/21/blockchain-capitals-bart-stephens-lost-63-million-in-sim-swap-crypto-hack/",
          "publisher": "Forbes"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked",
      "year": 2023,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-blockchain-capital-co-founder-loses-6-3m-in-sim-swap-14m-attempt-blocked"
    },
    {
      "title": "AI voice clone of teenage daughter used in Arizona virtual kidnapping attempt",
      "date": "2023-04",
      "date_precision": "month",
      "victim_org": "Jennifer DeStefano, a private individual in Scottsdale, Arizona",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "The mother testified that the caller played back what sounded exactly like her 15-year-old daughter's voice, sobs and inflection included; investigators and researchers attributed this to AI voice cloning, though the sample source was never identified.",
      "outcomes": [
        "Attempt Blocked",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No money was transferred",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Jennifer DeStefano of Scottsdale, Arizona received a call in which she heard what she believed was her 15-year-old daughter crying, followed by a man claiming to hold the girl and demanding a US$1 million ransom, later reduced to US$50,000 in cash. While she kept the caller talking, other parents reached her husband, who confirmed the daughter was safe at home. No money changed hands. DeStefano described the incident in written testimony to the US Senate Judiciary Committee in June 2023, and it became one of the most cited AI voice-cloning cases in US policy debate.",
      "how_it_worked": "The pretext was the most emotionally overwhelming one available, a child in immediate physical danger, delivered by phone at a moment when the mother was away from her daughter and could not instantly verify. The cloned crying voice was the trust signal; it matched not just the timbre but the way the girl cries. The caller then applied escalating threats and refused to let her hang up or make another call, closing off exactly the verification path that would have ended the scam. Pressure was tuned by dropping the demand from US$1 million to US$50,000 cash, making compliance feel achievable, and by insisting on an in-person handover rather than a traceable wire.",
      "lessons": "Families need a pre-agreed verbal code word and a habit of hanging up and calling the relative back on a known number before acting on any ransom or emergency call.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Written Statement of Jennifer DeStefano, US Senate Committee on the Judiciary",
          "url": "https://www.judiciary.senate.gov/imo/media/doc/2023-06-13%20PM%20-%20Testimony%20-%20DeStefano.pdf",
          "publisher": "US Senate Committee on the Judiciary"
        },
        {
          "title": "AI kidnapping scam targets Arizona mother",
          "url": "https://www.fox10phoenix.com/news/ai-kidnapping-scam-targets-arizona-mother-youll-never-see-your-daughter-again",
          "publisher": "FOX 10 Phoenix"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-ai-voice-clone-of-teenage-daughter-used-in-arizona-virtual-kidnapping-at",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-ai-voice-clone-of-teenage-daughter-used-in-arizona-virtual-kidnapping-at"
    },
    {
      "title": "3CX supply chain attack began with a trojanised X_TRADER installer on staff PC",
      "date": "2023-03-29",
      "date_precision": "day",
      "victim_org": "3CX Ltd.",
      "sector": "Technology",
      "country": "Cyprus",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Supply Chain Compromise",
        "Espionage",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No loss figure published; 3CX said it had over 600,000 customer companies, though only a subset installed the trojanised builds.",
      "records_affected": null,
      "threat_actor": "UNC4736 / Lazarus-linked North Korean cluster (Mandiant attribution)",
      "summary": "In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.",
      "how_it_worked": "The employee retrieved what appeared to be a legitimate, digitally signed X_TRADER installer from the vendor's website in 2022. The package carried the VEILEDSIGNAL backdoor, giving the attackers a foothold and the employee's 3CX corporate credentials. Using those credentials the intruders moved into 3CX's network, reached the Windows and macOS build systems, and inserted malicious code into the desktop app build pipeline so that shipped, code-signed updates carried a downloader. Affected customer installations fetched encrypted payloads hidden in icon files on GitHub and, for a small number of selected targets, received a second-stage infostealer. Some reporting has also referred to fake-recruiter lures against 3CX staff, but the confirmed initial vector is the trojanised installer.",
      "lessons": "Build systems should be reachable only from hardened, managed workstations with no personal software installation, and installers from any vendor should be validated against a known-good hash and detonated before use.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
          "publisher": "Mandiant / Google Cloud"
        },
        {
          "title": "3CX Breach Was a Double Supply Chain Compromise",
          "url": "https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "Security Update 20 April 2023 - Initial Intrusion Vector Found",
          "url": "https://www.3cx.com/blog/news/mandiant-security-update2/",
          "publisher": "3CX"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st"
    },
    {
      "title": "Coinbase employee phished by SMS then talked through by a fake IT caller",
      "date": "2023-02-05",
      "date_precision": "day",
      "victim_org": "Coinbase",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Help Desk Impersonation",
        "Tech Support Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.",
      "outcomes": [
        "Data Breach",
        "Attempt Blocked",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No customer funds or customer data were lost; exposure was limited to some employee contact details.",
      "records_affected": null,
      "threat_actor": "Reported as the 0ktapus / Scattered Spider cluster",
      "summary": "In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.",
      "how_it_worked": "The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.",
      "lessons": "Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Social Engineering - A Coinbase Case Study",
          "url": "https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study",
          "publisher": "Coinbase"
        },
        {
          "title": "Coinbase cyberattack targeted employees with fake SMS alert",
          "url": "https://www.bleepingcomputer.com/news/security/coinbase-cyberattack-targeted-employees-with-fake-sms-alert/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Coinbase breached by social engineers, employee data stolen",
          "url": "https://news.sophos.com/en-us/2023/02/21/coinbase-breached-by-social-engineers-employee-data-stolen",
          "publisher": "Sophos News"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller"
    },
    {
      "title": "Reddit source code stolen via a phishing site cloning its intranet gateway",
      "date": "2023-02-05",
      "date_precision": "day",
      "victim_org": "Reddit",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Reddit disclosed that on 5 February 2023 an employee reported a targeted phishing attack after attackers stood up a website that closely mimicked Reddit's internal intranet gateway. The site harvested credentials and second-factor tokens, giving the intruder several hours of access to internal documents, code, dashboards and business systems. Reddit said no production systems were compromised and no user passwords or payment data were taken.",
      "how_it_worked": "The campaign sent plausible-sounding prompts to employees pointing at a cloned intranet gateway login page. One employee entered their credentials and their second-factor token into the clone; because the token was relayed immediately, the attacker completed a session on the real gateway. During a limited window the intruder accessed internal documents, limited source code, some internal dashboards and contact information for a few hundred current and former employees, plus information on advertisers. The employee self-reported quickly, which let Reddit revoke the session and lock the account, limiting dwell time to hours rather than weeks.",
      "lessons": "Phishing-resistant MFA defeats token-relay pages outright, and a blame-free self-reporting culture is what turned this into hours of exposure rather than months.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Reddit says limited amount of source code, employee data accessed in phishing attack",
          "url": "https://www.cybersecuritydive.com/news/reddit-source-code-employee-data-phishing/642510/",
          "publisher": "Cybersecurity Dive"
        },
        {
          "title": "Reddit Suffers Security Breach Exposing Internal Documents and Source Code",
          "url": "https://thehackernews.com/2023/02/reddit-suffers-security-breach-exposing.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Reddit discloses security breach that exposed source code and internal docs",
          "url": "https://securityaffairs.com/142071/data-breach/reddit-security-breach.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-reddit-source-code-stolen-via-a-phishing-site-cloning-its-intranet-gatew",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-reddit-source-code-stolen-via-a-phishing-site-cloning-its-intranet-gatew"
    },
    {
      "title": "French woman loses EUR 830,000 to an AI-image 'Brad Pitt' romance scam",
      "date": "2023-02",
      "date_precision": "month",
      "victim_org": "Private individual in France (identified only as 'Anne')",
      "sector": "Consumer",
      "country": "France",
      "primary_vector": "Romance / Investment Scam",
      "secondary_vectors": [],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Scammers sent AI-generated photographs purporting to show Brad Pitt in a hospital bed, along with images of a fake passport, to sustain the impersonation across an 18-month relationship.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 857900,
      "loss_note": "EUR 830,000, approx US$858,000",
      "records_affected": null,
      "threat_actor": "Nigerian-linked fraud network under French investigation",
      "summary": "Beginning in February 2023, a 53-year-old French woman known publicly as Anne was drawn into an online relationship with someone posing as actor Brad Pitt. Over about 18 months she sent EUR 830,000, largely after being told he needed money for kidney cancer treatment and that his accounts were frozen by divorce proceedings. AI-generated images of the actor in hospital and a forged passport reinforced the deception. She realised she had been defrauded on seeing genuine photographs of Pitt with his partner, and filed a police complaint; the case became public in January 2025 when French broadcaster TF1 aired and then withdrew her interview.",
      "how_it_worked": "Contact began through social media with a persona claiming to be the actor's mother, which lent credibility before the celebrity persona itself appeared. The relationship was built slowly with daily messages, declarations of love and a promise of marriage, so that by the time money was requested the target was emotionally invested rather than evaluating a proposition. AI-generated hospital photographs, tailored to each new claim, answered the natural demand for proof, and a fabricated passport addressed identity doubts. The medical emergency supplied urgency, and the story that the actor's assets were frozen in divorce explained why a wealthy man would need her money at all.",
      "lessons": "Any claim of celebrity contact should be treated as fraudulent absent verified representation, and banks flagging repeated large outbound transfers from an unusual customer profile can interrupt the sequence.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Nigerian scammers accused in AI-driven fake Brad Pitt fraud",
          "url": "https://www.france24.com/en/live-news/20250121-nigerian-scammers-accused-in-ai-driven-fake-brad-pitt-fraud",
          "publisher": "AFP via France 24"
        },
        {
          "title": "AI Brad Pitt convinced a French woman to pay EUR 830K for kidney treatment",
          "url": "https://www.ccn.com/news/technology/ai-brad-pitt-convinced-french-woman-pay-e830k/",
          "publisher": "CCN"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-french-woman-loses-eur-830-000-to-an-ai-image-brad-pitt-romance-scam",
      "year": 2023,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-french-woman-loses-eur-830-000-to-an-ai-image-brad-pitt-romance-scam"
    },
    {
      "title": "Nature's Sunshine loses $4.8 million in BEC against Synergy Japan unit",
      "date": "2023-02",
      "date_precision": "month",
      "victim_org": "Nature's Sunshine Products, Inc. (Synergy Japan)",
      "sector": "Consumer",
      "country": "Japan",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "Unknown",
      "ai_notes": "The company's filing did not describe the impersonation technique or reference AI.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 4800000,
      "loss_note": "$4.8 million in fraudulently induced wire transfers between February 1 and February 17, 2023. Recovery amount not disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Nature's Sunshine Products disclosed in a Form 8-K filed February 24, 2023 that a criminal scheme involving employee impersonation and fraudulent requests targeting its Synergy Japan operations produced a series of fraudulently induced wire transfers totaling $4.8 million between February 1 and February 17, 2023. The company discovered the fraud on February 17, 2023, contacted its bank and law enforcement to attempt recovery, and said it had identified no additional fraudulent activity.",
      "how_it_worked": "The attackers focused on a foreign subsidiary, where distance from group finance, language differences and time-zone gaps weaken verification. Impersonating company personnel, they submitted payment requests over a seventeen-day window rather than a single lump sum, letting each transfer pass as an ordinary local disbursement while the cumulative total reached $4.8 million. Because the requests appeared internal and no technical compromise of company systems was reported, they moved through the subsidiary's normal approval path unchallenged. The pattern was recognized only when the cluster of transfers was reviewed together, after which the parent engaged its bank and law enforcement and reviewed controls across its international units.",
      "lessons": "Cumulative velocity monitoring across a subsidiary's outbound payments, not just per-transaction limits, is what surfaces a drip-feed impersonation scheme before it reaches millions.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Nature's Sunshine Products, Inc. Form 8-K, Item 8.01 (filed February 24, 2023)",
          "url": "https://www.sec.gov/Archives/edgar/data/275053/000027505323000003/natr-20230217.htm",
          "publisher": "U.S. Securities and Exchange Commission (EDGAR)"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-nature-s-sunshine-loses-4-8-million-in-bec-against-synergy-japan-unit",
      "year": 2023,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-nature-s-sunshine-loses-4-8-million-in-bec-against-synergy-japan-unit"
    },
    {
      "title": "Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers",
      "date": "2023-01-11",
      "date_precision": "day",
      "victim_org": "Mailchimp (Intuit)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure published; downstream Trezor customers were subsequently targeted by wallet-draining phishing.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.",
      "how_it_worked": "Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.",
      "lessons": "Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Mailchimp suffers another data breach after social engineering attack on employees",
          "url": "https://www.computing.co.uk/news/4063093/mailchimp-suffers-breach-social-engineering-attack-employees",
          "publisher": "Computing"
        },
        {
          "title": "DigitalOcean says customer email addresses were exposed",
          "url": "https://techcrunch.com/2022/08/16/digitalocean-emails-mailchimp-breach/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Impact to DigitalOcean customers resulting from Mailchimp security incident",
          "url": "https://www.digitalocean.com/blog/digitalocean-response-to-mailchimp-security-incident",
          "publisher": "DigitalOcean"
        },
        {
          "title": "Mailchimp suffers third breach in 12 months",
          "url": "https://www.computerweekly.com/news/252529368/Mailchimp-suffers-third-breach-in-12-months",
          "publisher": "Computer Weekly"
        },
        {
          "title": "IOTW: Mailchimp suffers another social engineering attack",
          "url": "https://www.cshub.com/attacks/news/iotw-mailchimp-suffers-another-social-engineering-attack",
          "publisher": "Cyber Security Hub"
        },
        {
          "title": "Mailchimp discloses a new security breach, the second one in 6 months",
          "url": "https://securityaffairs.com/140997/data-breach/mailchimp-security-breach.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "Companies impacted by Mailchimp data breach warn their customers",
          "url": "https://securityaffairs.com/141203/data-breach/companies-impacted-by-mailchimp-breach.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor"
    },
    {
      "title": "Riot Games loses League of Legends source code to a social engineering attack",
      "date": "2023-01",
      "date_precision": "month",
      "victim_org": "Riot Games",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Extortion",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "Riot refused the $10 million ransom demand and did not publish remediation costs.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Riot Games disclosed in January 2023 that attackers used social engineering to compromise its development environment and steal source code for League of Legends and Teamfight Tactics along with a legacy anti-cheat platform. The company received a ransom email demanding $10 million and publicly refused to pay. Riot said no player data or personal information was compromised, but the intrusion disrupted its build pipeline and delayed game patches.",
      "how_it_worked": "Riot attributed the intrusion to social engineering rather than a software vulnerability and said an employee's access was the entry point, without publishing the script used. The attackers' goal shaped the tradecraft: rather than encrypting systems they moved quietly into the build and source environment, took the anti-cheat and game code that has resale value in the cheat-development market, and only surfaced afterwards with an emailed extortion demand. Riot's refusal to pay, and its public commitment to publish a post-incident report, limited the leverage the stolen code created.",
      "lessons": "Source and build environments should require phishing-resistant MFA and device trust separately from general corporate SSO, so one socially engineered employee cannot reach them.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Riot Games receives 'ransom email' for stolen source code following social engineering attack",
          "url": "https://therecord.media/riot-games-receives-ransom-email-for-stolen-source-code-following-social-engineering-attack",
          "publisher": "The Record"
        },
        {
          "title": "Riot Games receives ransom demand from hackers, refuses to pay",
          "url": "https://www.bleepingcomputer.com/news/security/riot-games-receives-ransom-demand-from-hackers-refuses-to-pay/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a",
      "year": 2023,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a"
    },
    {
      "title": "FTC: business and government impersonation scams hit $1.1 billion in 2023",
      "date": "2023",
      "date_precision": "year",
      "victim_org": "US consumers (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Tech Support Scam",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Smishing (SMS)",
        "Callback Phishing (TOAD)"
      ],
      "ai_involvement": "Unknown",
      "ai_notes": "The 2024 data spotlight does not break out AI-enabled impersonation.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft",
        "Identity Theft"
      ],
      "loss_usd": 1100000000,
      "loss_note": "$1.1 billion in combined reported losses to business and government impersonation scams in 2023, more than triple the $310 million reported in 2020. Over 330,000 business impersonation reports and nearly 160,000 government impersonation reports, together about 48 percent of fraud reports made directly to the FTC.",
      "records_affected": 490000,
      "threat_actor": null,
      "summary": "An FTC data spotlight published in April 2024 found that consumers reported losing $1.1 billion to business and government impersonation scams in 2023, more than triple the 2020 figure. The FTC received over 330,000 reports of business impersonation and nearly 160,000 of government impersonation, together accounting for roughly 48 percent of fraud reports filed directly with the agency. The report documents a shift toward bank transfers, wires, ACH, Zelle and Bitcoin ATMs alongside continuing gift card abuse.",
      "how_it_worked": "The dominant openers are bogus account security alerts purporting to come from a company such as Amazon or from a bank, claiming unauthorised activity and steering the victim toward transferring funds or feeding cash into a Bitcoin ATM to protect their money. A second pattern is the fake subscription renewal notice, often impersonating Geek Squad, which offers a refund and then coerces the victim into buying gift cards and reading out the numbers. The most damaging innovation is the multi-agency handoff: scammers who begin as a business then transfer the victim to a fake bank representative, FBI agent or even a purported FTC employee, so that each successive persona corroborates the last.",
      "lessons": "No government agency or legitimate business asks anyone to move money to protect it or to pay in gift cards or Bitcoin ATM deposits; retailer and ATM operator interdiction prompts at the point of payment are the strongest late-stage control.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Impersonation scams: not what they used to be",
          "url": "https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2024/04/impersonation-scams-not-what-they-used-be",
          "publisher": "Federal Trade Commission"
        }
      ],
      "entry_type": "benchmark",
      "slug": "2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023",
      "year": 2023,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2023-ftc-business-and-government-impersonation-scams-hit-1-1-billion-in-2023"
    },
    {
      "title": "Activision breached after an HR employee falls for an SMS phishing message",
      "date": "2022-12-04",
      "date_precision": "day",
      "victim_org": "Activision Blizzard",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed.",
      "records_affected": 19444,
      "threat_actor": null,
      "summary": "Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.",
      "how_it_worked": "The attacker sent text messages to an HR employee that led to credential capture, then used the account to move into internal collaboration systems. Once inside Slack, the intruder posted messages attempting to lure additional employees into clicking further links, using the credibility of an internal account to widen the compromise. They also accessed a spreadsheet of employee information including names, email addresses, phone numbers, salaries and office locations, and the marketing content calendar. Screenshots of the internal Slack activity and the stolen data were later published by researchers and on a hacking forum.",
      "lessons": "Phishing-resistant MFA on corporate identity, plus alerting on internal chat messages that contain newly-registered external links, limits both the initial takeover and the internal spread.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Activision confirms data breach exposing employee and game info",
          "url": "https://www.bleepingcomputer.com/news/security/activision-confirms-data-breach-exposing-employee-and-game-info/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Hackers steal Activision games and employee data",
          "url": "https://techcrunch.com/2023/02/21/hackers-allegedly-steal-activision-games-and-employee-data/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Activision Data Breach Contains Employee Details, Call of Duty's Future, and More",
          "url": "https://insider-gaming.com/activision-data-breach/",
          "publisher": "Insider Gaming"
        },
        {
          "title": "Threat actors leak Activision employee data on hacking forum",
          "url": "https://securityaffairs.com/142779/data-breach/activision-data-leak.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-activision-breached-after-an-hr-employee-falls-for-an-sms-phishing-messa",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-activision-breached-after-an-hr-employee-falls-for-an-sms-phishing-messa"
    },
    {
      "title": "SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night",
      "date": "2022-11-11",
      "date_precision": "day",
      "victim_org": "FTX (referred to as 'Victim 1' in the indictment)",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Physical Pretexting"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported; the impersonation used a physical fake ID at a retail store.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Identity Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 400000000,
      "loss_note": "The DOJ indictment concerns a theft of roughly $400 million. FTX administrators reported $413 million in unauthorised transfers, and Elliptic valued the outflow at $477 million. Prosecutors have not officially named FTX as the victim.",
      "records_affected": null,
      "threat_actor": "Robert Powell ('ElSwapo1', the 'Powell SIM Swapping Crew'), Emily Hernandez, Carter Rohn",
      "summary": "On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.",
      "how_it_worked": "A member of the crew walked into an AT&T retail location carrying a counterfeit ID in the target's name and asked staff to move the number to a new device. The store employee, following normal identity-check procedure against a document that looked genuine, completed the port. From that point every SMS one-time code and password-reset link for the target's accounts arrived on the attackers' handset. The crew used those codes to reach account credentials and then initiated the transfers out of FTX wallets, timed to a night when the company was in bankruptcy chaos and unusual outflows were least likely to be challenged.",
      "lessons": "Enterprise-controlled authentication that never touches a consumer mobile number, combined with number-lock and in-person ID escalation at carrier retail, closes the pathway a physical fake ID otherwise opens.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Arrests in $400M SIM-Swap Tied to Heist at FTX?",
          "url": "https://krebsonsecurity.com/2024/02/arrests-in-400m-sim-swap-tied-to-heist-at-ftx/",
          "publisher": "Krebs on Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night",
      "year": 2022,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-sim-swap-at-an-at-t-store-enabled-the-400m-ftx-drain-on-bankruptcy-night"
    },
    {
      "title": "Ramon 'Hushpuppi' Abbas sentenced for laundering BEC and cyber-heist proceeds",
      "date": "2022-11-07",
      "date_precision": "day",
      "victim_org": "Multiple (New York law firm, a Maltese bank, a Qatari businessman, others)",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Romance / Investment Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "Restitution ordered of $1,732,841. Individual episodes included about $922,857 fraudulently induced from a New York law firm in October 2019 and an intended $14.7 million from a foreign bank cyber-heist; prosecutors said he conspired to launder over $300 million.",
      "records_affected": null,
      "threat_actor": "Ramon Olorunwa Abbas ('Ray Hushpuppi'), Nigeria/UAE, with co-conspirator Ghaleb Alaumary",
      "summary": "Ramon Olorunwa Abbas, the Instagram figure known as Ray Hushpuppi, was arrested in Dubai in June 2020, pleaded guilty in April 2021 and was sentenced on November 7, 2022 to 135 months in federal prison with $1,732,841 in restitution. He laundered proceeds of business email compromise frauds, bank cyber-heists and school-financing scams, including about $922,857 induced from a New York law firm and funds from a January 2019 attack on a Maltese bank.",
      "how_it_worked": "Abbas supplied the financial plumbing that makes BEC profitable. Co-conspirators compromised or spoofed the email of parties to real transactions, such as a law firm holding client funds for a closing, and issued altered wire instructions that matched a payment the victim already expected to make. Abbas provided and coordinated the receiving accounts, including accounts opened with fraudulent identity documents, and moved the proceeds rapidly across jurisdictions to defeat recall. He also ran advance-fee variants, extracting roughly $330,000 from a Qatari businessman seeking a $15 million school loan and then demanding further payments framed as taxes.",
      "lessons": "Payment recipients in escrow and closing transactions should be verified by phone against instructions exchanged before the transaction opened, since the diversion email typically arrives at the exact moment a payment is expected.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Nigerian Man Sentenced to Over 11 Years in Federal Prison for Conspiring to Launder Tens of Millions of Dollars from Online Scams",
          "url": "https://www.justice.gov/usao-cdca/pr/nigerian-man-sentenced-over-11-years-federal-prison-conspiring-launder-tens-millions",
          "publisher": "U.S. Department of Justice, C.D. Cal."
        }
      ],
      "entry_type": "campaign",
      "slug": "2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-ramon-hushpuppi-abbas-sentenced-for-laundering-bec-and-cyber-heist-proce"
    },
    {
      "title": "Dropbox loses 130 GitHub repositories to CircleCI-impersonating phishing",
      "date": "2022-10-14",
      "date_precision": "day",
      "victim_org": "Dropbox",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.",
      "how_it_worked": "The lure imitated CircleCI, a service Dropbox developers used and which legitimately prompts users to sign in with GitHub, so the request to authenticate looked routine. The phishing page collected the GitHub username, password and the time-based one-time passcode, which the attacker replayed immediately to establish a session. With developer access they cloned 130 private repositories containing modified third-party libraries, internal prototypes, and some security team tools and configuration files, along with a few thousand names and email addresses for employees, current and past customers, sales leads and vendors. Dropbox rotated credentials and moved to accelerate its rollout of hardware security keys.",
      "lessons": "Time-based one-time passcodes are phishable in real time; WebAuthn keys on source-control accounts, and machine-to-machine tokens scoped per repository, remove both halves of this attack.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "130 Dropbox code repos plundered after successful phishing attack",
          "url": "https://www.helpnetsecurity.com/2022/11/02/dropbox-data-breach/",
          "publisher": "Help Net Security"
        },
        {
          "title": "Dropbox Suffers Data Breach From Phishing Attack, Exposing Customer and Employee Emails",
          "url": "https://blog.gitguardian.com/dropbox-breach-hack-github-circleci/",
          "publisher": "GitGuardian"
        },
        {
          "title": "Dropbox confirms serious security breach in which hackers stole code from 130 GitHub repositories",
          "url": "https://betanews.com/2022/11/02/dropbox-confirms-serious-security-breach-in-which-hackers-stole-code-from-130-github-repositories/",
          "publisher": "BetaNews"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-dropbox-loses-130-github-repositories-to-circleci-impersonating-phishing"
    },
    {
      "title": "Zendesk breach followed successful SMS phishing of employees",
      "date": "2022-10",
      "date_precision": "month",
      "victim_org": "Zendesk",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.",
      "how_it_worked": "Employees received text messages that led to a page impersonating Zendesk's single sign-on portal. Several staff entered their credentials, which the attacker used to authenticate to internal systems. Because Zendesk operates a support ticketing platform for other businesses, mailboxes and ticket stores can contain customer correspondence, attachments and account details belonging to Zendesk's own clients, which is what created the downstream exposure. Zendesk described the incident as a sophisticated SMS phishing campaign, disabled the affected accounts and notified customers whose service data may have been reached.",
      "lessons": "SaaS providers holding tenant data should mandate phishing-resistant MFA for all staff and alert on employee logins from unfamiliar devices to tenant-facing consoles.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Zendesk Hacked After Employees Fall for Phishing Attack",
          "url": "https://www.securityweek.com/zendesk-hacked-after-employees-fall-for-phishing-attack/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Compromised Zendesk Employee Credentials Lead to Breach",
          "url": "https://www.darkreading.com/application-security/compromised-zendesk-employee-credentials-breach",
          "publisher": "Dark Reading"
        },
        {
          "title": "Zendesk hit by phishing-related data breach",
          "url": "https://www.scworld.com/brief/zendesk-hit-by-phishing-related-data-breach",
          "publisher": "SC Media"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-zendesk-breach-followed-successful-sms-phishing-of-employees",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-zendesk-breach-followed-successful-sms-phishing-of-employees"
    },
    {
      "slug": "2022-bed-bath-beyond-discloses-data-breach-to-sec-after-an-employee-was-phish",
      "title": "Bed Bath & Beyond discloses data breach to SEC after an employee was phished",
      "date": "2022-10",
      "date_precision": "month",
      "year": 2022,
      "victim_org": "Bed Bath & Beyond",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Bed Bath & Beyond disclosed in an SEC Form 8-K filed on 28 October 2022 that a third party had improperly accessed company data after a successful phishing attack against one employee. The access covered files on that employee's hard drive and certain shared drives. The retailer said it had no reason to believe sensitive or personally identifiable information was accessed, and declined to say what data the drives contained.",
      "how_it_worked": "A single employee at the retailer was targeted with a phishing message and fell for it, handing the attacker access to that employee's account. What followed illustrates why one employee's compromise is rarely contained to one employee: the attacker reached not only files on the individual's own hard drive but also the shared network drives that the account had rights to open. Corporate shared drives accumulate years of departmental documents that no one has reviewed for sensitivity. The retailer disclosed the event as a material item to the SEC while investigation was still under way, and did not detail the phishing method used.",
      "lessons": "Least-privilege access to shared drives and periodic review of what accumulates on them decide how much one phished account is actually worth.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Bed, Bath & Beyond confirms data breach following employee phishing attack",
          "url": "https://techcrunch.com/2022/10/31/bed-bath-beyond-data-breach/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Bed Bath & Beyond Investigating Data Breach After Employee Falls for Phishing Attack",
          "url": "https://www.securityweek.com/bed-bath-beyond-investigating-data-breach-after-employee-falls-phishing-attack/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-bed-bath-beyond-discloses-data-breach-to-sec-after-an-employee-was-phish"
    },
    {
      "slug": "2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx",
      "title": "3Commas users phished for API keys, leading to unauthorised trades on FTX accounts",
      "date": "2022-10",
      "date_precision": "month",
      "year": 2022,
      "victim_org": "3Commas users (with linked FTX and Binance accounts)",
      "sector": "Cryptocurrency",
      "country": "Estonia",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Cryptocurrency Theft",
        "Credential Theft"
      ],
      "loss_usd": 6000000,
      "loss_kind": "aggregate",
      "loss_note": "Reported aggregate user losses of roughly US$6 million across affected accounts; FTX said it would compensate some affected users. Individual reported losses ranged widely.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.",
      "how_it_worked": "Attackers stood up phishing sites imitating 3Commas and lured users, mainly through crypto community channels and search, into connecting their exchange accounts there. Victims typed their exchange API keys into the fake interface believing they were configuring a trading bot, which is exactly what a real 3Commas onboarding asks for, so the request was indistinguishable from the legitimate flow. With trading-enabled API keys the attackers did not need to withdraw funds, which would have hit withdrawal controls; instead they ran wash trades against illiquid pairs, moving value out of victims' accounts through the market itself.",
      "lessons": "API keys should be issued with the narrowest permissions and an IP allowlist, and platforms should never accept exchange keys through a page a user reached from an untrusted link.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "FTX API keys connected to 3Commas confirmed to have been exploited",
          "url": "https://www.theblock.co/post/179237/ftx-api-keys-3commas-exploited",
          "publisher": "The Block"
        },
        {
          "title": "3Commas legal statement in regard of violated API keys",
          "url": "https://3commas.io/blog/3commas-legal-statement-in-regard-of-violated-api-keys",
          "publisher": "3Commas"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx"
    },
    {
      "title": "Rockstar Games internal Slack breached and GTA 6 footage leaked",
      "date": "2022-09-18",
      "date_precision": "day",
      "victim_org": "Rockstar Games",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "Rockstar and parent Take-Two did not quantify losses publicly.",
      "records_affected": null,
      "threat_actor": "Arion Kurtaj, linked to Lapsus$ (same actor as the Uber intrusion)",
      "summary": "An actor using the handle teapotuberhacker, the same persona behind the Uber intrusion days earlier, posted roughly 90 in-development Grand Theft Auto VI videos and claimed to hold GTA V and GTA VI source code, saying they had reached Rockstar's internal Slack and Confluence. Rockstar confirmed a network intrusion and unauthorised access to early development footage. A UK teenager, Arion Kurtaj, was later convicted and in December 2023 given an indefinite hospital order.",
      "how_it_worked": "The actor did not publish a technical exploit chain, and Rockstar has never described the entry point, so the mechanics are attacker-claimed and inferred from the same operator's behaviour at Uber days earlier: harvesting employee credentials and then talking a human into approving access, followed by collection from collaboration platforms rather than code repositories. Once inside Slack and Confluence the value was not code execution but corporate memory, build videos, design documents and chat, which the actor packaged directly into an extortion attempt and a public leak.",
      "lessons": "Collaboration platforms hold the crown jewels for a media company and deserve the same phishing-resistant MFA, device trust and data-egress monitoring as source control.",
      "confidence": "Alleged",
      "sources": [
        {
          "title": "Alleged Grand Theft Auto 6 (GTA6) gameplay videos and source code leaked online",
          "url": "https://securityaffairs.com/135923/data-breach/gta6-gameplay-videos-source-code-leak.html",
          "publisher": "Security Affairs"
        },
        {
          "title": "London Police arrested a teen suspected to be behind Uber, Rockstar Games breaches",
          "url": "https://securityaffairs.com/136146/cyber-crime/uber-rockstar-games-hacker-arrest.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked"
    },
    {
      "slug": "2022-github-warns-of-phishing-campaign-impersonating-circleci-to-steal-develo",
      "title": "GitHub warns of phishing campaign impersonating CircleCI to steal developer credentials",
      "date": "2022-09-16",
      "date_precision": "day",
      "year": 2022,
      "victim_org": "GitHub users and customer organisations (GitHub-reported campaign)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "GitHub issued a security alert on 21 September 2022 about a phishing campaign, first seen on 16 September, in which attackers impersonated the CI/CD service CircleCI to harvest GitHub credentials and time-based one-time passcodes. Attackers who succeeded immediately created personal access tokens, authorised OAuth apps or added SSH keys to keep access, and in some cases cloned private repositories and pushed changes. GitHub suspended affected accounts and reset credentials.",
      "how_it_worked": "Developers received emails claiming that CircleCI's terms of service and privacy policy had changed and that they needed to sign in to their GitHub account to keep using the service. The link led to a convincing GitHub log-in page under attacker control, which relayed the entered username, password and TOTP code to the real GitHub in real time. The pretext worked because CircleCI is a legitimate part of many developers' daily toolchain and a policy-update notice is mundane, while the audience, engineers with repository and token privileges, is exactly the population whose accounts unlock source code and downstream software supply chains.",
      "lessons": "Hardware security keys are the only MFA form that survives a real-time relay, and organisations should alert on new personal access tokens, OAuth grants and SSH keys added to developer accounts.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Security alert: new phishing campaign targets GitHub users",
          "url": "https://github.blog/news-insights/company-news/security-alert-new-phishing-campaign-targets-github-users/",
          "publisher": "The GitHub Blog"
        },
        {
          "title": "Hackers Using Fake CircleCI Notifications to Hack GitHub Accounts",
          "url": "https://thehackernews.com/2022/09/hackers-using-fake-circleci.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-github-warns-of-phishing-campaign-impersonating-circleci-to-steal-develo"
    },
    {
      "title": "Uber breached after MFA push bombing and a WhatsApp message posing as IT",
      "date": "2022-09-15",
      "date_precision": "day",
      "victim_org": "Uber Technologies",
      "sector": "Transportation & Logistics",
      "country": "United States",
      "primary_vector": "MFA Fatigue / Push Bombing",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Insider Access",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No monetary loss disclosed; Uber said no public-facing systems or user accounts were accessed.",
      "records_affected": null,
      "threat_actor": "Lapsus$ (an 18-year-old member was later convicted in the UK)",
      "summary": "In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.",
      "how_it_worked": "With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.",
      "lessons": "Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/uber-breach-external-contractor-mfa-bombing-attack",
          "publisher": "Dark Reading"
        },
        {
          "title": "Lessons to learn from the Uber security breach",
          "url": "https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/09/27-september-2022-lessons-to-learn-from-the-uber-security-breach.pdf.coredownload.inline.pdf",
          "publisher": "KPMG"
        },
        {
          "title": "Detecting Scatter Swine: Insights into a Relentless Phishing Campaign",
          "url": "https://sec.okta.com/articles/scatterswine/",
          "publisher": "Okta Security"
        },
        {
          "title": "Security Update",
          "url": "https://www.uber.com/newsroom/security-update/",
          "publisher": "Uber"
        },
        {
          "title": "Uber links breach to Lapsus$ group, blames contractor for hack",
          "url": "https://www.bleepingcomputer.com/news/security/uber-links-breach-to-lapsus-group-blames-contractor-for-hack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it"
    },
    {
      "title": "DoorDash customer data exposed through phished third-party vendor employees",
      "date": "2022-08-25",
      "date_precision": "day",
      "victim_org": "DoorDash",
      "sector": "Transportation & Logistics",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Smishing (SMS)",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed.",
      "records_affected": null,
      "threat_actor": "Scatter Swine / 0ktapus (the campaign that also hit Twilio)",
      "summary": "DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.",
      "how_it_worked": "The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.",
      "lessons": "Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "DoorDash hit by data breach linked to Twilio hackers",
          "url": "https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/",
          "publisher": "TechCrunch"
        },
        {
          "title": "DoorDash discloses new data breach tied to Twilio hackers",
          "url": "https://www.bleepingcomputer.com/news/security/doordash-discloses-new-data-breach-tied-to-twilio-hackers/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others",
          "url": "https://www.securityweek.com/doordash-data-compromised-following-twilio-hack/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ"
    },
    {
      "title": "Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers",
      "date": "2022-08-04",
      "date_precision": "day",
      "victim_org": "Twilio",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported; the kit relayed credentials to operators via Telegram in real time.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_note": "No aggregate loss figure published across the affected organisations.",
      "records_affected": null,
      "threat_actor": "Scatter Swine / 0ktapus (tracked by Okta and Group-IB; overlaps with Scattered Spider reporting)",
      "summary": "In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.",
      "how_it_worked": "The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.",
      "lessons": "SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Detecting Scatter Swine: Insights into a Relentless Phishing Campaign",
          "url": "https://sec.okta.com/articles/scatterswine/",
          "publisher": "Okta Security"
        },
        {
          "title": "Twilio confirms data breach after its employees got phished",
          "url": "https://www.helpnetsecurity.com/2022/08/09/twilio-phished-data-breach/",
          "publisher": "Help Net Security"
        },
        {
          "title": "Twilio says breach also compromised Authy two-factor app users",
          "url": "https://techcrunch.com/2022/08/26/twilio-breach-authy/",
          "publisher": "TechCrunch"
        },
        {
          "title": "Incident Report: Employee and Customer Account Compromise",
          "url": "https://www.twilio.com/en-us/blog/archive/2022/august-2022-social-engineering-attack",
          "publisher": "Twilio"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust"
    },
    {
      "slug": "2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai",
      "title": "Klaviyo employee phished; attacker used internal tools to take crypto mailing lists",
      "date": "2022-08-03",
      "date_precision": "day",
      "year": 2022,
      "victim_org": "Klaviyo",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.",
      "how_it_worked": "The employee's log-in credentials were captured through a phishing attack, giving the attacker an authenticated session inside Klaviyo's internal support environment. From there the operation was pure search: the attacker queried the customer base specifically for cryptocurrency companies and pulled their subscriber lists. The objective was never Klaviyo itself but the audience data its crypto customers had entrusted to it, because a verified list of a crypto exchange's subscribers is a ready-made target set for wallet-draining phishing. Klaviyo subsequently restricted employee access to internal tooling and improved detection of anomalous internal behaviour.",
      "lessons": "Phishing-resistant MFA on staff accounts plus alerting on unusual cross-tenant queries in support tools would have caught a search pattern this specific.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Klaviyo security incident",
          "url": "https://www.klaviyo.com/blog/august-2022-security-incident",
          "publisher": "Klaviyo"
        },
        {
          "title": "Email marketing firm hacked to steal crypto-focused mailing lists",
          "url": "https://www.bleepingcomputer.com/news/security/email-marketing-firm-hacked-to-steal-crypto-focused-mailing-lists/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai"
    },
    {
      "title": "Deepfake of Binance communications chief used to scam crypto projects on video calls",
      "date": "2022-08",
      "date_precision": "month",
      "victim_org": "Multiple cryptocurrency projects seeking Binance listings",
      "sector": "Cryptocurrency",
      "country": "Multiple countries",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [
        "Romance / Investment Scam"
      ],
      "ai_involvement": "Confirmed AI-enabled",
      "ai_notes": "Binance chief communications officer Patrick Hillmann said attackers built an AI video 'hologram' of him from his past news interviews and TV appearances and used it live on Zoom calls.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Cryptocurrency Theft"
      ],
      "loss_usd": null,
      "loss_note": "Losses to individual projects were not disclosed",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In August 2022 Binance disclosed that a 'sophisticated hacking team' had produced a deepfake video likeness of chief communications officer Patrick Hillmann and used it on Zoom calls with representatives of cryptocurrency projects. The impersonator offered help getting tokens listed on Binance and solicited payments and information. Hillmann said several project managers were convinced before the fraud was discovered, and that the clone was built from his publicly available interview footage.",
      "how_it_worked": "The pretext was the single thing small crypto projects want most, a listing on the largest exchange, and the caller occupied a role that plausibly controls access to it. Contact was made over social channels and then escalated to a Zoom call, where the deepfake of a face the targets had seen in Binance media coverage supplied the trust signal that a mere email could not. Because listing discussions are routinely confidential and involve fees, requests for money and business documents did not look out of place. Victims were pushed to move fast on the implied scarcity of a listing slot, and only later checked with Binance through official channels.",
      "lessons": "Exchange listing and partnership discussions should be confirmed through the company's published contact channels, and no vendor should treat a video likeness as proof of employment.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Binance exec says scammers made a deepfake hologram of him",
          "url": "https://www.theregister.com/2022/08/23/binance_deepfake_scam/",
          "publisher": "The Register"
        },
        {
          "title": "Deepfake hologram targets Binance and crypto community",
          "url": "https://www.malwarebytes.com/blog/news/2022/08/deepfake-hologram-targets-binance-and-crypto-community",
          "publisher": "Malwarebytes Labs"
        }
      ],
      "entry_type": "campaign",
      "slug": "2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on"
    },
    {
      "slug": "2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org",
      "title": "0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations",
      "date": "2022-08",
      "date_precision": "month",
      "year": 2022,
      "victim_org": "Over 130 organisations targeted (Group-IB tracked campaign)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Data Breach",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 9931,
      "threat_actor": "0ktapus (linked to Scattered Spider / UNC3944 activity)",
      "summary": "Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.",
      "how_it_worked": "Employees received text messages, often outside working hours, claiming their VPN session had expired or that a schedule change required immediate action, with a link to what looked like their employer's Okta single sign-on page. The pages were cloned per target company, so each recipient saw their own branding. Victims typed their username, password and then the one-time MFA code, all of which were relayed to the operators in real time and used to log in before the code expired. SMS was chosen deliberately: it arrives on a phone, outside corporate email defences, and reads as urgent IT housekeeping rather than an attack.",
      "lessons": "Only phishing-resistant authentication such as FIDO2 security keys defeats a real-time relay of passwords and one-time codes; SMS-delivered lures also need out-of-band IT verification channels staff actually know to use.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Roasting 0ktapus: The phishing campaign going after Okta identity credentials",
          "url": "https://www.group-ib.com/blog/0ktapus/",
          "publisher": "Group-IB"
        },
        {
          "title": "0ktapus Phishing Campaign Targets Okta Identity Credentials",
          "url": "https://www.infosecurity-magazine.com/news/0ktapus-phishing-targets-okta/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org"
    },
    {
      "title": "Cloudflare blocks the same SMS phishing attack that breached Twilio",
      "date": "2022-07-20",
      "date_precision": "day",
      "victim_org": "Cloudflare",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Smishing (SMS)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Attempt Blocked",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No loss; the intrusion attempt failed at the authentication step.",
      "records_affected": null,
      "threat_actor": "Scatter Swine / 0ktapus (same actor as the Twilio campaign)",
      "summary": "On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.",
      "how_it_worked": "The SMS lures directed staff to a convincing clone of Cloudflare's Okta sign-in page. Credentials typed into the clone were relayed in real time over Telegram, and the page also prompted for the second factor so operators could complete the login within the code's validity window. It additionally attempted to push AnyDesk remote access software to visitors for persistence if the credential path failed. Three employees submitted credentials, but the hardware keys are bound to the legitimate origin and would not produce a valid assertion for the attacker's domain, so no session was ever established. Cloudflare Gateway also blocked the malicious domain on corporate devices, and none of the targets installed the remote access tool.",
      "lessons": "This is the control demonstration for the whole category: origin-bound hardware security keys make credential relay structurally impossible, regardless of how convincing the lure is.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "The mechanics of a sophisticated phishing scam and how we stopped it",
          "url": "https://blog.cloudflare.com/2022-07-sms-phishing-attacks/",
          "publisher": "Cloudflare Blog"
        },
        {
          "title": "Cloudflare employees also hit by hackers behind Twilio breach",
          "url": "https://www.bleepingcomputer.com/news/security/cloudflare-employees-also-hit-by-hackers-behind-twilio-breach/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Cloudflare scuppers Twilio-like cyber attack with hardware keys",
          "url": "https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys",
          "publisher": "IT Pro"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio"
    },
    {
      "slug": "2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or",
      "title": "Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations",
      "date": "2022-07-12",
      "date_precision": "day",
      "year": 2022,
      "victim_org": "More than 10,000 organisations targeted (Microsoft-tracked campaign)",
      "sector": "Technology",
      "country": "Global",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Business Email Compromise",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Wire Fraud / Financial Loss",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.",
      "how_it_worked": "Targets received phishing emails, often disguised as voice message notifications, linking to a proxy server that displayed the genuine Microsoft log-in page. The victim typed their real password and completed their real MFA challenge, both of which were passed straight through to Microsoft, so the experience was indistinguishable from a normal log-in. The proxy captured the resulting session cookie, which the attacker replayed to enter the mailbox without any further authentication. Microsoft observed operators moving to payment fraud within minutes, hunting invoice threads, adding hidden mailbox rules to suppress replies and emailing the victim's suppliers with altered bank details.",
      "lessons": "Standard MFA is not proof against session-token theft; phishing-resistant credentials bound to the origin, plus conditional access on device compliance and token protection, are what break the proxy.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud",
          "url": "https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/",
          "publisher": "Microsoft Security Blog"
        },
        {
          "title": "Microsoft: 10,000 Organizations Targeted in Large-Scale Phishing Campaign",
          "url": "https://www.securityweek.com/microsoft-10000-organizations-targeted-large-scale-phishing-campaign/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or"
    },
    {
      "slug": "2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m",
      "title": "American Airlines discloses breach after phishing compromised employee mailboxes",
      "date": "2022-07",
      "date_precision": "month",
      "year": 2022,
      "victim_org": "American Airlines",
      "sector": "Transportation & Logistics",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 1708,
      "threat_actor": null,
      "summary": "American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.",
      "how_it_worked": "Attackers phished American Airlines employees and captured their mailbox credentials. The consequences ran in two directions. Inbound, the mailboxes held correspondence containing customer and employee identity documents, passport and driver's licence numbers among them, which is what made a small number of accounts a reportable data breach. Outbound, the attackers used the genuine airline accounts to send more phishing, because a message that actually originates from an American Airlines address passes authentication checks and carries the brand's credibility with recipients. The airline said it had no evidence of misuse but notified affected individuals and offered identity protection.",
      "lessons": "MFA on corporate mail plus data-loss controls that keep identity documents out of mailboxes limit both the exposure and the reuse of the account for onward phishing.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "American Airlines discloses data breach after employee email compromise",
          "url": "https://www.bleepingcomputer.com/news/security/american-airlines-discloses-data-breach-after-employee-email-compromise/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "American Airlines Says Personal Data Exposed After Email Phishing Attack",
          "url": "https://www.securityweek.com/american-airlines-says-personal-data-exposed-after-email-phishing-attack/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m"
    },
    {
      "title": "Phishing of a Harmony developer preceded the $100M Horizon Bridge theft",
      "date": "2022-06-23",
      "date_precision": "day",
      "victim_org": "Harmony (Horizon Bridge)",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 100000000,
      "loss_note": "The FBI put the theft at $100 million in virtual currency, spanning 14 bridged assets including USDC, ETH, USDT and BNB.",
      "records_affected": null,
      "threat_actor": "Lazarus Group and APT38 (DPRK), per FBI attribution",
      "summary": "Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.",
      "how_it_worked": "Harmony stated the attackers 'employed a phishing scheme to trick at least one software developer to install malicious software on their laptop.' That access let them read internal chat threads to learn how the bridge was operated and reach non-public bridge infrastructure code, then obtain backdoor access to one or more servers. Because the Horizon Bridge used a multisignature scheme requiring only two of five signatures, compromising the operational hosts holding those keys was enough to authorise transfers. On June 23 the attackers moved fourteen bridged asset types out in a series of transactions. Harmony emphasised the bridge contracts themselves were never exploited.",
      "lessons": "Raising the signature threshold and isolating signing keys on dedicated hardware away from developer workstations would have meant that phishing one laptop could not produce a valid bridge withdrawal.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Summary of the Harmony Horizon Bridge Incident",
          "url": "https://medium.com/harmony-one/summary-of-the-harmony-horizon-bridge-incident-f9bd87c0c68e",
          "publisher": "Harmony"
        },
        {
          "title": "FBI: North Korean hackers stole $100 million in Harmony crypto hack",
          "url": "https://www.bleepingcomputer.com/news/security/fbi-north-korean-hackers-stole-100-million-in-harmony-crypto-hack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft",
      "year": 2022,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-phishing-of-a-harmony-developer-preceded-the-100m-horizon-bridge-theft"
    },
    {
      "title": "European mayors duped by deepfake video calls posing as Kyiv mayor Klitschko",
      "date": "2022-06",
      "date_precision": "month",
      "victim_org": "City governments of Berlin, Madrid and Vienna",
      "sector": "Government",
      "country": "Germany",
      "primary_vector": "Deepfake Video Call",
      "secondary_vectors": [],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Berlin's mayoral office concluded after the call that deepfake technology had been used to render Vitali Klitschko's face and voice in a live video conference; other analysts suggested edited genuine footage may have been used instead.",
      "outcomes": [
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In June 2022 the mayors of Berlin (Franziska Giffey), Madrid (Jose Luis Martinez-Almeida) and Vienna (Michael Ludwig) each held video calls with someone presenting as Kyiv mayor Vitali Klitschko. Giffey's office said the call was cut short when the topics and framing became implausible, and concluded a deepfake had been used. Klitschko linked the calls to Russian efforts to drive a wedge between Ukraine and its European partners. Attribution was never publicly established.",
      "how_it_worked": "The approach exploited an entirely normal wartime diplomatic pattern: European capitals were actively arranging solidarity calls with Ukrainian city leaders, so an inbound request for a video meeting with Klitschko fit expectations and passed through official scheduling channels. On camera the impersonator looked and sounded like a figure the mayors had seen in constant media coverage, which supplied the trust signal. The caller then steered the conversation toward politically loaded subjects, apparently to elicit quotable statements about Ukrainian refugees and support for Ukraine. Berlin's staff aborted only when the substance of the conversation, rather than the imagery, stopped making sense.",
      "lessons": "Video identity is not authentication; inbound requests for calls with senior officials should be confirmed through the counterpart's own foreign ministry or embassy channel before the meeting is booked.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "European mayors duped into calls with fake Kyiv mayor",
          "url": "https://www.clickorlando.com/news/world/2022/06/25/european-mayors-duped-into-calls-with-fake-kyiv-mayor/",
          "publisher": "Associated Press"
        },
        {
          "title": "European mayors duped into calls with fake Kyiv mayor",
          "url": "https://www.cnbc.com/2022/06/25/european-mayors-duped-into-calls-with-fake-kyiv-mayor.html",
          "publisher": "CNBC"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-european-mayors-duped-by-deepfake-video-calls-posing-as-kyiv-mayor-klits",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-european-mayors-duped-by-deepfake-video-calls-posing-as-kyiv-mayor-klits"
    },
    {
      "title": "Cisco breached after vishing and MFA fatigue against an employee",
      "date": "2022-05-24",
      "date_precision": "day",
      "victim_org": "Cisco Systems",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "MFA Fatigue / Push Bombing",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed; Cisco said no impact to its business operations, products or supply chain.",
      "records_affected": null,
      "threat_actor": "Initial access broker linked to UNC2447, Lapsus$ and Yanluowang",
      "summary": "Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.",
      "how_it_worked": "Credentials saved in Chrome were synchronised to the employee's personal Google account, which the attacker compromised. Holding valid corporate credentials, the attacker triggered a stream of MFA push prompts to wear the user down, while simultaneously calling them in English with a plausible accent posing as support from trusted organisations. The employee eventually approved one push, giving the attacker VPN access. They then enrolled new MFA devices, escalated to administrative privileges, added backdoor accounts, and used remote access tooling and LogMeIn/TeamViewer to maintain persistence, repeatedly attempting to return after eviction.",
      "lessons": "Number matching or FIDO2 keys instead of simple push approval, plus blocking browser credential sync to personal accounts on managed devices, would have closed both halves of this chain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Cisco Talos shares insights related to recent cyber attack on Cisco",
          "url": "https://blog.talosintelligence.com/recent-cyber-attack/",
          "publisher": "Cisco Talos"
        },
        {
          "title": "Cisco Confirms Network Breach Via Hacked Employee Google Account",
          "url": "https://threatpost.com/cisco-network-breach-google/180385/",
          "publisher": "Threatpost"
        },
        {
          "title": "Cisco network hack: Voice phishing and MFA fatigue gave attacker access",
          "url": "https://www.thestack.technology/cisco-network-hack-voice-phishing-mfa-fatigue/",
          "publisher": "The Stack"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee"
    },
    {
      "title": "FBI: business email compromise exposed $43 billion in losses across 177 countries",
      "date": "2022-05-04",
      "date_precision": "day",
      "victim_org": "Businesses, government entities and individuals worldwide (multi-victim campaign)",
      "sector": "Financial Services",
      "country": "Global",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "The 2022 advisory does not describe AI-enabled BEC.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Data Breach",
        "Cryptocurrency Theft"
      ],
      "loss_usd": 43312749946,
      "loss_note": "$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.",
      "records_affected": 241206,
      "threat_actor": null,
      "summary": "On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.",
      "how_it_worked": "BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.",
      "lessons": "Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Business Email Compromise: The $43 Billion Scam",
          "url": "https://www.ic3.gov/PSA/2022/PSA220504",
          "publisher": "FBI Internet Crime Complaint Center"
        }
      ],
      "entry_type": "benchmark",
      "slug": "2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co",
      "year": 2022,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"
    },
    {
      "title": "Ghostwriter credential phishing against Ukrainian government and military accounts",
      "date": "2022-05",
      "date_precision": "month",
      "victim_org": "Ukrainian government and military personnel",
      "sector": "Government",
      "country": "Ukraine",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Watering Hole / Malvertising"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Credential Theft",
        "Espionage",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "No monetary loss; Google reported no accounts were compromised in the Ghostwriter campaign it described.",
      "records_affected": null,
      "threat_actor": "Ghostwriter / UNC1151 (Belarus-attributed), alongside APT28 and Turla activity",
      "summary": "Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.",
      "how_it_worked": "Ghostwriter sent messages containing links to legitimate but compromised third-party websites that hosted the first-stage phishing page, which lends the URL an innocuous reputation and defeats simple domain blocklists. Users who clicked were redirected to attacker-controlled infrastructure presenting a replica webmail sign-in page, where entered credentials were captured. The campaign leaned on wartime urgency and the volume of official correspondence flowing to government and military staff, conditions in which recipients process messages quickly and are primed to expect unfamiliar senders and new systems.",
      "lessons": "Enrolling government and military accounts in advanced protection with hardware security keys, and treating links to unfamiliar third-party sites as untrusted regardless of domain reputation, blocks this class of harvesting.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Update on cyber activity in Eastern Europe",
          "url": "https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/",
          "publisher": "Google Threat Analysis Group"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar"
    },
    {
      "title": "Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds",
      "date": "2022-04-03",
      "date_precision": "day",
      "victim_org": "SatoshiLabs (Trezor), via email provider Mailchimp",
      "sector": "Cryptocurrency",
      "country": "Czech Republic",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Cryptocurrency Theft"
      ],
      "loss_usd": null,
      "loss_note": "Neither Trezor nor Mailchimp published a loss figure, and Trezor said at the time it was unclear whether any funds were successfully stolen. The '106,856 customers' figure that circulated came from the phishing email itself and was attacker-authored text, not a confirmed breach count.",
      "records_affected": null,
      "threat_actor": "Unattributed actor targeting cryptocurrency-sector Mailchimp tenants",
      "summary": "Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.",
      "how_it_worked": "The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.",
      "lessons": "Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Ongoing phishing attacks on Trezor users",
          "url": "https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304",
          "publisher": "Trezor (SatoshiLabs)"
        },
        {
          "title": "Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam",
          "url": "https://decrypt.co/96942/mailchimp-insider-targets-trezor-crypto-wallets-phishing-scam",
          "publisher": "Decrypt"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"
    },
    {
      "title": "Operation Eagle Sweep: 65 arrests in global BEC disruption",
      "date": "2022-03-30",
      "date_precision": "day",
      "victim_org": "Multiple businesses and individuals (500+ U.S. victims)",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Romance / Investment Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "Not a single-victim loss. The targeted actors were tied to more than 500 U.S. victims and over $51 million in losses; FBI noted nearly $2.4 billion in reported BEC/EAC losses in 2021.",
      "records_affected": null,
      "threat_actor": "BEC networks arrested in Nigeria, South Africa, Canada and Cambodia, plus U.S.-based money laundering cells",
      "summary": "Operation Eagle Sweep, announced by the FBI and Justice Department on March 30, 2022, was a three-month coordinated action against business email compromise networks. It produced 65 arrests, including 12 in Nigeria, eight in South Africa, two in Canada and one in Cambodia, with parallel operations by Australia, Japan and Nigeria. The targeted actors were linked to more than 500 U.S. victims and over $51 million in losses. Cases included a Houston laundering network that moved at least $4.5 million to Nigeria.",
      "how_it_worked": "The disrupted crews used compromised or spoofed business email accounts to insert themselves into payment flows, then requested wires or changed the banking details on invoices, closings and payroll so victims paid criminals instead of counterparties. The same organizations also targeted individuals, especially real estate purchasers and elderly victims, using romance and advance-fee variants that share the same laundering back end. Proceeds were collected in U.S.-based mule accounts, often opened with stolen or synthetic identities, and forwarded to Nigeria and other destinations. Enforcement paired arrests of the fraud operators with prosecutions of the laundering cells to reduce the networks' ability to cash out.",
      "lessons": "Because the same infrastructure serves corporate and consumer variants, banks and businesses benefit most from beneficiary-account verification and rapid kill-chain reporting rather than victim-type-specific controls.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Global Operation Disrupts Business Email Compromise Schemes",
          "url": "https://www.fbi.gov/news/stories/coordinated-operation-disrupts-global-bec-schemes-033022",
          "publisher": "Federal Bureau of Investigation"
        }
      ],
      "entry_type": "campaign",
      "slug": "2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-operation-eagle-sweep-65-arrests-in-global-bec-disruption"
    },
    {
      "title": "Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF",
      "date": "2022-03-23",
      "date_precision": "day",
      "victim_org": "Sky Mavis (Ronin Network / Axie Infinity)",
      "sector": "Cryptocurrency",
      "country": "Vietnam",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported; the recruiter persona and interview process were run by humans.",
      "outcomes": [
        "Cryptocurrency Theft"
      ],
      "loss_usd": 620000000,
      "loss_note": "173,600 ETH and 25.5 million USDC were drained; the value is commonly reported as roughly $540 million at the time of the hack and about $620-625 million at the time of disclosure, depending on the valuation date.",
      "records_affected": null,
      "threat_actor": "Lazarus Group (North Korea); sanctioned by the US Treasury in April 2022",
      "summary": "On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.",
      "how_it_worked": "Attackers posing as a non-existent company recruited a senior engineer over LinkedIn with an unusually generous compensation package, running a plausible multi-round interview process to build credibility. The final offer arrived as a PDF; downloading and opening it on a company machine executed spyware that gave the attackers a foothold in Sky Mavis systems. From there they obtained the private keys for four of the nine Ronin validator nodes, and used a still-active allowlist permission previously granted by Sky Mavis to the Axie DAO to obtain a fifth signature, reaching the five-of-nine threshold needed to authorise withdrawals from the bridge.",
      "lessons": "Validator key material should live in hardware security modules on isolated machines that never render untrusted documents, and delegated signing permissions must expire automatically rather than persist after a temporary need ends.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "How a fake job offer took down the world's most popular crypto game",
          "url": "https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game",
          "publisher": "The Block"
        },
        {
          "title": "Hackers Used Fake Job Offer to Hack and Steal $540 Million from Axie Infinity",
          "url": "https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html",
          "publisher": "The Hacker News"
        },
        {
          "title": "Spear Phishing Fake Job Offer Likely Behind Axie Infinity's Lazarus $600m Hack",
          "url": "https://www.infosecurity-magazine.com/news/fake-job-offer-behind-axie/",
          "publisher": "Infosecurity Magazine"
        },
        {
          "title": "Hackers stole $620 million from Axie Infinity via fake job interviews",
          "url": "https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake-job-interviews/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf",
      "year": 2022,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-ronin-bridge-crypto-theft-caused-by-a-fake-linkedin-job-offer-pdf"
    },
    {
      "slug": "2022-hubspot-employee-account-compromised-exposing-customer-data-at-crypto-fi",
      "title": "HubSpot employee account compromised, exposing customer data at crypto firms",
      "date": "2022-03-18",
      "date_precision": "day",
      "year": 2022,
      "victim_org": "HubSpot",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Supply Chain Compromise",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 18 March 2022 the CRM and marketing platform HubSpot disclosed that a threat actor had compromised a HubSpot employee account and used internal employee tooling to export contact data from a small number of customer portals. The targeting focused on cryptocurrency companies; BlockFi, Swan Bitcoin, NYDIG, Circle and Pantera Capital were among the customers that notified their users. HubSpot terminated the employee's access and disabled the affected accounts.",
      "how_it_worked": "The attacker gained control of a single HubSpot employee's account and then used the internal support tooling that comes with it. That tooling is designed to let staff assist customers by reaching into their portals, so once inside there was no further exploitation required, only the normal use of a legitimate function. The attacker moved directly to cryptocurrency customers, exported their marketing contact lists, and thereby obtained the names, email addresses and in some cases phone numbers of people known to hold crypto, which is precisely the targeting list for follow-on phishing. Downstream customers had no visibility into the vendor account that held their data.",
      "lessons": "Internal support tooling that can read customer data needs per-access justification, strict scoping and export alerting, so one compromised staff account cannot silently harvest many tenants.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Cryptocurrency Services Hit by Data Breach at CRM Company HubSpot",
          "url": "https://www.securityweek.com/cryptocurrency-services-hit-data-breach-crm-company-hubspot/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "HubSpot Data Breach Ripples Through Cryptocurrency Industry",
          "url": "https://threatpost.com/hubspot-data-breach-crytocurrency-industry/179086/",
          "publisher": "Threatpost"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-hubspot-employee-account-compromised-exposing-customer-data-at-crypto-fi"
    },
    {
      "slug": "2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so",
      "title": "LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code",
      "date": "2022-03",
      "date_precision": "month",
      "year": 2022,
      "victim_org": "T-Mobile US",
      "sector": "Telecom",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Insider Recruitment",
        "MFA Fatigue / Push Bombing"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Insider Access",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "LAPSUS$ (DEV-0537)",
      "summary": "Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.",
      "how_it_worked": "LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.",
      "lessons": "Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code",
          "url": "https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code",
          "url": "https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html",
          "publisher": "The Hacker News"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so"
    },
    {
      "title": "Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling",
      "date": "2022-01-21",
      "date_precision": "day",
      "victim_org": "Okta (via subprocessor Sitel/Sykes)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Supply Chain Compromise"
      ],
      "loss_usd": null,
      "loss_note": "Okta did not disclose a financial loss figure.",
      "records_affected": null,
      "threat_actor": "Lapsus$",
      "summary": "A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.",
      "how_it_worked": "Lapsus$ specialised in abusing the human layer of outsourced IT: support agents at business-process outsourcers hold standing, broadly scoped access to customer tenants but sit outside the customer's own security controls. Having taken over a Sitel engineer's workstation, the actor inherited that trusted seat and drove the Okta SuperUser console as the agent, in the agent's session, from the agent's device. No password or MFA prompt was presented to the attacker because the legitimate operator had already satisfied them. The blast radius was limited only by what the support role could do.",
      "lessons": "Outsourced support seats need the same scrutiny as privileged internal admins: just-in-time, scoped, session-recorded access with device trust, rather than standing tenant-wide impersonation rights.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Okta Concludes its Investigation Into the January 2022 Compromise",
          "url": "https://www.okta.com/blog/company-and-culture/okta-concludes-its-investigation-into-the-january-2022-compromise/",
          "publisher": "Okta"
        },
        {
          "title": "Okta says hundreds of companies impacted by security breach",
          "url": "https://techcrunch.com/2022/03/23/okta-breach-sykes-sitel/",
          "publisher": "TechCrunch"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling"
    },
    {
      "title": "Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge",
      "date": "2022",
      "date_precision": "year",
      "victim_org": "Unnamed aerospace company in Spain",
      "sector": "Defense",
      "country": "Spain",
      "primary_vector": "Fake Job Offer / Recruitment Lure",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported; the recruiter persona was operated manually over LinkedIn Messaging.",
      "outcomes": [
        "Espionage",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss reported; the objective was espionage.",
      "records_affected": null,
      "threat_actor": "Lazarus Group (North Korea), Operation Dream Job",
      "summary": "ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.",
      "how_it_worked": "A fake recruiter contacted employees through LinkedIn Messaging claiming to be running a Meta hiring process. The candidate was sent two supposed C++ programming tests, Quiz1.exe and Quiz2.exe, packaged inside ISO images hosted on cloud storage; one printed 'Hello, World!' and the other computed Fibonacci numbers, so the tasks appeared genuine. Running them side-loaded a malicious DLL that installed the NickelLoader downloader, which fetched miniBlindingCan and LightlessCan. LightlessCan supports up to 68 commands and reimplements many Windows utilities internally rather than spawning visible processes, reducing the telemetry available to endpoint monitoring during the espionage phase.",
      "lessons": "Recruitment materials should never be executed on corporate endpoints; disposable virtual machines for candidate exercises plus application allow-listing eliminate this entire vector.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
          "url": "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/",
          "publisher": "ESET WeLiveSecurity"
        },
        {
          "title": "North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain",
          "url": "https://www.eset.com/us/about/newsroom/press-releases/north-korea-linked-lazarus-impersonates-meta-on-linkedin-to-attack-an-aerospace-company-in-spain/",
          "publisher": "ESET"
        },
        {
          "title": "Lazarus hackers breach aerospace firm with new LightlessCan malware",
          "url": "https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding",
      "year": 2022,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding"
    },
    {
      "title": "FTC data: $147.8M in gift card fraud driven by government and business impersonators",
      "date": "2021-12-08",
      "date_precision": "day",
      "victim_org": "US consumers (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Tech Support Scam",
        "Romance / Investment Scam",
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement described.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 147800000,
      "loss_note": "$147.8 million reported lost across 39,263 gift card fraud reports in the first nine months of 2021. Government impersonation accounted for 7,844 reports and $39.6 million; business impersonation for 12,239 reports and $35.5 million.",
      "records_affected": 39263,
      "threat_actor": null,
      "summary": "An FTC data spotlight published on 8 December 2021 found that consumers filed 39,263 reports of gift card payments to scammers in the first nine months of 2021, with $147.8 million in reported losses. About one in four fraud victims who reported a payment method named gift cards. Target cards accounted for more than twice the losses of any other brand, with a $2,500 median loss, followed by Google Play, Apple, eBay and Walmart. Phone calls were the contact method in 37 percent of cases.",
      "how_it_worked": "A caller impersonating the Social Security Administration, another government agency, or a business such as Amazon or Apple tells the victim that money is owed or that an account has been compromised, and instructs them to resolve it immediately by buying gift cards at a nearby retailer. The victim is kept on the phone throughout the drive and the purchase, which prevents consultation with anyone and lets the scammer coach them past cashier questions with a cover story about buying gifts. At the register the victim reads the card numbers and PINs aloud over the phone, and the value is drained within minutes. Gift cards are attractive because they are irreversible and untraceable.",
      "lessons": "Retail checkout interdiction, where staff are trained and empowered to stop high-value gift card purchases by customers on the phone, is the single highest-yield control at the point of loss.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Scammers prefer gift cards, but not just any card will do",
          "url": "https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2021/12/scammers-prefer-gift-cards-not-just-any-card-will-do",
          "publisher": "Federal Trade Commission"
        }
      ],
      "entry_type": "benchmark",
      "slug": "2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp",
      "year": 2021,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2021-ftc-data-147-8m-in-gift-card-fraud-driven-by-government-and-business-imp"
    },
    {
      "slug": "2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom",
      "title": "Robinhood support employee socially engineered by phone; 7 million customers exposed",
      "date": "2021-11-03",
      "date_precision": "day",
      "year": 2021,
      "victim_org": "Robinhood Markets",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "An extortion demand was made; Robinhood said it reported the demand to law enforcement rather than paying.",
      "records_affected": 7000000,
      "threat_actor": null,
      "summary": "On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.",
      "how_it_worked": "The attack was a phone call, not an email. The caller reached a customer support employee and, over the course of the conversation, obtained access to support tooling, most plausibly by presenting as internal IT or as an authorised colleague needing assistance. Support staff are the ideal target for this because their entire job is to be helpful under time pressure to people they cannot see, and their tooling is broad by design: a single support console can query millions of customer records. Robinhood confirmed no Social Security numbers, bank account numbers or debit card numbers were exposed, but the breadth of the customer list made the extortion attempt credible.",
      "lessons": "Support consoles need per-record justification, rate limits and bulk-export alerting, and any inbound request for support access should be verified through an internal directory callback.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Robinhood data breach affects 7 million customers",
          "url": "https://fortune.com/2021/11/08/robinhood-data-breach-7-million-customers",
          "publisher": "Fortune"
        },
        {
          "title": "Robinhood Data Breach Leads Data Events in November",
          "url": "https://www.idtheftcenter.org/post/robinhood-data-breach-leads-data-events-november-number-data-compromises-reaches-all-time-high/",
          "publisher": "Identity Theft Resource Center"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom"
    },
    {
      "slug": "2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak",
      "title": "Peterborough, New Hampshire loses $2.3 million after a finance mailbox takeover",
      "date": "2021-07",
      "date_precision": "month",
      "year": 2021,
      "victim_org": "Town of Peterborough, New Hampshire",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 2300000,
      "loss_kind": "direct_loss",
      "loss_note": "About US$2.3 million diverted, roughly 15 percent of the town's annual budget; the US Secret Service recovered US$594,331 that had not yet been converted to cryptocurrency.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "The town of Peterborough, New Hampshire discovered in summer 2021 that about $2.3 million of payments had been diverted to fraudsters. The account of a town finance staff member had been compromised in April, and the attackers used it to redirect payments due to the ConVal School District and to a bridge contractor. The US Secret Service recovered $594,331; the rest had been moved on or converted to cryptocurrency.",
      "how_it_worked": "After taking over a town finance employee's email account, the attackers read the genuine correspondence with two payees, the regional school district and a bridge construction contractor, both of which had asked to be paid by electronic transfer. They then inserted themselves into those live threads with revised banking details, and deleted the payees' incoming emails so that the real counterparties' queries never reached town staff. The town had procedures requiring notarised change forms and confirmatory phone calls, but staff who were supposed to check each other's work did not follow them, which is what let the diverted payments clear.",
      "lessons": "Existing verification procedures only work if they are enforced; mailbox rule creation and mass deletion in a finance account should also raise an automatic alert.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Peterborough payment scam: Single compromised email account led to $2.3M theft",
          "url": "https://ledgertranscript.com/2021/10/05/pbscam-ml-100521-42830401/",
          "publisher": "Monadnock Ledger-Transcript"
        },
        {
          "title": "Cyber-thieves Scam New Hampshire Town Out of $2.3m",
          "url": "https://www.infosecurity-magazine.com/news/cyberthieves-scam-new-hampshire/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2021-peterborough-new-hampshire-loses-2-3-million-after-a-finance-mailbox-tak"
    },
    {
      "title": "Electronic Arts source code stolen via Slack cookie and IT help desk impersonation",
      "date": "2021-06",
      "date_precision": "month",
      "victim_org": "Electronic Arts",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Help Desk Impersonation",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "No confirmed payment or loss figure; the stolen data was advertised for sale on underground forums.",
      "records_affected": null,
      "threat_actor": "Unnamed criminal group that spoke to Motherboard/Vice",
      "summary": "In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.",
      "how_it_worked": "The chain began with a cookie sold on a criminal marketplace that carried a live Slack session for an EA employee. Inside Slack the attackers had the informal context, names and internal jargon needed to sound like staff. They then approached IT support in chat, claiming a lost phone, and persuaded the agent to issue a replacement MFA token without independent identity proofing. With working corporate credentials and MFA they reached EA's internal developer compilation service, created a virtual machine to gain broader network visibility, and downloaded game source code and internal tooling. EA said no player data was accessed.",
      "lessons": "Help desk MFA resets need identity proofing that does not depend on the requester's own chat account, such as manager verification or a video check against an HR photo record.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "How Hackers Used Slack to Break into EA Games",
          "url": "https://www.vice.com/en/article/how-ea-games-was-hacked-slack/",
          "publisher": "Vice / Motherboard"
        },
        {
          "title": "Hackers reportedly used EA Games' Slack to breach network, access source code",
          "url": "https://cyberscoop.com/ea-games-fifa-hack-hackers-slack/",
          "publisher": "CyberScoop"
        },
        {
          "title": "Details Emerge on How Gaming Giant EA Was Hacked",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/report-details-how-gaming-giant-ea-was-hacked",
          "publisher": "Dark Reading"
        }
      ],
      "entry_type": "incident",
      "slug": "2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp",
      "year": 2021,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp"
    },
    {
      "title": "Sequoia Capital investor data exposed after employee falls for phishing email",
      "date": "2021-02",
      "date_precision": "month",
      "victim_org": "Sequoia Capital",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Business Email Compromise"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss disclosed; the associated fraudulent transfer attempt was reported as unsuccessful.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.",
      "how_it_worked": "An employee at the firm received and acted on a phishing email, handing over credentials that gave the attacker access to their corporate mailbox. The intruder used that mailbox to read stored correspondence containing investor personal and financial details, and attempted to leverage the account for fraudulent payment instructions in the style of a business email compromise, which was not successful. Sequoia notified affected limited partners, engaged outside investigators and law enforcement, and offered credit monitoring. No malware deployment or wider network intrusion was reported.",
      "lessons": "Phishing-resistant MFA on cloud mailboxes plus alerting on anomalous mailbox rules and sign-in locations catches this pattern in hours rather than weeks.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Scoop: Sequoia Capital says it was hacked",
          "url": "https://www.axios.com/2021/02/20/sequoia-capital-says-it-was-hacked",
          "publisher": "Axios"
        },
        {
          "title": "VC Giant Sequoia Capital Informs Investors of Data Breach",
          "url": "https://www.securityweek.com/vc-giant-sequoia-capital-informs-investors-data-breach/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "VC giant Sequoia Capital discloses data breach after failed BEC attack",
          "url": "https://www.bleepingcomputer.com/news/security/vc-giant-sequoia-capital-discloses-data-breach-after-failed-bec-attack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing",
      "year": 2021,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing"
    },
    {
      "title": "One Treasure Island nonprofit loses $650,000 to hijacked email thread",
      "date": "2021",
      "date_precision": "year",
      "victim_org": "One Treasure Island",
      "sector": "Nonprofit",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 650000,
      "loss_note": "$650,000 diverted. Funds initially landed at a bank in Odessa, Texas; the nonprofit reported difficulty obtaining law enforcement and bank assistance and no recovery was confirmed in the cited reporting.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.",
      "how_it_worked": "The attackers took over the outsourced bookkeeper's mailbox, which sat at the center of the nonprofit's payment approvals, and then replied inside a live thread about a pending grant disbursement rather than starting fresh correspondence. Because the message carried the real address, the real subject line and the real transaction context, the substituted wiring instructions read as an ordinary administrative update. Staff sent the $650,000 grant payment to the criminals' account at a small out-of-state bank, which was then drained onward. The organization discovered the diversion only when the intended recipient reported non-receipt, and small-nonprofit resourcing left it largely on its own to chase the money.",
      "lessons": "Thread hijacking beats sender-address checks, so any change of wire instructions inside an existing thread must trigger a verbal callback to a previously known number before funds move.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Scammed San Francisco Nonprofit Falls Victim to Costliest Type of Cybercrime",
          "url": "https://www.cbsnews.com/sanfrancisco/news/scammed-san-francisco-nonprofit-falls-victim-to-costliest-type-of-cybercrime/",
          "publisher": "CBS News Bay Area / Associated Press"
        },
        {
          "title": "A nonprofit that helps the poor lost $650,000 to scammers",
          "url": "https://www.sfchronicle.com/crime/article/S-F-nonprofit-lost-650-000-to-hackers-and-a-16191669.php",
          "publisher": "San Francisco Chronicle"
        }
      ],
      "entry_type": "incident",
      "slug": "2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread",
      "year": 2021,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2021-one-treasure-island-nonprofit-loses-650-000-to-hijacked-email-thread"
    },
    {
      "slug": "2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a",
      "title": "Baltimore County schools ransomware started with a contractor opening a phishing email",
      "date": "2020-11-24",
      "date_precision": "day",
      "year": 2020,
      "victim_org": "Baltimore County Public Schools",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption",
        "Data Breach"
      ],
      "loss_usd": 9700000,
      "loss_kind": "business_impact",
      "loss_note": "About US$9.7 million in recovery and remediation costs according to the Maryland Office of the Inspector General for Education; no ransom was paid.",
      "records_affected": null,
      "threat_actor": "Ryuk (reported)",
      "summary": "Baltimore County Public Schools, one of the largest US school districts, was hit by ransomware on 24 November 2020, shutting down remote learning for about 115,000 students during the pandemic. A later investigative report by the Maryland Office of the Inspector General for Education found that a contractor had mistakenly opened a malicious email that initiated the attack, and that the district had not acted on prior security recommendations. Recovery costs reached roughly $9.7 million.",
      "how_it_worked": "A contractor working with the district opened a malicious email attachment, which established the foothold that led to district-wide encryption on the eve of the Thanksgiving holiday, a timing choice that maximised the gap before anyone noticed. The Inspector General's report placed the weight of the finding not on the click but on what surrounded it: the district had received specific security recommendations from a prior state audit and had not implemented them, and had extended network access to a contractor without correspondingly hardened controls. Remote learning for 115,000 students halted, and rebuilding cost nearly ten million dollars.",
      "lessons": "Contractor accounts need the same email defences, MFA and least privilege as employees, and audit findings left unimplemented become the incident's root cause.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Baltimore County schools ignored warnings before 2020 cyberattack, audit finds",
          "url": "https://statescoop.com/baltimore-county-schools-ransomware-attack-2020-inspector-general/",
          "publisher": "StateScoop"
        },
        {
          "title": "Report: Contractor 'mistakenly' opened email starting Baltimore County school cyberattack",
          "url": "https://foxbaltimore.com/news/local/investigative-report-released-2-years-after-baltimore-county-schools-cyberattack",
          "publisher": "Fox Baltimore (WBFF)"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-baltimore-county-schools-ransomware-started-with-a-contractor-opening-a"
    },
    {
      "title": "Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash",
      "date": "2020-11-13",
      "date_precision": "day",
      "victim_org": "GoDaddy (registrar); Liquid.com and NiceHash",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No voice cloning was reported; the callers used conventional pretexting against registrar staff.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No customer funds were reported lost. Liquid said customer funds remained secure; NiceHash said no emails, passwords or personal data were compromised.",
      "records_affected": null,
      "threat_actor": "Unattributed",
      "summary": "Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.",
      "how_it_worked": "The attackers called GoDaddy employees and pretended to be authorised parties with a routine domain administration need, a pretext the registrar's own staff were positioned to fulfil. Once a rep made the change, the attackers held registrar-level control of the target's domain and could repoint DNS at will. For Liquid, control of the domain's MX and name server records let them take over internal email accounts, which in turn exposed customer names, addresses, encrypted passwords and identity verification documents. NiceHash saw the same DNS manipulation but reported no data compromise. The exchanges' own security was never touched; the failure was one level up, at the registrar.",
      "lessons": "Registry lock on critical domains, which requires manual out-of-band verification before any DNS or nameserver change, defeats registrar-side social engineering outright.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "GoDaddy Employees Tricked into Compromising Cryptocurrency Sites",
          "url": "https://threatpost.com/godaddy-employees-tricked-compromise-cryptocurrency/161520/",
          "publisher": "Threatpost"
        },
        {
          "title": "GoDaddy Employees Tricked Into Transferring Control of Crypto Firm Domains: Report",
          "url": "https://www.coindesk.com/markets/2020/11/22/godaddy-employees-tricked-into-transferring-control-of-crypto-firm-domains-report",
          "publisher": "CoinDesk"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic",
      "year": 2020,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic"
    },
    {
      "title": "Russian offered a Tesla employee $1M to plant ransomware at the Nevada Gigafactory",
      "date": "2020-08",
      "date_precision": "month",
      "victim_org": "Tesla, Inc.",
      "sector": "Manufacturing",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Attempt Blocked"
      ],
      "loss_usd": null,
      "loss_note": "No loss occurred. The targeted employee reported the approach to Tesla and the FBI, and the plot was never executed.",
      "records_affected": null,
      "threat_actor": "Egor Igorevich Kriuchkov (later pleaded guilty)",
      "summary": "Egor Kriuchkov, a 27-year-old Russian national who entered the US in July 2020, approached a Russian-speaking Tesla employee at the Nevada Gigafactory and offered payment to introduce malware into Tesla's network. The offer began at $500,000 and rose to $1 million in cash or bitcoin. The employee reported the approach, cooperated with the FBI, and Kriuchkov was arrested in Los Angeles after attempting to flee the country. Elon Musk publicly confirmed the incident.",
      "how_it_worked": "Kriuchkov built rapport with the employee in person over social meetings before naming the ask. The proposal was for the employee to run attacker-supplied ransomware inside the plant network, either by opening a malicious email attachment or plugging in an infected USB stick, while the conspirators ran a simultaneous distributed denial-of-service attack to occupy Tesla's security team. The group intended to exfiltrate Tesla files and extort the company for their non-release; Kriuchkov said the malware itself had cost $250,000 to develop. The scheme died at the first step because the employee, rather than accepting, told Tesla and then wore a wire for the FBI.",
      "lessons": "A no-blame, clearly advertised channel for reporting bribery approaches is the control that actually catches insider recruitment, since no technical control sees the offer being made.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "How a $1 million plot to hack Tesla failed",
          "url": "https://www.technologyreview.com/2020/08/28/1007752/how-a-1-million-plot-to-hack-tesla-failed/",
          "publisher": "MIT Technology Review"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi",
      "year": 2020,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-russian-offered-a-tesla-employee-1m-to-plant-ransomware-at-the-nevada-gi"
    },
    {
      "title": "Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed",
      "date": "2020-07-23",
      "date_precision": "day",
      "victim_org": "Garmin Ltd.",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Watering Hole / Malvertising",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption",
        "Extortion"
      ],
      "loss_usd": null,
      "loss_note": "Garmin never confirmed a ransom payment or a loss figure; press reporting of a multimillion-dollar payment is unverified.",
      "records_affected": null,
      "threat_actor": "Evil Corp (WastedLocker operators)",
      "summary": "Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.",
      "how_it_worked": "In the WastedLocker campaigns of 2020 as documented by researchers, users browsing legitimate but compromised news and business websites were served a fake browser or Flash update overlay. Accepting the prompt downloaded a JavaScript-based loader, after which operators escalated privileges, moved laterally with Cobalt Strike and PowerShell, disabled security tooling and deployed WastedLocker across servers. For Garmin, only the ransomware family and the operational impact were publicly established; the entry point was never disclosed by the company or by law enforcement, so the human-deception element in this specific case is inferred from the campaign pattern rather than confirmed.",
      "lessons": "Blocking user-initiated software updates from browser prompts and enforcing application control on workstations removes the fake-update lure that this ransomware family relied on.",
      "confidence": "Alleged",
      "sources": [
        {
          "title": "Garmin outage caused by confirmed WastedLocker ransomware attack",
          "url": "https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "WastedLocker explained: How this targeted ransomware extorts millions from victims",
          "url": "https://www.csoonline.com/article/569859/wastedlocker-explained-how-this-targeted-ransomware-extorts-millions-from-victims.html",
          "publisher": "CSO Online"
        },
        {
          "title": "LockerGoga and WastedLocker ransomware insight",
          "url": "https://www.recordedfuture.com/blog/lockergoga-ransomware-insight",
          "publisher": "Recorded Future"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c",
      "year": 2020,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c"
    },
    {
      "title": "Twitter's July 2020 account takeover started with phone spear phishing of employees",
      "date": "2020-07-15",
      "date_precision": "day",
      "victim_org": "Twitter, Inc.",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "The callers used ordinary voice social engineering and pre-collected personal details; no synthetic voice was reported.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Data Breach",
        "Credential Theft",
        "Identity Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 118000,
      "loss_note": "The New York Department of Financial Services investigation report puts the bitcoin obtained through the scam tweets at approximately $118,000.",
      "records_affected": 130,
      "threat_actor": "Graham Ivan Clark and co-conspirators (later criminally charged)",
      "summary": "On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.",
      "how_it_worked": "Callers rang Twitter staff claiming to be from the internal help desk and offering to fix VPN connectivity problems, a plausible complaint during the shift to remote working. They used personal information gathered in advance about each employee to sound credible, then directed the target to a site that mirrored Twitter's real VPN portal. As the employee typed their credentials and MFA code, the attackers entered the same values into the genuine portal, completing the login inside the code's validity window. From there they reached internal account-management tooling and used it to reset the email addresses and disable MFA on high-profile accounts.",
      "lessons": "Phishing-resistant FIDO2/WebAuthn authenticators would have broken the real-time credential relay, and out-of-band callback verification for any unsolicited IT help desk contact would have stopped the pretext at the first call.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Twitter Investigation Report",
          "url": "https://www.dfs.ny.gov/system/files/documents/2026/07/Twitter-Investigation-Report.pdf",
          "publisher": "New York State Department of Financial Services"
        },
        {
          "title": "Department of Financial Services Calls for Regulation of Social Media Giants After Twitter Hack Investigation",
          "url": "https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202010141",
          "publisher": "New York State Department of Financial Services"
        },
        {
          "title": "Twitter breach: Staff tricked by 'phone spear phishing'",
          "url": "https://www.welivesecurity.com/2020/07/31/twitter-breach-staff-tricked-phone-spear-phishing/",
          "publisher": "ESET WeLiveSecurity"
        },
        {
          "title": "New York regulator faults Twitter for lax security measures prior to big account breach",
          "url": "https://cyberscoop.com/twitter-hack-social-engineering-new-york-financial-services/",
          "publisher": "CyberScoop"
        },
        {
          "title": "Twitter Investigation Report",
          "url": "https://www.dfs.ny.gov/Twitter_Report",
          "publisher": "New York State Department of Financial Services"
        },
        {
          "title": "Twitter says hackers used a telephone to fool staff and gain access",
          "url": "https://www.nbcnews.com/business/business-news/twitter-says-hackers-used-telephone-fool-staff-gain-access-n1235466",
          "publisher": "NBC News"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o",
      "year": 2020,
      "loss_kind": "criminal_proceeds",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o"
    },
    {
      "title": "Scattered Canary floods Washington's pandemic unemployment system with fake claims",
      "date": "2020-05",
      "date_precision": "month",
      "victim_org": "Washington State Employment Security Department",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Business Email Compromise"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "Reported as hundreds of millions of dollars; the state had not determined a final figure at the time of reporting, and a substantial portion was later recovered.",
      "records_affected": null,
      "threat_actor": "Scattered Canary (Nigeria-based fraud ring)",
      "summary": "In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.",
      "how_it_worked": "The ring assembled identity packages from earlier consumer data breaches, giving them the Social Security numbers, dates of birth and addresses of real Washington workers. They registered claims using disposable email services and Gmail address variations so that a single controlled inbox could receive correspondence for many claimants, and they targeted the enhanced $600 weekly federal supplement, which raised the payout per fraudulent claim. Benefit payments were then directed to out-of-state bank accounts held by recruited mules. The pretext succeeded because the agency, overwhelmed by unprecedented claim volume, had relaxed verification to speed payments.",
      "lessons": "Identity proofing and cross-matching against employer wage records must not be suspended under surge conditions; duplicate-contact and out-of-state-payee detection would have surfaced the ring early.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "How missed 'red flags' helped Nigerian fraud ring 'Scattered Canary' bilk Washington's unemployment system amid coronavirus chaos",
          "url": "https://www.spokesman.com/stories/2020/may/25/how-missed-red-flags-helped-nigerian-fraud-ring-sc/",
          "publisher": "The Spokesman-Review / The Seattle Times"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-scattered-canary-floods-washington-s-pandemic-unemployment-system-with-f",
      "year": 2020,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-scattered-canary-floods-washington-s-pandemic-unemployment-system-with-f"
    },
    {
      "title": "Hacker bribed a Roblox support contractor to access user data and reset accounts",
      "date": "2020-05",
      "date_precision": "month",
      "victim_org": "Roblox Corporation",
      "sector": "Gaming & Casino",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Insider Access",
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No dollar loss was published. The hacker changed passwords on two accounts and took in-game items from those users.",
      "records_affected": null,
      "threat_actor": "Unnamed individual who had previously sought a Roblox bug bounty",
      "summary": "A hacker bribed a Roblox customer support representative, listed publicly as an in-game support contractor, to obtain access to the company's customer support panel. The panel exposed personal data on Roblox's user base and allowed password resets, removal of two-factor authentication, account bans and data changes. Roblox said it acted immediately, notified the small number of affected customers, and reported the hacker to HackerOne.",
      "how_it_worked": "The attacker skipped Roblox's perimeter entirely and bought a person instead. He identified a support contractor via LinkedIn and paid them for access to the internal customer support console, which was designed to let agents administer any account. With that console the attacker could read email addresses, force password resets, strip 2FA from targeted accounts, ban users and alter records, including for high-profile creators. He used it to change passwords on two accounts and take their in-game items. Roblox had earlier denied him a bug bounty payout over suspected malicious activity, which appears to have preceded the insider approach.",
      "lessons": "Support consoles that can reset any account need per-record justification, least-privilege scoping and anomaly alerting on bulk or high-profile lookups, so a single bribed agent cannot become a master key.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Hacker Bribed 'Roblox' Insider to Access User Data",
          "url": "https://www.vice.com/en/article/hacker-bribed-roblox-insider-accessed-user-data-reset-passwords/",
          "publisher": "Vice / Motherboard"
        },
        {
          "title": "Hacker Bribed Roblox Worker For Access To Users' Personal Data",
          "url": "https://www.gamespot.com/articles/hacker-bribed-roblox-worker-for-access-to-users-pe/1100-6477149/",
          "publisher": "GameSpot"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-hacker-bribed-a-roblox-support-contractor-to-access-user-data-and-reset",
      "year": 2020,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-hacker-bribed-a-roblox-support-contractor-to-access-user-data-and-reset"
    },
    {
      "title": "WHO impersonation surge during COVID-19 targets donors and staff",
      "date": "2020-04-23",
      "date_precision": "day",
      "victim_org": "World Health Organization and the general public (multi-victim campaign)",
      "sector": "Healthcare",
      "country": "Global",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported in 2020.",
      "outcomes": [
        "Credential Theft",
        "Wire Fraud / Financial Loss",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_note": "WHO did not publish a total for donations diverted by impersonators.",
      "records_affected": 450,
      "threat_actor": null,
      "summary": "On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.",
      "how_it_worked": "Attackers exploited the single most trusted authority of the moment. Emails carrying WHO branding promised guidance on the outbreak and asked recipients to click through to a credential capture page or open an attachment, and separate campaigns solicited donations to a fake version of the COVID-19 Solidarity Response Fund or issued invoices purporting to come from it. The lever was fear plus civic goodwill under acute uncertainty, when recipients were actively seeking official pandemic information and wanted to help. The leaked credentials came from an older extranet system used by current staff, retired employees and partners.",
      "lessons": "Legacy extranets holding partner credentials must be retired or moved behind modern multi-factor authentication, and public-facing agencies should publish a single authoritative donation channel to make impersonation obvious.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "WHO reports fivefold increase in cyber attacks, urges vigilance",
          "url": "https://www.who.int/news/item/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance",
          "publisher": "World Health Organization"
        },
        {
          "title": "Cyber security: beware of criminals pretending to be WHO",
          "url": "https://www.who.int/about/cyber-security",
          "publisher": "World Health Organization"
        }
      ],
      "entry_type": "campaign",
      "slug": "2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff",
      "year": 2020,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff"
    },
    {
      "slug": "2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c",
      "title": "Magellan Health ransomware began with a phishing email impersonating a client",
      "date": "2020-04-06",
      "date_precision": "day",
      "year": 2020,
      "victim_org": "Magellan Health",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Ransomware Deployment",
        "Data Breach",
        "Credential Theft",
        "Extortion"
      ],
      "loss_usd": 1430000,
      "loss_kind": "business_impact",
      "loss_note": "US$1.43 million class-action settlement resolving claims over the breach and the delay in notification.",
      "records_affected": 364892,
      "threat_actor": null,
      "summary": "Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.",
      "how_it_worked": "The attacker impersonated one of Magellan's own clients, which is a stronger pretext than a generic executive spoof because a managed care company's staff correspond with client organisations constantly and are expected to be responsive to them. The employee provided access credentials in response to that message. Over the following five days the attackers moved through the network, reached a corporate server holding employee records including tax documentation with Social Security numbers, exfiltrated a subset of it, and installed software to harvest further log-ins before triggering encryption. The five-day dwell time is where the data theft happened.",
      "lessons": "Client-impersonation phishing defeats seniority-based suspicion, so the control is MFA plus detection of internal reconnaissance in the days between the click and the encryption.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Data Stolen in Magellan Health Ransomware Attack",
          "url": "https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/",
          "publisher": "HIPAA Journal"
        },
        {
          "title": "Healthcare giant Magellan Health hit by ransomware attack",
          "url": "https://www.bleepingcomputer.com/news/security/healthcare-giant-magellan-health-hit-by-ransomware-attack/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c"
    },
    {
      "title": "Puerto Rico government agency sends $2.6 million to fraudulent account",
      "date": "2020-01-17",
      "date_precision": "day",
      "victim_org": "Puerto Rico Industrial Development Company (PRIDCO)",
      "sector": "Government",
      "country": "Puerto Rico",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 2600000,
      "loss_note": "$2.6 million transferred on January 17, 2020. Recovery outcome not confirmed in the cited reporting.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Puerto Rico's Industrial Development Company transferred $2.6 million on January 17, 2020 to an account controlled by fraudsters after officials received an email claiming that the bank account used for remittance payments had changed. The agency's finance director, Rubén Rivera, filed a police complaint in February 2020 after the diversion was discovered. The incident occurred while the territory was in a prolonged fiscal crisis.",
      "how_it_worked": "The scheme exploited an inter-agency remittance payment process in which large periodic transfers are routine and the receiving party is trusted. The fraudulent email announced a change of banking details for those remittances, a message finance staff had reason to expect from time to time, and gave no cause for alarm because it referenced a genuine payment relationship. Officials updated the destination details and executed the scheduled payment of $2.6 million into the criminals' account. The loss surfaced only when the legitimate recipient's non-receipt was noticed, by which time the funds had left the account, prompting a complaint to police and a wider review of government payment controls.",
      "lessons": "Government payment offices need a standing rule that account-change notices are never actioned from email alone, plus periodic reconciliation with recipients to catch a diversion within days rather than weeks.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Official says Puerto Rico government lost $2.6M in phishing scam",
          "url": "https://www.pbs.org/newshour/nation/official-says-puerto-rico-government-lost-2-6m-in-phishing-scam",
          "publisher": "PBS NewsHour / Associated Press"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account",
      "year": 2020,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-puerto-rico-government-agency-sends-2-6-million-to-fraudulent-account"
    },
    {
      "title": "Cloned company director's voice used in US$35M bank transfer fraud",
      "date": "2020",
      "date_precision": "year",
      "victim_org": "Unnamed company and its bank; investigated by UAE authorities",
      "sector": "Financial Services",
      "country": "United Arab Emirates",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Business Email Compromise",
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "UAE investigators stated in court filings that the fraudsters used 'deep voice' technology to clone a company director's speech for the phone call. The specific tooling was not established publicly.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 35000000,
      "loss_note": "Up to US$35 million per UAE court documents; US$400,000 traced to two US accounts at Centennial Bank",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In early 2020 a branch manager of a Japanese company in Hong Kong received a call from a voice he recognised as a director of the parent business, who said the company was about to make an acquisition and needed transfers authorised. Emails purportedly from the director and from a lawyer named Martin Zelner appeared to corroborate the story. UAE prosecutors, who investigated the case, said in a US legal assistance request that up to US$35 million was moved and that at least 17 people were involved. Forbes obtained the court filing in 2021.",
      "how_it_worked": "The pretext was a confidential corporate acquisition that required the branch to release large sums quickly. The channel was a phone call from a person whose voice the manager had heard before, reinforced by a parallel email thread from the same director and from an outside lawyer retained to coordinate the deal, which is a familiar and legitimising pattern in M&A work. Secrecy was built into the story, so the manager had a reason not to ask colleagues. The layered corroboration between a recognised voice and matching documentation removed his doubt, and the transfers were executed before anyone verified through an independent channel.",
      "lessons": "Any acquisition-related payment instruction should require verification through a pre-established channel with a named counterparty, not the contact details supplied inside the request itself.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Fraudsters Cloned Company Director's Voice In $35 Million Bank Heist, Police Find",
          "url": "https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/",
          "publisher": "Forbes"
        },
        {
          "title": "Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme",
          "url": "https://incidentdatabase.ai/cite/147/",
          "publisher": "AI Incident Database"
        }
      ],
      "entry_type": "incident",
      "slug": "2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud",
      "year": 2020,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2020-cloned-company-director-s-voice-used-in-us-35m-bank-transfer-fraud"
    },
    {
      "title": "Operation reWired: 281 arrested worldwide in BEC crackdown",
      "date": "2019-09-10",
      "date_precision": "day",
      "victim_org": "Multiple businesses and individuals (global)",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation",
        "Credential Phishing Portal",
        "Romance / Investment Scam"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Attempt Blocked",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "Not a single-victim loss. The four-month operation produced 281 arrests, seized about $3.7 million and disrupted roughly $118 million in fraudulent wire transfers. IC3 reported nearly $1.3 billion in BEC/EAC losses for 2018 alone.",
      "records_affected": null,
      "threat_actor": "Multiple BEC networks, predominantly Nigeria-based, plus actors in Turkey and Ghana",
      "summary": "Announced on September 10, 2019, Operation reWired was a four-month international action against business email compromise. It resulted in 281 arrests, 74 in the United States and 207 abroad, including 167 in Nigeria, 18 in Turkey and 15 in Ghana. Authorities seized approximately $3.7 million and disrupted around $118 million in fraudulent transfers. One case involved a community college and an energy company that lost about $5 million, of which banks froze roughly $3.6 million.",
      "how_it_worked": "Operators compromised business and personal email accounts through phishing and credential theft, then monitored correspondence to time an intervention around a real pending payment. When a legitimate invoice, payroll run or closing disbursement was in flight, they injected altered banking instructions that appeared to come from the known counterparty. Victims spanned companies, schools, energy firms, seniors and real estate purchasers. Proceeds were funneled through networks of money mules and fictitious identities before being sent overseas. Thirty-nine FBI field offices and partners in nine countries coordinated arrests, seizures and mule warning letters simultaneously to disrupt both the fraud and its laundering infrastructure.",
      "lessons": "Because criminal proceeds move through domestic mule accounts within hours, rapid reporting to the FBI's IC3 Recovery Asset Team is the single most effective control after a diverted payment is discovered.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "281 Arrested Worldwide in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes",
          "url": "https://www.justice.gov/archives/opa/pr/281-arrested-worldwide-coordinated-international-enforcement-operation-targeting-hundreds",
          "publisher": "U.S. Department of Justice"
        },
        {
          "title": "Operation reWired",
          "url": "https://www.fbi.gov/news/stories/operation-rewired-bec-takedown-091019",
          "publisher": "Federal Bureau of Investigation"
        },
        {
          "title": "74 Arrested in Coordinated International Enforcement Operation Targeting Hundreds of Individuals in Business Email Compromise Schemes",
          "url": "https://www.justice.gov/archives/opa/pr/74-arrested-coordinated-international-enforcement-operation-targeting-hundreds-individuals",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "campaign",
      "slug": "2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown",
      "year": 2019,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-operation-rewired-281-arrested-worldwide-in-bec-crackdown"
    },
    {
      "slug": "2019-nikkei-america-employee-wires-29-million-on-fraudulent-management-instru",
      "title": "Nikkei America employee wires $29 million on fraudulent management instructions",
      "date": "2019-09",
      "date_precision": "month",
      "year": 2019,
      "victim_org": "Nikkei Inc. (Nikkei America)",
      "sector": "Media & Entertainment",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 29000000,
      "loss_kind": "direct_loss",
      "loss_note": "About US$29 million (approximately 3.2 billion yen) transferred to a bank account controlled by the fraudsters; Nikkei said it was pursuing recovery.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Japanese media group Nikkei disclosed in October 2019 that an employee at its US subsidiary, Nikkei America, had transferred about $29 million to a bank account controlled by fraudsters the previous month. The employee acted on instructions from someone impersonating a Nikkei management executive. Nikkei reported the matter to authorities in the United States and Hong Kong and said it was working to recover the funds.",
      "how_it_worked": "Someone posing as a Nikkei management executive instructed an employee in the American subsidiary's finance function to make a large transfer, and the employee did so believing the request was a legitimate internal payment. The structure is the recurring one for cross-border subsidiary fraud: the target sits in an overseas office where head-office instructions arrive by email as a matter of course, where time-zone gaps make immediate verbal confirmation awkward, and where the seniority gradient discourages challenge. No independent check on the beneficiary account was performed before the money left, and the fraud surfaced afterwards during internal review.",
      "lessons": "A hard rule that no single employee can release a transfer of this size without a second approver and a verified callback would have stopped it.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Media Giant Nikkei Loses $29 Million to BEC Scammers",
          "url": "https://www.bleepingcomputer.com/news/security/media-giant-nikkei-loses-29-million-to-bec-scammers/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Japanese media giant Nikkei says $29 million lost in BEC scam",
          "url": "https://cyberscoop.com/nikkei-email-scam-bec-29-million/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-nikkei-america-employee-wires-29-million-on-fraudulent-management-instru"
    },
    {
      "title": "Toyota Boshoku European unit loses $37 million to payment-instruction BEC",
      "date": "2019-08-14",
      "date_precision": "day",
      "victim_org": "Toyota Boshoku Corporation (European subsidiary)",
      "sector": "Manufacturing",
      "country": "Japan",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 37000000,
      "loss_note": "Approximately ¥4 billion, reported as about $37 million; the company said it was pursuing recovery of the funds.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Toyota Boshoku, a Toyota Group parts supplier, announced in September 2019 that a European subsidiary had been defrauded of roughly ¥4 billion (about $37 million) on 14 August 2019 after receiving fraudulent electronic payment instructions. The company said a third party had directed funds to an account it controlled and that it was working with lawyers and authorities to recover the money.",
      "how_it_worked": "Attackers sent messages that impersonated a trading partner or an internal authority and instructed the subsidiary's finance function to redirect a large trade payment to a different bank account. Because the amount and the counterparty were consistent with the subsidiary's normal automotive supply-chain payments, the request did not stand out, and the transfer was executed on the strength of the emailed instruction alone. The loss was discovered after the fact, and Toyota Boshoku disclosed it to the market alongside a downward revision of expected results while pursuing legal recovery.",
      "lessons": "Any instruction that changes payee bank details, even mid-transaction with a known partner, should require independent verification through an established contact and a second approver outside the requesting chain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Over $37 Million Lost by Toyota Boshoku Subsidiary in BEC Scam",
          "url": "https://www.bleepingcomputer.com/news/security/over-37-million-lost-by-toyota-boshoku-subsidiary-in-bec-scam/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "Toyota Parts Supplier Loses $37 Million in Email Scam",
          "url": "https://www.tripwire.com/state-of-security/toyota-parts-supplier-loses-37-million-email-scam",
          "publisher": "Tripwire State of Security"
        },
        {
          "title": "Toyota Boshoku Corporation lost over $37 Million following BEC attack",
          "url": "https://securityaffairs.com/90955/cyber-crime/toyota-boshoku-corporation-bec.html",
          "publisher": "Security Affairs"
        }
      ],
      "entry_type": "incident",
      "slug": "2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec",
      "year": 2019,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-toyota-boshoku-european-unit-loses-37-million-to-payment-instruction-bec"
    },
    {
      "slug": "2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake",
      "title": "Lancaster University phishing breach exposes 12,500 applicants, then fake invoices follow",
      "date": "2019-07",
      "date_precision": "month",
      "year": 2019,
      "victim_org": "Lancaster University",
      "sector": "Education",
      "country": "United Kingdom",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 12500,
      "threat_actor": null,
      "summary": "Lancaster University disclosed on 22 July 2019 that a sophisticated and malicious phishing attack had exposed the records of around 12,500 undergraduate applicants for 2019 and 2020, along with some current student data. Exposed fields included names, addresses, telephone numbers and email addresses. Fraudulent invoices were subsequently sent to some applicants using the stolen details. Police arrested a suspect within days.",
      "how_it_worked": "Phishing against university staff yielded access to the applicant records system. What made this breach unusual is the immediate monetisation: rather than selling the data, the attacker used it to send fraudulent invoices directly to undergraduate applicants. Those recipients were the ideal targets, because a prospective student who has just applied is expecting communication from the university about fees and accommodation, and has no baseline for what a genuine invoice looks like. The stolen contact details supplied exactly the personalisation, real name, real address, real course application, that makes a fake bill credible. The university reported to the ICO and warned applicants directly.",
      "lessons": "Multi-factor authentication on staff accounts, plus a published policy that the university never invoices applicants by email, closes both the intrusion and the downstream fraud.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Lancaster University Confirms Data Breach, Applicants Targeted",
          "url": "https://www.infosecurity-magazine.com/news/lancaster-university-breach/",
          "publisher": "Infosecurity Magazine"
        },
        {
          "title": "Lancaster University data breach",
          "url": "https://www.theregister.com/2019/07/23/lancaster_university_data_breach/",
          "publisher": "The Register"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-lancaster-university-phishing-breach-exposes-12-500-applicants-then-fake"
    },
    {
      "slug": "2019-riviera-beach-pays-600-000-ransom-after-an-employee-clicked-a-malicious",
      "title": "Riviera Beach pays $600,000 ransom after an employee clicked a malicious email link",
      "date": "2019-05-29",
      "date_precision": "day",
      "year": 2019,
      "victim_org": "City of Riviera Beach, Florida",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption",
        "Extortion"
      ],
      "loss_usd": 600000,
      "loss_kind": "ransom_paid",
      "loss_note": "65 bitcoin, about US$600,000 at the time, authorised by the city council and paid largely through the city's insurance. The city separately approved about US$1 million for replacement hardware.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "The city of Riviera Beach, Florida was hit by ransomware in late May 2019 after a city employee clicked a malicious link in an email. The attack disabled city email, payroll systems and parts of the 911 dispatch infrastructure, forcing staff onto paper processes. In June 2019 the city council voted to pay 65 bitcoin, roughly $600,000, to obtain a decryption key, in addition to about $1 million already approved for new hardware.",
      "how_it_worked": "A single employee in the city's administration opened an email and clicked the link inside it, which delivered the payload that encrypted municipal systems. Nothing about the delivery was exotic; the significance is what a small municipality's environment allowed to follow. Flat networks, shared administrative credentials and backups reachable from the same domain meant one workstation compromise propagated to payroll, email, utility billing and dispatch support systems. With no clean restore path and public safety services degraded, the council concluded that paying the ransom was faster than rebuilding, making Riviera Beach the template case for municipal ransom payment.",
      "lessons": "Offline, immutable backups tested for restoration change the entire calculus, because the decision to pay was driven by recovery capability rather than by the initial click.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Florida city to pay $600K ransom to hacker who seized computer systems weeks ago",
          "url": "https://www.cnn.com/2019/06/20/us/riviera-beach-to-pay-hacker/index.html",
          "publisher": "CNN"
        },
        {
          "title": "Florida city pays hackers $600,000 after ransomware attack",
          "url": "https://statescoop.com/florida-city-pays-hackers-600000-after-ransomware-attack/",
          "publisher": "StateScoop"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-riviera-beach-pays-600-000-ransom-after-an-employee-clicked-a-malicious"
    },
    {
      "slug": "2019-presbyterian-healthcare-services-phishing-exposes-data-on-183-000-patien",
      "title": "Presbyterian Healthcare Services phishing exposes data on 183,000 patients",
      "date": "2019-05-09",
      "date_precision": "day",
      "year": 2019,
      "victim_org": "Presbyterian Healthcare Services",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 183000,
      "threat_actor": null,
      "summary": "New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.",
      "how_it_worked": "Attackers sent phishing emails to Presbyterian staff that led to a page requesting their work credentials. Staff who entered their username and password gave the attackers direct log-in access to the organisation's email system, with no malware involved and nothing unusual for endpoint tools to detect. Access ran for about four weeks before it was found. As with most healthcare mailbox compromises, the exposure came from the ordinary contents of clinical and administrative inboxes, which routinely carry patient identifiers, diagnoses, insurance data and Social Security numbers in message bodies and attachments.",
      "lessons": "Multi-factor authentication on webmail is the single control that turns a harvested healthcare password into a dead end.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Phishing Attack on Presbyterian Healthcare Services Exposed PHI of 183,000 Patients",
          "url": "https://www.hipaajournal.com/phishing-attack-on-presbyterian-healthcare-services-exposed-phi-of-183000-patients/",
          "publisher": "HIPAA Journal"
        },
        {
          "title": "Presbyterian Healthcare phishing scam hits 183K patient records",
          "url": "https://www.healthcareitnews.com/news/presbyterian-healthcare-phishing-scam-hits-183k-patient-records",
          "publisher": "Healthcare IT News"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-presbyterian-healthcare-services-phishing-exposes-data-on-183-000-patien"
    },
    {
      "slug": "2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu",
      "title": "Wipro employee accounts phished and used to attack the IT giant's own customers",
      "date": "2019-04",
      "date_precision": "month",
      "year": 2019,
      "victim_org": "Wipro Limited",
      "sector": "Technology",
      "country": "India",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Supply Chain Compromise",
        "Data Breach"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.",
      "how_it_worked": "Attackers ran a phishing campaign against Wipro staff and captured credentials for a number of corporate accounts. The value of those accounts was not Wipro's own data but Wipro's position as a trusted outsourcing provider with standing access into client environments. Emails sent from genuine Wipro addresses to client contacts carry an authority that no spoofed domain can match, so the compromised mailboxes became the delivery mechanism for attacks on downstream customers. The follow-on activity was financially motivated, centring on gift-card and payment fraud at the affected clients rather than espionage.",
      "lessons": "Managed service providers need phishing-resistant MFA on all staff accounts and customer-side monitoring of provider access, because a phished MSP mailbox is a trusted channel into every client.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Wipro admits to potential breach to employee accounts by phishing attack",
          "url": "https://www.computerweekly.com/news/252461760/Wipro-admits-to-potential-breach-to-employee-accounts-by-phishing-attack",
          "publisher": "Computer Weekly"
        },
        {
          "title": "How Not to Acknowledge a Data Breach",
          "url": "https://krebsonsecurity.com/2019/04/how-not-to-acknowledge-a-data-breach/comment-page-1/",
          "publisher": "Krebs on Security"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu"
    },
    {
      "title": "Norsk Hydro LockerGoga attack traced to weaponised email from a trusted customer",
      "date": "2019-03-19",
      "date_precision": "day",
      "victim_org": "Norsk Hydro ASA",
      "sector": "Manufacturing",
      "country": "Norway",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Ransomware Deployment",
        "Service Disruption"
      ],
      "loss_usd": 71000000,
      "loss_note": "Microsoft's account of the incident states the financial impact would eventually approach $71 million; Hydro's own quarterly disclosures gave figures in a similar range and the company was partly insured.",
      "records_affected": null,
      "threat_actor": "LockerGoga operators",
      "summary": "Norwegian aluminium producer Norsk Hydro was hit by LockerGoga ransomware on 19 March 2019, encrypting thousands of servers and PCs and forcing plants worldwide onto manual operation. Microsoft's account of the response states that in December 2018 attackers had weaponised an email attachment sent from a trusted customer's employee to a Hydro employee, installing a trojan roughly three months before the ransomware was launched. Hydro refused to pay and published unusually detailed updates throughout the recovery.",
      "how_it_worked": "The attackers first compromised a customer's mailbox, then used that genuine business relationship to send a document attachment to a Hydro employee. Because the sender was a real, expected correspondent, the attachment was opened and installed a trojan. Over the following months the intruders escalated into Active Directory, obtained domain-level control and then pushed LockerGoga across the estate, which encrypted files and, in some variants, changed local account passwords and logged users out. Hydro's 35,000 employees across 40 countries lost access to IT systems; some smelters ran on paper procedures for weeks.",
      "lessons": "Attachments from known senders still need detonation and macro controls, and tiered Active Directory administration prevents a single infected desktop from becoming domain-wide ransomware deployment.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Hackers hit Norsk Hydro with ransomware. The company responded with transparency",
          "url": "https://news.microsoft.com/source/features/digital-transformation/hackers-hit-norsk-hydro-ransomware-company-responded-transparency/",
          "publisher": "Microsoft Source"
        },
        {
          "title": "Norsk Hydro responds to ransomware attack with transparency",
          "url": "https://www.microsoft.com/en-us/security/blog/2019/12/17/norsk-hydro-ransomware-attack-transparency/",
          "publisher": "Microsoft Security Blog"
        },
        {
          "title": "Hydro Hit by LockerGoga Ransomware via Active Directory",
          "url": "https://www.bankinfosecurity.com/hydro-hit-by-lockergoga-ransomware-via-active-directory-a-12207",
          "publisher": "BankInfoSecurity"
        }
      ],
      "entry_type": "incident",
      "slug": "2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted",
      "year": 2019,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-norsk-hydro-lockergoga-attack-traced-to-weaponised-email-from-a-trusted"
    },
    {
      "title": "UK energy firm CEO tricked by AI voice clone of German parent-company boss",
      "date": "2019-03",
      "date_precision": "month",
      "victim_org": "Unnamed UK-based energy company (subsidiary of a German parent)",
      "sector": "Energy & Utilities",
      "country": "United Kingdom",
      "primary_vector": "Voice Clone / Audio Deepfake",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Business Email Compromise"
      ],
      "ai_involvement": "Suspected AI-enabled",
      "ai_notes": "Fraud investigators at insurer Euler Hermes attributed the call to commercial voice-synthesis software that reproduced the German executive's accent and speech melody. The AI attribution rests on the insurer's assessment, not on forensic recovery of the tool.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 243000,
      "loss_note": "EUR 220,000, approx US$243,000",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In March 2019 the chief executive of a UK energy company transferred EUR 220,000 (about US$243,000) to a Hungarian account after a phone call from someone he believed was the chief executive of the German parent company. The insurer Euler Hermes, which covered the claim, said the caller used AI-based software to mimic the executive's voice. The money was moved on to Mexico and then dispersed. This is widely cited as the first publicly reported corporate voice-deepfake fraud.",
      "how_it_worked": "The attacker phoned the UK CEO directly and presented as the group chief executive, a person the target reported to and whose voice he knew. The cloned audio carried the familiar German accent and cadence, which served as the trust signal that displaced any need for written confirmation. The pretext was an urgent payment to a Hungarian supplier that had to clear within the hour, and the caller promised the subsidiary would be reimbursed immediately. After the first transfer succeeded the fraudster called back twice more, once claiming reimbursement had been sent and once asking for a further payment. The CEO only balked when the promised refund failed to appear and a later call arrived from an Austrian number.",
      "lessons": "Out-of-band callback to a known-good number and a dual-authorisation rule for first-time beneficiary payments would have broken the single-channel voice trust the attack depended on.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "A Voice Deepfake Was Used To Scam A CEO Out Of $243,000",
          "url": "https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/",
          "publisher": "Forbes"
        },
        {
          "title": "Scammers deepfake CEO's voice to talk underling into $243,000 transfer",
          "url": "https://www.sophos.com/en-us/blog/scammers-deepfake-ceos-voice-to-talk-underling-into-243000-transfer",
          "publisher": "Sophos Naked Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo",
      "year": 2019,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-uk-energy-firm-ceo-tricked-by-ai-voice-clone-of-german-parent-company-bo"
    },
    {
      "slug": "2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000",
      "title": "Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients",
      "date": "2019-01-08",
      "date_precision": "day",
      "year": 2019,
      "victim_org": "Oregon Department of Human Services",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 645000,
      "threat_actor": null,
      "summary": "On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.",
      "how_it_worked": "A single phishing email reached staff across a large state welfare agency and nine separate employees acted on it, which is the salient fact: the message was ordinary enough that nearly a dozen people in different roles saw nothing wrong. No malware was installed at any point, so there was nothing for endpoint defences to catch. The attacker simply logged into the mailboxes with the harvested credentials and read them like any other user. The exposure was so large because caseworker mailboxes in a human services agency accumulate years of correspondence about benefit recipients, with identifiers and health details in the message bodies.",
      "lessons": "Multi-factor authentication would have neutralised the stolen passwords outright; mailbox retention limits would have shrunk the two million messages sitting behind them.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Phishing Attack Exposes Data of 645,000 Oregon DHS Clients",
          "url": "https://www.bleepingcomputer.com/news/security/phishing-attack-exposes-data-of-645-000-oregon-dhs-clients/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "645,000 Clients Affected in Oregon Department of Human Services Data Breach",
          "url": "https://www.securityweek.com/645000-clients-affected-oregon-department-human-services-data-breach/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000"
    },
    {
      "title": "Tecnimont India loses $18.6 million to fake CEO conference calls",
      "date": "2018-12",
      "date_precision": "month",
      "victim_org": "Tecnimont SpA (Indian subsidiary, Maire Tecnimont group)",
      "sector": "Professional Services",
      "country": "India",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vishing (Voice Phishing)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "Impersonation on the conference calls was performed by live human actors; no synthetic voice was reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 18600000,
      "loss_note": "About 1.3 billion rupees, reported as roughly $18.5-18.6 million, sent in three installments to banks in Hong Kong.",
      "records_affected": null,
      "threat_actor": "Group reported by the company to be operating from China",
      "summary": "The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.",
      "how_it_worked": "This scheme layered voice over email to defeat skepticism. Messages arrived from a domain closely resembling the group CEO's, describing a secret acquisition in China that had to be funded from India because regulatory constraints supposedly blocked transfers from Italy. To answer the obvious objection, the fraudsters convened conference calls in which multiple actors played the CEO, group executives and an external Swiss attorney, giving the transaction the texture of a real deal team. Secrecy was justified as regulatory sensitivity, which kept the India head from calling headquarters. Three tranches were wired to Hong Kong before the parent company discovered the deception.",
      "lessons": "Verification must go through a channel the attacker does not control: a callback to headquarters' known switchboard would have collapsed the entire fake deal team.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Chinese group swindles $18.5 million from Indian arm of Italian company",
          "url": "https://in.marketscreener.com/quote/stock/MAIRE-S-P-A-13369769/news/Maire-Tecnimont-Chinese-group-swindles-18-5-million-from-Indian-arm-of-Italian-company-Economic-27846733/",
          "publisher": "The Economic Times via MarketScreener"
        },
        {
          "title": "BEC Scam Leads to Theft of $18.6 Million",
          "url": "https://www.bankinfosecurity.com/bec-scam-leads-to-theft-186-million-fraud-a-11930",
          "publisher": "BankInfoSecurity"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls",
      "year": 2018,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-tecnimont-india-loses-18-6-million-to-fake-ceo-conference-calls"
    },
    {
      "title": "Cabarrus County, NC diverts $2.5 million school payment to BEC actors",
      "date": "2018-11",
      "date_precision": "month",
      "victim_org": "Cabarrus County, North Carolina",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Business Email Compromise"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 2504601,
      "loss_note": "$2,504,601 paid to fraudsters; $776,518.40 recovered, leaving about $1.7 million unrecovered.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.",
      "how_it_worked": "The attackers targeted the vendor master-data process rather than a single invoice. Posing as the school construction contractor, they submitted a bank-account change request accompanied by forms and signatures that matched what the county's finance staff expected to see for a legitimate update. Once the fraudulent account details were accepted into the vendor record, the next scheduled construction draw, more than $2.5 million, flowed to the criminals automatically through the county's normal payment run, with no anomaly to catch. The money was then layered through multiple downstream accounts, and only a fraction was traced and clawed back after the county recognized the diversion weeks later.",
      "lessons": "Vendor bank-detail changes should be treated as a privileged change: verified by outbound call to a number from the original contract, confirmed by a second staffer, and followed by a small test payment before the next large draw.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Scammers Grab $2.5 Million From North Carolina County in BEC Scam",
          "url": "https://www.securityweek.com/scammers-grab-25-million-north-carolina-county-bec-scam/",
          "publisher": "SecurityWeek"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors",
      "year": 2018,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-cabarrus-county-nc-diverts-2-5-million-school-payment-to-bec-actors"
    },
    {
      "title": "Mobile carrier employee took $500-a-day bribes to perform SIM swaps",
      "date": "2018-10",
      "date_precision": "month",
      "victim_org": "Unnamed US mobile carrier ('Phone Company A') and at least 19 of its customers",
      "sector": "Telecom",
      "country": "United States",
      "primary_vector": "Insider Recruitment",
      "secondary_vectors": [
        "SIM Swap"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Insider Access",
        "Identity Theft",
        "Cryptocurrency Theft"
      ],
      "loss_usd": null,
      "loss_note": "DOJ did not state aggregate victim losses in the charging announcement. Defiore received approximately $2,325 across twelve bribe payments, at roughly $500 per day of swaps.",
      "records_affected": 19,
      "threat_actor": "Stephen Daniel Defiore and unnamed co-conspirators",
      "summary": "A US Attorney's Office charged a former mobile phone company employee with accepting bribes to perform unauthorized SIM swaps on customer accounts. Between October 20 and November 9, 2018, a co-conspirator sent him customer phone numbers, four-digit PINs and destination SIM numbers, and he executed the swaps from inside the carrier's systems. At least 19 customers were targeted in the wider conspiracy, including a New Orleans physician.",
      "how_it_worked": "The deceived party here was the carrier itself, not a customer. Rather than talk a retail rep into a fraudulent swap, the conspiracy simply put one on payroll. A co-conspirator messaged Defiore a target's phone number, account PIN and the SIM identifier to swap the line to; Defiore, who worked at the carrier from August 2017 to November 2018, used his legitimate employee access to execute the change and was paid roughly $500 per day. Because the change was made by an authorized account with a valid business reason on its face, none of the carrier's customer-facing verification controls applied. The hijacked numbers then received the victims' SMS authentication codes.",
      "lessons": "SIM-change transactions need behavioral monitoring on the employee side, including per-rep swap-rate baselining and out-of-band customer confirmation, since insider abuse looks identical to authorized work in the logs.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Former Phone Company Employee Charged for Role in SIM Swap Scam That Targeted at Least 19 Customers",
          "url": "https://www.justice.gov/usao-edla/pr/former-phone-company-employee-charged-rolein-sim-swap-scam-targeted-least-19-customers",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps",
      "year": 2018,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-mobile-carrier-employee-took-500-a-day-bribes-to-perform-sim-swaps"
    },
    {
      "slug": "2018-san-diego-unified-staff-phished-exposing-500-000-students-parents-and-em",
      "title": "San Diego Unified staff phished, exposing 500,000 students, parents and employees",
      "date": "2018-10",
      "date_precision": "month",
      "year": 2018,
      "victim_org": "San Diego Unified School District",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 500000,
      "threat_actor": null,
      "summary": "San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.",
      "how_it_worked": "The attacker sent phishing emails to district staff that led to pages designed to capture network log-in credentials. Because a school district's staff population is large, distributed across many sites and generally does not have dedicated security support, a broad credential-harvesting campaign only had to work on a handful of recipients. The stolen log-ins gave ordinary authenticated access to district systems, which is why the intrusion looked like normal staff activity for eleven months. It was detected in October 2018 only because multiple employees independently reported the phishing emails, which prompted the investigation that revealed the wider access.",
      "lessons": "Multi-factor authentication on staff single sign-on, plus alerting on anomalous access to student information systems, is what turns an eleven-month intrusion into a same-day one.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Info on Over 500,000 Students and Staff Exposed in San Diego School District Hack",
          "url": "https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/",
          "publisher": "BleepingComputer"
        },
        {
          "title": "San Diego Schools Say Phishing Scam Caused Cyber Breach",
          "url": "https://www.newsweek.com/san-diego-unified-school-district-san-diego-police-department-phishing-cyber-1269185",
          "publisher": "Newsweek"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-san-diego-unified-staff-phished-exposing-500-000-students-parents-and-em"
    },
    {
      "title": "Virtual kidnapping ring extorts parents with staged ransom calls",
      "date": "2018-09-20",
      "date_precision": "day",
      "victim_org": "Parents in Texas, California and Idaho (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States and Mexico",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "The scheme used pre-recorded gasping audio and live callers, not synthetic voice.",
      "outcomes": [
        "Extortion",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "The Justice Department did not publish a total loss figure for this prosecution.",
      "records_affected": null,
      "threat_actor": "Yanette Rodriguez Acosta and Mexico-based co-conspirators (convicted)",
      "summary": "On 20 September 2018 Yanette Rodriguez Acosta of Houston was sentenced to 88 months in federal prison for conspiracy to commit wire fraud and money laundering in a virtual kidnapping extortion scheme. Co-conspirators in Mexico called victims in Texas, California and Idaho falsely claiming to have kidnapped their children and demanding ransom. The sentencing judge said the defendant showed gleeful disregard for victims while inflicting pain, fear and long-term effects for profit.",
      "how_it_worked": "The call opened with recorded audio of a child gasping and saying mom or dad. When the parent reacted by calling out their child's name, the caller seized that name and used it for the rest of the call, manufacturing proof of possession without knowing anything about the family. Threats of violence followed, and the parent was kept on the phone continuously for hours while driving to banks and wire transfer offices, a tactic that prevents any call to the child's school or mobile phone. In one case a couple searched nearby dumpsters for their child's body. No actual abduction ever occurred.",
      "lessons": "The single control is refusing to stay on the line: any ransom call should be met by a second person immediately calling the supposed victim on another phone, which collapses the pretext in seconds.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Texas Woman Sentenced in Virtual Kidnapping Extortion Scheme",
          "url": "https://www.justice.gov/usao-sdtx/pr/texas-woman-sentenced-virtual-kidnapping-extortion-scheme",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "campaign",
      "slug": "2018-virtual-kidnapping-ring-extorts-parents-with-staged-ransom-calls",
      "year": 2018,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-virtual-kidnapping-ring-extorts-parents-with-staged-ransom-calls"
    },
    {
      "title": "India-based IRS and USCIS impersonation call centers: 24 defendants sentenced",
      "date": "2018-07-20",
      "date_precision": "day",
      "victim_org": "US consumers, many of them elderly (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States and India",
      "primary_vector": "Vishing (Voice Phishing)",
      "secondary_vectors": [
        "Insider Recruitment"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement; the calls were made by live scripted operators.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Identity Theft"
      ],
      "loss_usd": 8970396,
      "loss_note": "Restitution of $8,970,396 was ordered for identified victims across 22 defendants, with money judgments exceeding $72.9 million; defendants were held liable for laundering between $3.5 million and $25 million collectively.",
      "records_affected": null,
      "threat_actor": "Ahmedabad-based call center network and US-based runner network",
      "summary": "On 20 July 2018 the Department of Justice announced that 24 defendants had been sentenced for running and supporting India-based call centers that impersonated IRS and USCIS officials to defraud US victims. Sentences ranged from probation to 20 years, with the three longest being 240, 188 and 165 months. Restitution of $8,970,396 was ordered and money judgments exceeded $72.9 million. A further 32 India-based conspirators were charged.",
      "how_it_worked": "Operators in Ahmedabad called Americans, many of them elderly or recent immigrants, and identified themselves as IRS or USCIS officials. They asserted that back taxes were owed or that an immigration status problem had been found, and threatened immediate arrest, imprisonment, fines or deportation unless payment was made at once. The lever was raw state authority plus a deliberately compressed timeline that prevented the victim from consulting family or a lawyer. Payment was demanded in stored value cards or wire transfers, and US-based runners then liquidated the cards, bought money orders and collected wires under false identities to launder the proceeds.",
      "lessons": "Public education that tax and immigration agencies never demand payment by gift card or threaten immediate arrest by phone, combined with retailer prompts at gift card checkout, directly disrupts this model.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "24 Defendants Sentenced in Multimillion Dollar India-Based Call Center Scam Targeting U.S. Victims",
          "url": "https://www.justice.gov/archives/opa/pr/24-defendants-sentenced-multimillion-dollar-india-based-call-center-scam-targeting-us-victims",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "campaign",
      "slug": "2018-india-based-irs-and-uscis-impersonation-call-centers-24-defendants-sente",
      "year": 2018,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-india-based-irs-and-uscis-impersonation-call-centers-24-defendants-sente"
    },
    {
      "title": "City of Ottawa treasurer wires about US$98,000 to fake city manager",
      "date": "2018-07",
      "date_precision": "month",
      "victim_org": "City of Ottawa",
      "sector": "Government",
      "country": "Canada",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 98000,
      "loss_note": "Approximately US$98,000 wired (reported locally as roughly C$128,000). A second request for US$150,000 was blocked. The U.S. Secret Service monitored a receiving account and an individual connected to the scheme was arrested.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.",
      "how_it_worked": "The attacker impersonated the city manager, the one person whose instruction the treasurer would be least likely to challenge, and framed the payment as a confidential acquisition requiring a quick wire. The exchange ran over several emails, letting the fraudster answer questions and build rapport in the city manager's voice, which reinforced authenticity. Because the amount was modest by municipal standards and the requester was the treasurer's superior, the transfer cleared normal handling. The scheme unraveled only by coincidence when the treasurer was physically next to the real city manager during a follow-up request, illustrating that the control that caught it was luck rather than process.",
      "lessons": "Executive-initiated wire requests should require verbal confirmation on a known number before release, and municipalities should bar email as an authorization channel for funds transfers entirely.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "City of Ottawa treasurer fell victim to US$100K phishing scam: auditor general",
          "url": "https://obj.ca/city-of-ottawa-treasurer-fell-victim-to-us100k-phishing-scam-auditor-general/",
          "publisher": "Ottawa Business Journal"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-city-of-ottawa-treasurer-wires-about-us-98-000-to-fake-city-manager",
      "year": 2018,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-city-of-ottawa-treasurer-wires-about-us-98-000-to-fake-city-manager"
    },
    {
      "title": "Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud",
      "date": "2018-04",
      "date_precision": "month",
      "victim_org": "Unatrac Holding Limited (Caterpillar export sales affiliate)",
      "sector": "Manufacturing",
      "country": "United Kingdom",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Credential Phishing Portal",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Credential Theft"
      ],
      "loss_usd": 11000000,
      "loss_note": "Approximately $11 million in fraudulent transfer requests sent from the compromised CFO account in April 2018; DOJ cited about $11 million in known losses across the wider scheme.",
      "records_affected": null,
      "threat_actor": "Obinwanne Okeke ('Invictus Obi') and co-conspirators, Nigeria",
      "summary": "Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.",
      "how_it_worked": "The crew sent a credential-phishing email to Unatrac's chief financial officer that harvested his Microsoft Office 365 login. With mailbox access, they read pending payment correspondence, then sent roughly fifteen fraudulent transfer requests and payment approvals over eight days in April 2018 that appeared to come directly from the CFO. Fake invoices and altered supplier banking details supported the requests, and finance staff processed them as ordinary executive-approved payments because they arrived from the genuine internal account. Funds were routed to overseas accounts. The company recognized the fraud only after the CFO's mailbox behavior and the missing payments were reconciled in June 2018.",
      "lessons": "Multifactor authentication on executive mailboxes plus monitoring for anomalous mailbox rules and sign-ins would have blocked the takeover that made every downstream approval look authentic.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Nigerian National Sentenced to Prison for $11 Million Global Fraud Scheme",
          "url": "https://www.justice.gov/usao-edva/pr/nigerian-national-sentenced-prison-11-million-global-fraud-scheme",
          "publisher": "U.S. Department of Justice, E.D. Va."
        }
      ],
      "entry_type": "incident",
      "slug": "2018-obinwanne-okeke-sentenced-to-10-years-over-11-million-unatrac-bec-fraud",
      "year": 2018,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-obinwanne-okeke-sentenced-to-10-years-over-11-million-unatrac-bec-fraud"
    },
    {
      "slug": "2018-fin7-breach-of-saks-fifth-avenue-and-lord-taylor-exposes-5-million-payme",
      "title": "FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards",
      "date": "2018-04",
      "date_precision": "month",
      "year": 2018,
      "victim_org": "Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor)",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 5000000,
      "threat_actor": "FIN7 / JokerStash (Fin7 syndicate)",
      "summary": "In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.",
      "how_it_worked": "FIN7's tradecraft against retail and hospitality victims was consistent: emails written to look like routine business correspondence, carrying a malicious attachment, sent to corporate staff, then reinforced by a phone call from a group member who referenced the message and urged the recipient to open it. Opening the document installed a backdoor and gave the group a corporate foothold from which they reached point-of-sale infrastructure and deployed card-scraping malware. At Hudson's Bay this produced roughly five million card records over about a year, which then surfaced for sale in tranches on an underground marketplace.",
      "lessons": "Network segmentation between corporate email endpoints and payment infrastructure limits how far one opened attachment can travel.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Fin7 Syndicate Hacks Saks Fifth Avenue and Lord & Taylor",
          "url": "https://geminiadvisory.io/fin7-syndicate-hacks-saks-fifth-avenue-and-lord-taylor/",
          "publisher": "Gemini Advisory"
        },
        {
          "title": "Hackers steal payment card data of 5 million Saks, Lord & Taylor customers",
          "url": "https://www.helpnetsecurity.com/2018/04/03/saks-breach/",
          "publisher": "Help Net Security"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-fin7-breach-of-saks-fifth-avenue-and-lord-taylor-exposes-5-million-payme"
    },
    {
      "title": "Pathé Dutch branch wires €19 million in fake CEO acquisition scam",
      "date": "2018-03",
      "date_precision": "month",
      "victim_org": "Pathé (Netherlands branch)",
      "sector": "Media & Entertainment",
      "country": "Netherlands",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 21500000,
      "loss_note": "More than €19 million (about $21.5 million) paid in multiple transfers, including from the Pathé group cash pool in France. Recovery not publicly confirmed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In March 2018 fraudsters impersonating the chief executive of French film company Pathé's parent persuaded the Dutch branch's leadership to make a series of payments totaling more than €19 million for a purported acquisition of a Dubai-based company. Branch director Dertje Meijer and CFO Edwin Slutter were both dismissed after the loss surfaced. An external investigation cleared them of involvement, and Slutter later won partial relief in a wrongful-termination suit.",
      "how_it_worked": "The attackers opened with a low-key question about a KPMG contact to establish a plausible thread, then escalated to a confidential acquisition of a Dubai entity, insisting that all communication run through a spoofed personal address 'as a security measure' for sensitive transactions. When the CFO asked for verification, the fraudsters produced a forged authorization email from the Pathé France manager complete with copied signatures and an invoice from the supposed Dubai target. The CFO checked the signatures, which matched, and payments proceeded from several sources including the group cash pool. Small inconsistencies in the correspondence were noticed but not escalated until headquarters queried the withdrawals.",
      "lessons": "Document-based verification is not verification when the attacker supplies the documents; approval for cross-border deal payments must be confirmed by voice with named group officers on known numbers.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "BEC scammers stole €19m from film company Pathé",
          "url": "https://www.helpnetsecurity.com/2018/11/14/pathe-bec-scam/",
          "publisher": "Help Net Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-pathe-dutch-branch-wires-19-million-in-fake-ceo-acquisition-scam",
      "year": 2018,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-pathe-dutch-branch-wires-19-million-in-fake-ceo-acquisition-scam"
    },
    {
      "slug": "2018-cinema-group-pathe-loses-eur-19-2-million-to-ceo-fraud-dutch-executives",
      "title": "Cinema group Pathe loses EUR 19.2 million to CEO fraud; Dutch executives dismissed",
      "date": "2018-03",
      "date_precision": "month",
      "year": 2018,
      "victim_org": "Pathe (Pathe Nederland)",
      "sector": "Media & Entertainment",
      "country": "Netherlands",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 21500000,
      "loss_kind": "direct_loss",
      "loss_note": "EUR 19.2 million (about US$21.5 million at the time). A Dutch court later upheld the dismissal of the executives involved.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Between March and May 2018 the Dutch arm of the French cinema chain Pathe transferred about EUR 19.2 million in a series of payments to accounts in Dubai, acting on emails purporting to come from Pathe's French head office. The company dismissed the managing director and financial director of Pathe Nederland; a Dutch court ruling later published details of the case and upheld the dismissals.",
      "how_it_worked": "Emails presented as coming from Pathe's headquarters in France told the Dutch leadership that the group was making a confidential acquisition in Dubai and needed funds released quickly, with strict instructions not to discuss it internally because of regulatory sensitivity. The correspondence adopted the tone and structure of genuine group communications and continued over weeks, with follow-up messages managing the executives' doubts as the sums grew. The confidentiality clause was the key mechanism: it explained away every anomaly and stopped the one action, a phone call to Paris, that would have ended the fraud immediately.",
      "lessons": "Any instruction whose own terms forbid verification should be treated as fraudulent by default; secrecy is the tell, not the credential.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Details of Pathe Nederland's EUR 19.2M Loss to CEO-fraud Revealed",
          "url": "https://celluloidjunkie.com/2018/11/12/details-of-pathe-nederlands-e19-2m-loss-to-ceo-fraud-revealed/",
          "publisher": "Celluloid Junkie"
        },
        {
          "title": "Dutch Film Boss Sacked After EUR 19m BEC Loss",
          "url": "https://www.infosecurity-magazine.com/news/dutch-film-boss-sacked-after-19m/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-cinema-group-pathe-loses-eur-19-2-million-to-ceo-fraud-dutch-executives"
    },
    {
      "slug": "2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli",
      "title": "UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients",
      "date": "2018-03",
      "date_precision": "month",
      "year": 2018,
      "victim_org": "UnityPoint Health",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": 2800000,
      "loss_kind": "business_impact",
      "loss_note": "US$2.8 million class-action settlement to resolve litigation over the breach.",
      "records_affected": 1400000,
      "threat_actor": null,
      "summary": "UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.",
      "how_it_worked": "The phishing emails were crafted to appear to come from an executive inside UnityPoint Health, which gave them the internal legitimacy that gets messages read and links clicked. Staff who followed the links and entered their credentials handed over access to their mailboxes, and the attackers used those accounts for about three weeks. The financial motive shows in what they did next: they hunted for vendor invoices and payroll processes to redirect. The patient data exposure, which included medical, insurance, Social Security and in some cases payment card details, was collateral, simply whatever happened to be sitting in the compromised inboxes.",
      "lessons": "Multi-factor authentication on clinical staff email, and a policy against storing patient identifiers in mailboxes, would have limited both the access and the exposure.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "1.4 million patient records breached in UnityPoint Health phishing attack",
          "url": "https://www.healthcareitnews.com/news/14-million-patient-records-breached-unitypoint-health-phishing-attack",
          "publisher": "Healthcare IT News"
        },
        {
          "title": "1.4 Million Patients Warned About UnityPoint Health Phishing Attack",
          "url": "https://www.hipaajournal.com/unitypoint-health-phishing-attack-1-4-million-patients/",
          "publisher": "HIPAA Journal"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli"
    },
    {
      "title": "AT&T SIM swap drains $24M in crypto from investor Michael Terpin",
      "date": "2018-01",
      "date_precision": "month",
      "victim_org": "Michael Terpin (individual investor; Transform Group)",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Insider Recruitment",
        "Help Desk Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media was reported in this case; the attack relied on carrier account takeover and insider assistance.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Identity Theft"
      ],
      "loss_usd": 24000000,
      "loss_note": "Approximately $24 million in cryptocurrency at the values cited in Terpin's litigation and contemporaneous reporting. A Los Angeles Superior Court default judgment against Nicholas Truglia totaled $75.8 million including treble RICO damages and prejudgment interest.",
      "records_affected": null,
      "threat_actor": "Nicholas Truglia and associates; Ellis Pinsky, then 15, later named as a participant",
      "summary": "Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.",
      "how_it_worked": "Attackers targeted the mobile carrier rather than Terpin directly. According to reporting on the litigation, a then-15-year-old and an accomplice bribed an AT&T employee to move Terpin's SIM information onto a blank SIM card in a phone they controlled. Once the number was theirs, inbound SMS one-time codes and password-reset links flowed to the attackers, letting them reset credentials on Terpin's email and exchange accounts and sweep his holdings. Terpin had reportedly already asked AT&T to place additional protections on the account, which the complaint alleged were not effective against an employee acting from inside the carrier's own systems.",
      "lessons": "Removing SMS from the authentication path for high-value crypto accounts, and enforcing dual-control plus supervisory approval on carrier-side SIM changes, would have broken this chain.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Cryptocurrency Investor Michael Terpin Wins $75.8 Million Judgment in First-Ever SIM Swap Racketeering Case",
          "url": "https://www.greenbergglusker.com/news/cryptocurrency-investor-michael-terpin-wins-75-8-million-judgment-in-first-ever-sim-swap-racketeering-case",
          "publisher": "Greenberg Glusker"
        },
        {
          "title": "Court revives 2020 AT&T case over $24M crypto theft via SIM swap",
          "url": "https://cointelegraph.com/news/att-court-sim-swap-crypto-theft",
          "publisher": "Cointelegraph"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin",
      "year": 2018,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-at-t-sim-swap-drains-24m-in-crypto-from-investor-michael-terpin"
    },
    {
      "title": "Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree",
      "date": "2018",
      "date_precision": "year",
      "victim_org": "Approximately 40 individual cryptocurrency holders",
      "sector": "Cryptocurrency",
      "country": "United States",
      "primary_vector": "SIM Swap",
      "secondary_vectors": [
        "Help Desk Impersonation",
        "Insider Recruitment"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement was reported.",
      "outcomes": [
        "Cryptocurrency Theft",
        "Identity Theft"
      ],
      "loss_usd": 7500000,
      "loss_note": "CoinDesk reported thefts exceeding $7.5 million across roughly 40 victims, including a single May 2018 theft of more than $5.2 million from a Cupertino entrepreneur. Vice reported the aggregate as 'over $5 million'. About $400,000 was recovered at arrest.",
      "records_affected": null,
      "threat_actor": "Joel Ortiz",
      "summary": "Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.",
      "how_it_worked": "Ortiz and associates identified crypto holders from conference attendance and social media, then attacked their mobile carrier accounts rather than their wallets. Using victim personal data and, in the wider SIM-swap ecosystem the task force mapped, cooperative or deceived retail carrier staff, they had target numbers ported onto SIM cards they controlled. Possession of the number let them intercept SMS one-time passcodes and password-reset links, take over email and exchange accounts, and transfer funds out. One May 2018 swap moved more than $5.2 million within minutes. Proceeds went to club spending, a helicopter rental and designer goods.",
      "lessons": "Carrier port-out PINs and number-lock features, plus app- or hardware-based MFA instead of SMS on exchange accounts, remove the single point of failure this scheme depended on.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Student Gets 10-Year Jail Term for SIM-Swap Crypto Thefts Worth $7.5 Million",
          "url": "https://www.coindesk.com/markets/2019/04/23/student-gets-10-year-jail-term-for-sim-swap-crypto-thefts-worth-75-million",
          "publisher": "CoinDesk"
        },
        {
          "title": "Hacker Who Stole $5 Million By SIM Swapping Gets 10 Years in Prison",
          "url": "https://www.vice.com/en/article/hacker-joel-ortiz-sim-swapping-10-years-in-prison/",
          "publisher": "Vice / Motherboard"
        }
      ],
      "entry_type": "incident",
      "slug": "2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree",
      "year": 2018,
      "loss_kind": "aggregate",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2018-joel-ortiz-gets-10-years-for-7-5m-sim-swap-crypto-theft-spree"
    },
    {
      "title": "Operation Tech Trap: 29 actions against fake Microsoft and Apple support pop-ups",
      "date": "2017-05-12",
      "date_precision": "day",
      "victim_org": "US consumers (multi-victim campaign)",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Tech Support Scam",
      "secondary_vectors": [
        "Callback Phishing (TOAD)",
        "Watering Hole / Malvertising"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement; the era predates generative tooling in this scam type.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "The FTC stated consumers paid millions of dollars but published no single campaign total. Individual matters included a $27 million default judgment and $1.3 million in forfeited assets.",
      "records_affected": null,
      "threat_actor": "Repair All PC LLC, Troth Solutions, Vylah Tec, Universal Network Solutions, Click4Support, BigDog Solutions, First Choice Tech Support and others",
      "summary": "On 12 May 2017 the FTC announced Operation Tech Trap with federal, state and international partners, unveiling 16 new complaints, settlements, indictments and guilty pleas and bringing the total to 29 actions in a year against technical support scammers. Defendants included Repair All PC LLC, Troth Solutions Inc., Vylah Tec LLC, Universal Network Solutions LLC, Click4Support LLC, BigDog Solutions LLC and seven individuals connected to First Choice Tech Support LLC and Client Care Experts.",
      "how_it_worked": "Consumers browsing the web were served pop-up advertisements built to mimic genuine security alerts from Microsoft, Apple and other technology companies, warning that the machine was infected or being hacked and instructing the user to call a toll-free number. Telemarketers answering those calls claimed to represent the impersonated vendor, talked the victim into installing remote access software, and ran theatrical fake diagnostic tests that displayed ordinary system logs as evidence of infection. Having manufactured alarm and demonstrated apparent expertise, they sold hundreds of dollars of unnecessary repairs, software and multi-year service plans.",
      "lessons": "Browser and OS vendors blocking full-screen dialog abuse, plus the simple consumer rule that no legitimate vendor puts a support phone number in a security warning, removes the entry point.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "FTC and Federal, State and International Partners Announce Major Crackdown on Tech Support Scams",
          "url": "https://www.ftc.gov/news-events/news/press-releases/2017/05/ftc-federal-state-international-partners-announce-major-crackdown-tech-support-scams",
          "publisher": "Federal Trade Commission"
        }
      ],
      "entry_type": "campaign",
      "slug": "2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support",
      "year": 2017,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2017-operation-tech-trap-29-actions-against-fake-microsoft-and-apple-support"
    },
    {
      "title": "Save the Children Federation loses nearly $1 million in charity BEC fraud",
      "date": "2017-05",
      "date_precision": "month",
      "victim_org": "Save the Children Federation, Inc.",
      "sector": "Nonprofit",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Credential Theft"
      ],
      "loss_usd": 1000000,
      "loss_note": "Approximately $1 million diverted; insurance covered most of it, leaving the charity with a net loss of about $112,000.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.",
      "how_it_worked": "The attacker first phished credentials and gained control of a legitimate internal mailbox, which removed the usual lookalike-domain tell from the fraud. Operating from inside the organization's own email, they generated invoices and supporting documentation for a plausible program expense, solar equipment for Pakistani health facilities, that matched the charity's real field activities. Approvals then flowed through normal internal channels because every message came from a trusted colleague's real address. Payment was directed to a bank account in Japan, a jurisdiction inconsistent with the stated project, and the funds were gone before the discrepancy was noticed during later reconciliation.",
      "lessons": "Account takeover defeats sender-based trust, so payment approvals for program expenses need out-of-band confirmation plus a geography sanity check between the vendor, the project and the receiving bank.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Save the Children Charity Org Scammed for Almost $1 Million",
          "url": "https://www.bleepingcomputer.com/news/security/save-the-children-charity-org-scammed-for-almost-1-million/",
          "publisher": "BleepingComputer"
        }
      ],
      "entry_type": "incident",
      "slug": "2017-save-the-children-federation-loses-nearly-1-million-in-charity-bec-fraud",
      "year": 2017,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2017-save-the-children-federation-loses-nearly-1-million-in-charity-bec-fraud"
    },
    {
      "slug": "2017-chipotle-payment-card-breach-traced-to-fin7-phishing-emails-backed-by-ph",
      "title": "Chipotle payment card breach traced to FIN7 phishing emails backed by phone calls",
      "date": "2017-04",
      "date_precision": "month",
      "year": 2017,
      "victim_org": "Chipotle Mexican Grill",
      "sector": "Hospitality",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "FIN7 / Carbanak",
      "summary": "Chipotle disclosed in May 2017 that point-of-sale malware had captured payment card track data at restaurants between 24 March and 18 April 2017, including cardholder name, card number, expiry date and verification code. The FBI attributed the intrusion to FIN7, naming Chipotle among the group's publicly disclosed US victims. FIN7 entered victim networks through phishing emails that employees opened, reinforced by follow-up phone calls.",
      "how_it_worked": "FIN7 emailed restaurant corporate and store staff with messages written to read as ordinary business correspondence, such as catering orders or complaints, carrying an attached document. Group members then telephoned the recipient, referred to the email they had just sent and encouraged the employee to open the attachment, which is the detail that made the campaign so effective: the voice call converted a suspicious attachment into an expected one. Opening the document installed a backdoor, from which the group moved to point-of-sale systems and deployed card-scraping malware. Across its victims FIN7 took more than 15 million card records from over 6,500 terminals.",
      "lessons": "Treat an unsolicited phone call that vouches for an emailed attachment as an escalation, not a reassurance, and block macro-enabled documents from external senders.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "How Cyber Crime Group FIN7 Attacked and Stole Data from Hundreds of U.S. Companies",
          "url": "https://www.fbi.gov/contact-us/field-offices/seattle/news/stories/how-cyber-crime-group-fin7-attacked-and-stole-data-from-hundreds-of-us-companies",
          "publisher": "Federal Bureau of Investigation"
        },
        {
          "title": "Chipotle Mexican Grill Reports Findings from Investigation of Payment Card Security Incident",
          "url": "https://newsroom.chipotle.com/2017-05-26-chipotle-mexican-grill-reports-findings-from-investigation-of-payment-card-security-incident",
          "publisher": "Chipotle Mexican Grill"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2017-chipotle-payment-card-breach-traced-to-fin7-phishing-emails-backed-by-ph"
    },
    {
      "title": "IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits",
      "date": "2017-02-02",
      "date_precision": "day",
      "victim_org": "US school districts, tribal organizations, nonprofits and employers (multi-victim campaign)",
      "sector": "Education",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported in the IRS alert.",
      "outcomes": [
        "Data Breach",
        "Identity Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "The IRS did not publish an aggregate dollar figure; it stated some organisations lost both employee W-2s and thousands of dollars in wire transfers.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.",
      "how_it_worked": "Criminals spoofed an organisation's executive and emailed payroll or human resources staff asking for a list of all employees and their Forms W-2. School districts and small nonprofits were attractive because payroll is often handled by one or two people with no formal verification procedure and no security team. After the W-2 file was sent, the same spoofed executive followed up with a request to the payroll or comptroller staff to wire funds to a specified account, exploiting the compliance momentum created by the first successful request. Some organisations lost both the employee data and the money.",
      "lessons": "Small public-sector and nonprofit payroll functions need a written, mandatory callback rule for executive requests, since they lack the compensating controls larger firms rely on.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "IR-2017-20: Dangerous W-2 Phishing Scam Evolving; Targeting Schools, Restaurants, Hospitals, Tribal Groups and Others",
          "url": "https://www.irs.gov/pub/irs-news/ir-17-020.pdf",
          "publisher": "Internal Revenue Service"
        }
      ],
      "entry_type": "campaign",
      "slug": "2017-irs-warns-of-w-2-phishing-epidemic-spreading-to-school-districts-and-non",
      "year": 2017,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2017-irs-warns-of-w-2-phishing-epidemic-spreading-to-school-districts-and-non"
    },
    {
      "title": "Dublin Zoo defrauded of about €500,000 in invoice redirection scam",
      "date": "2017",
      "date_precision": "year",
      "victim_org": "Dublin Zoo",
      "sector": "Other",
      "country": "Ireland",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Business Email Compromise"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "Approximately €500,000 was diverted; Gardaí recovered most of the funds, with reporting indicating roughly €130,000 outstanding. No official USD figure was published.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.",
      "how_it_worked": "The scheme substituted the destination account on invoices the zoo already expected to pay, so nothing about the amount, the supplier name or the timing looked unusual. Criminals obtained or replicated genuine invoices and presented altered bank details as a routine change of the supplier's account, communicated by email or phone. Finance staff updated the payment details and released the payments in the ordinary run. Gardaí publicly warned after the case that no business should change a supplier's bank account number on the basis of a call or email without verifying the change with a known contact at the supplier, which is precisely the control gap the fraud exploited.",
      "lessons": "Treat supplier bank-detail changes as a security event requiring verification with a known contact using previously held numbers, and reconcile with suppliers promptly so a diversion is caught while funds are still recoverable.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Dublin Zoo lost €500k after falling victim to cyber scam",
          "url": "https://www.irishexaminer.com/ireland/dublin-zoo-lost-500k-after-falling-victim-to-cyber-scam-464818.html",
          "publisher": "Irish Examiner"
        }
      ],
      "entry_type": "incident",
      "slug": "2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam",
      "year": 2017,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam"
    },
    {
      "slug": "2017-russian-fsb-officers-spear-phished-wolf-creek-nuclear-plant-in-global-en",
      "title": "Russian FSB officers spear-phished Wolf Creek nuclear plant in global energy campaign",
      "date": "2017",
      "date_precision": "year",
      "year": 2017,
      "victim_org": "Wolf Creek Nuclear Operating Corporation",
      "sector": "Energy & Utilities",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Watering Hole / Malvertising",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Russian FSB Center 16 (Dragonfly / Energetic Bear); three officers indicted by the US DOJ in 2021, unsealed 2022",
      "summary": "A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.",
      "how_it_worked": "The operators mailed engineers and IT staff at energy companies with documents tailored to their work, including material presented as job applications and CVs and as industry technical content, so opening the attachment felt like part of the job. Recipients who opened the files installed malware or were funnelled to credential-harvesting pages. The campaign also compromised websites the same engineers routinely visited, so credentials could be captured without any email at all. At Wolf Creek the successful phishing gave access to the corporate business network, which the group then used to push deeper into the victim's systems.",
      "lessons": "Role-targeted phishing against engineers demands hardware-backed MFA and strict separation between corporate email environments and any network adjacent to operational technology.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide",
          "url": "https://www.justice.gov/archives/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical",
          "publisher": "U.S. Department of Justice"
        },
        {
          "title": "Indictment related to Wolf Creek computer hack unsealed",
          "url": "https://www.ans.org/news/article-3818/indictment-related-to-wolf-creek-computer-hack-unsealed/",
          "publisher": "American Nuclear Society"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2017-russian-fsb-officers-spear-phished-wolf-creek-nuclear-plant-in-global-en"
    },
    {
      "slug": "2016-gru-spear-phished-election-vendor-vr-systems-then-122-local-election-off",
      "title": "GRU spear-phished election vendor VR Systems, then 122 local election officials",
      "date": "2016-11",
      "date_precision": "month",
      "year": 2016,
      "victim_org": "VR Systems and US local election administrators",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": "Russian GRU military intelligence",
      "summary": "A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.",
      "how_it_worked": "The first stage was a credential phishing portal: emails that looked like Google security notices pointed VR Systems staff at a counterfeit Google sign-in page where they typed their passwords. The second stage weaponised the resulting familiarity. The operators registered a Gmail address in the name of a real VR Systems employee and mailed 122 local election administrators, who knew VR Systems as their voter-registration software vendor, attaching trojanised Word documents that ran PowerShell to fetch further malware. The trust signal was the vendor relationship itself, and the timing, days before the election, supplied the urgency that made recipients open attachments.",
      "lessons": "Phishing-resistant MFA on vendor accounts and out-of-band confirmation of unexpected vendor attachments would have broken both stages of the chain.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Top-Secret NSA Report Details Russian Hacking Effort Days Before 2016 Election",
          "url": "https://theintercept.com/2017/06/05/top-secret-nsa-report-details-russian-hacking-effort-days-before-2016-election/",
          "publisher": "The Intercept"
        },
        {
          "title": "Report: Russia Launched Cyberattack On Voting Vendor Ahead Of Election",
          "url": "https://www.npr.org/2017/06/05/531649602/report-russia-launched-cyberattack-on-voting-vendor-ahead-of-election",
          "publisher": "NPR"
        }
      ],
      "entry_type": "campaign",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spear-phished-election-vendor-vr-systems-then-122-local-election-off"
    },
    {
      "title": "Leoni AG Romanian subsidiary wires €40 million to fraudsters",
      "date": "2016-08",
      "date_precision": "month",
      "victim_org": "Leoni AG (Bistrița, Romania subsidiary)",
      "sector": "Manufacturing",
      "country": "Romania",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 44000000,
      "loss_note": "About €40 million (roughly $44 million) transferred to an account in the Czech Republic. Recovery not confirmed.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.",
      "how_it_worked": "The attackers researched Leoni's internal payment culture before striking, and reporting indicated they knew that German group executives had previously requested transfers by email. They created lookalike sender identities for those executives and directed instructions to the Romanian subsidiary's finance director, who was accustomed to acting on such requests. The messages mimicked the format, tone and approval language of genuine intra-group transfers and were supported by falsified documents. Because the request pattern matched prior legitimate behavior, the finance director executed the wire to a Czech account without a callback to Germany, and the funds were dispersed before the group detected the loss.",
      "lessons": "Intra-group cash movements need a codified verification protocol, ideally a signed treasury workflow rather than email, so that familiarity with past email requests cannot be weaponized.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Hackers steal EUR 40 mln from German group Leoni's subsidiary in Romania",
          "url": "https://www.romania-insider.com/hackers-steal-eur-40-mln-german-group-leoni-subsidiary-romania",
          "publisher": "Romania Insider"
        },
        {
          "title": "German wire supplier Leoni loses EUR 40m in email impersonation scam",
          "url": "https://www.bitdefender.com/en-us/blog/businessinsights/leoni-fraud-email-impersonation-scam",
          "publisher": "Bitdefender Business Insights"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters",
      "year": 2016,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters"
    },
    {
      "slug": "2016-milwaukee-bucks-employee-sends-players-and-staff-w-2s-to-an-impersonator",
      "title": "Milwaukee Bucks employee sends players' and staff W-2s to an impersonator",
      "date": "2016-04-26",
      "date_precision": "day",
      "year": 2016,
      "victim_org": "Milwaukee Bucks (NBA)",
      "sector": "Media & Entertainment",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": null,
      "threat_actor": null,
      "summary": "The NBA's Milwaukee Bucks disclosed in May 2016 that an employee had emailed 2015 W-2 tax documents for players and staff to an unknown party in response to a message impersonating the team's president. The documents included names, addresses, Social Security numbers and compensation figures. The team offered three years of credit monitoring to those affected.",
      "how_it_worked": "On 26 April 2016 an email arrived that appeared to be from the Bucks' president requesting the organisation's W-2 forms. A staff member sent them. The pretext was the standard W-2 season request, and the impersonated identity was the single most senior person in the organisation, which suppresses the instinct to verify. A professional sports team is an unusually attractive target for this scheme because the compensation figures in the files are large and publicly interesting, and because players' Social Security numbers carry high resale value. Discovery came only after the request was later questioned internally.",
      "lessons": "A named-executive request for the entire workforce's tax records should trigger a mandatory verification call, and payroll data should be exchanged only through controlled systems.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Milwaukee Bucks' tax information released by employee who fell for email scam",
          "url": "https://www.washingtonpost.com/news/early-lead/wp/2016/05/19/milwaukee-bucks-tax-information-released-by-employee-who-fell-for-email-scam/",
          "publisher": "The Washington Post"
        },
        {
          "title": "Bucks leak tax info of players, employees as result of email scam",
          "url": "https://www.espn.com/nba/story/_/id/15615363/milwaukee-bucks-leak-tax-information-players-employees-result-email-scam",
          "publisher": "ESPN"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-milwaukee-bucks-employee-sends-players-and-staff-w-2s-to-an-impersonator"
    },
    {
      "title": "John Podesta and DNC staff phished by fake Google security alerts in 2016",
      "date": "2016-03-19",
      "date_precision": "day",
      "victim_org": "Hillary for America campaign and the Democratic National Committee",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Espionage",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No direct monetary loss reported; harm was reputational and political.",
      "records_affected": null,
      "threat_actor": "Fancy Bear / APT28, identified in the July 2018 US indictment as GRU Unit 26165",
      "summary": "On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.",
      "how_it_worked": "The message imitated Google's 'Someone has your password' notification and carried a Bitly link masking an attacker-controlled domain that rendered a pixel-perfect Google account login page. A campaign IT aide replied that the mail was legitimate, later saying he had meant to write 'illegitimate,' and the link was clicked and the password entered. With mailbox access the operators archived the account's contents. The same infrastructure was used across hundreds of targets; because Bitly statistics were public, researchers were later able to reconstruct the target list and confirm the operator's identity.",
      "lessons": "Hardware security keys on campaign and executive Google accounts make a harvested password worthless, and a defined out-of-band process for verifying security alerts avoids relying on a hurried email reply.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Is this the email that hacked John Podesta's account?",
          "url": "https://www.cnn.com/2016/10/28/politics/phishing-email-hack-john-podesta-hillary-clinton-wikileaks/index.html",
          "publisher": "CNN"
        },
        {
          "title": "How hackers broke into John Podesta, DNC Gmail accounts",
          "url": "https://news.sophos.com/en-us/2016/10/25/how-hackers-broke-into-john-podesta-dnc-gmail-accounts/",
          "publisher": "Sophos Naked Security"
        },
        {
          "title": "How John Podesta's Emails Were Hacked And How To Prevent It From Happening To You",
          "url": "https://www.forbes.com/sites/kevinmurnane/2016/10/21/how-john-podestas-emails-were-hacked-and-how-to-prevent-it-from-happening-to-you/",
          "publisher": "Forbes"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201",
      "year": 2016,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201"
    },
    {
      "title": "Seagate CEO-impersonation phish exposes every US employee's W-2",
      "date": "2016-03-01",
      "date_precision": "day",
      "victim_org": "Seagate Technology",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "No direct wire loss; downstream harm was tax refund fraud exposure for employees.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.",
      "how_it_worked": "The attacker spoofed the display name and writing style of a senior executive and emailed payroll or HR staff during tax season with a short, direct request for the complete W-2 file. Two levers combined: the authority of a named chief executive and the seasonal normality of the request, since W-2 handling is exactly what payroll does in early March. The employee attached the full file and replied. Because W-2s pair Social Security numbers with income and address data, the single reply produced everything needed to file fraudulent tax refunds in each employee's name.",
      "lessons": "Bulk employee tax or PII files should never be releasable by email reply; a workflow requiring release through an authenticated HR system with a second approver would have blocked it.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Seagate Phish Exposes All Employee W-2's",
          "url": "https://krebsonsecurity.com/2016/03/seagate-phish-exposes-all-employee-w-2s/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "Snapchat and Seagate fall prey to new W-2 scam",
          "url": "https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/",
          "publisher": "CBS News"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2",
      "year": 2016,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-seagate-ceo-impersonation-phish-exposes-every-us-employee-s-w-2"
    },
    {
      "slug": "2016-sprouts-farmers-market-payroll-employee-emails-21-000-staff-w-2s-to-a-sc",
      "title": "Sprouts Farmers Market payroll employee emails 21,000 staff W-2s to a scammer",
      "date": "2016-03",
      "date_precision": "month",
      "year": 2016,
      "victim_org": "Sprouts Farmers Market",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 21000,
      "threat_actor": null,
      "summary": "In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.",
      "how_it_worked": "The attacker sent a short, plain email to a payroll staff member that appeared to come from a Sprouts executive and asked for all employee W-2 forms. The pretext matched the calendar: late March is the height of US tax season, when internal requests for wage data are entirely routine, so the ask raised no category alarm. The message used seniority as the trust signal and gave no reason for the request, which in a large organisation reads as normal executive brevity rather than suspicious. The employee replied with the file, handing over a complete identity-theft package for the workforce.",
      "lessons": "Bulk employee tax or payroll data should only leave through a ticketed request in an HR system, never as an email attachment, regardless of who appears to be asking.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Employers Beware of Phishing Scams",
          "url": "https://www.natlawreview.com/article/employers-beware-phishing-scams",
          "publisher": "The National Law Review"
        },
        {
          "title": "Sprouts Farmers Market Class Actions Target W-2 Phishing Scam",
          "url": "https://topclassactions.com/lawsuit-settlements/lawsuit-news/sprouts-farmers-market-class-actions-target-w-2-phishing-scam/",
          "publisher": "Top Class Actions"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-sprouts-farmers-market-payroll-employee-emails-21-000-staff-w-2s-to-a-sc"
    },
    {
      "title": "Snapchat payroll staff phished by fake CEO request for employee W-2s",
      "date": "2016-02-28",
      "date_precision": "day",
      "victim_org": "Snapchat, Inc.",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "No wire loss reported; exposure was employee payroll and identity data.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.",
      "how_it_worked": "The message was a classic CEO-fraud W-2 lure: a spoofed executive sender, minimal detail, an implied deadline, and a request that fell squarely inside the recipient's normal duties during US tax season. The lever was hierarchical authority combined with the reluctance of a junior payroll employee to question a terse instruction that appears to come from the founder. The extracted action was a single email attachment containing employees' names, addresses, Social Security numbers and wage data, which criminals use to file fraudulent federal tax returns and claim refunds before the real employee files.",
      "lessons": "Enforce a standing rule that no bulk tax or identity data leaves the organisation by email, backed by outbound DLP inspection for W-2 patterns and mandatory verbal verification of executive data requests.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Snapchat and Seagate fall prey to new W-2 scam",
          "url": "https://www.cbsnews.com/news/snapchat-and-seagate-fall-prey-to-new-w-2-scam/",
          "publisher": "CBS News"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-snapchat-payroll-staff-phished-by-fake-ceo-request-for-employee-w-2s",
      "year": 2016,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-snapchat-payroll-staff-phished-by-fake-ceo-request-for-employee-w-2s"
    },
    {
      "title": "Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails",
      "date": "2016-02",
      "date_precision": "month",
      "victim_org": "Bangladesh Bank (central bank of Bangladesh)",
      "sector": "Financial Services",
      "country": "Bangladesh",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Fake Job Offer / Recruitment Lure"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss",
        "Service Disruption"
      ],
      "loss_usd": 81000000,
      "loss_note": "$101 million in fraudulent SWIFT transfers were executed, of which $81 million reached accounts in the Philippines and about $20 million sent to Sri Lanka was blocked; a portion of the Philippine funds was later recovered, leaving roughly $65 million outstanding.",
      "records_affected": null,
      "threat_actor": "Lazarus Group (North Korea); US DOJ charged Park Jin Hyok in 2018",
      "summary": "In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.",
      "how_it_worked": "Emails from a fabricated job-seeker persona were sent to Bangladesh Bank employees with a link to a résumé hosted externally; retrieving it delivered malware that established remote access. The attackers dwelled for about a year, mapping the bank's network and the workstation used for SWIFT Alliance Access. They then deployed custom malware that manipulated the SWIFT client's database and print output so fraudulent messages would not appear on the confirmation printer, issued transfer instructions to the New York Fed over a weekend, and routed proceeds through Philippine bank accounts and casino junkets to launder them.",
      "lessons": "Isolating the SWIFT terminal on its own segment with application allow-listing, and independent reconciliation of outbound payment messages, would have caught both the intrusion path and the tampered confirmations.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Hackers took years before stealing $81m from Bangladesh Bank: FBI",
          "url": "https://www.newagebd.net/print/article/141463",
          "publisher": "New Age Bangladesh"
        },
        {
          "title": "When North Korean hackers almost pulled off a billion-dollar heist from Bangladesh Bank",
          "url": "https://www.thedailystar.net/tech-startup/news/when-north-korean-hackers-almost-pulled-billion-dollar-heist-bangladesh-bank-2115317",
          "publisher": "The Daily Star"
        },
        {
          "title": "Lessons Learned From the Bangladesh Bank Heist",
          "url": "https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/lessons-learned-from-the-bangladesh-bank-heist",
          "publisher": "ISACA Journal"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin",
      "year": 2016,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin"
    },
    {
      "title": "Austrian aerospace supplier FACC loses about €50 million to CEO fraud",
      "date": "2016-01",
      "date_precision": "month",
      "victim_org": "FACC AG",
      "sector": "Manufacturing",
      "country": "Austria",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported; the impersonation was email-based, not a voice clone.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 54000000,
      "loss_note": "FACC reported damage of approximately €50 million (roughly US$54 million at the time); USD figures in press reports range from about $47 million to $56 million depending on exchange rate and date.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.",
      "how_it_worked": "Fraudsters sent email instructions that appeared to come from FACC's chief executive, framed around a confidential acquisition and directing finance staff to wire funds to foreign accounts. The framing discouraged the recipients from consulting colleagues, and the payments were released without independent confirmation. Part of the money was frozen in transit; the remainder was dispersed abroad. Austrian police later arrested an alleged accomplice tied to receiving accounts in Hong Kong. No malware or network intrusion was involved, which is why FACC described it as damage from a criminal act rather than a technical breach.",
      "lessons": "A mandatory callback to a directory-listed number for any payment framed as confidential or urgent, plus dual sign-off on international transfers, defeats CEO fraud outright.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Austrian Firm Fires CEO After $56-million Cyber Scam",
          "url": "https://www.securityweek.com/austrian-firm-fires-ceo-after-56-million-cyber-scam/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "Aerospace firm loses $47 million in cyber fraud, fires CEO",
          "url": "https://www.bitdefender.com/en-us/blog/businessinsights/cyber-fraud-ceo-fired",
          "publisher": "Bitdefender Business Insights"
        },
        {
          "title": "Cops nab accomplice in Austrian €50m caper",
          "url": "https://www.thelocal.at/20160828/cops-nab-accomplice-in-austrian-50m-caper-facc-hong-kong/",
          "publisher": "The Local Austria"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-austrian-aerospace-supplier-facc-loses-about-50-million-to-ceo-fraud",
      "year": 2016,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-austrian-aerospace-supplier-facc-loses-about-50-million-to-ceo-fraud"
    },
    {
      "title": "Belgian bank Crelan loses €70 million to CEO-fraud payment orders",
      "date": "2016-01",
      "date_precision": "month",
      "victim_org": "Crelan NV/SA",
      "sector": "Financial Services",
      "country": "Belgium",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 75800000,
      "loss_note": "€70 million (about $75.8 million). The bank said reserves absorbed the loss and customers were not affected.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.",
      "how_it_worked": "The scheme attacked a bank's own treasury payment process rather than customer accounts. Fraudsters used a compromised or spoofed executive mailbox to issue payment instructions to finance staff, relying on the authority of the sender and on urgency and confidentiality to suppress questions. Because the orders came through the expected internal channel and carried apparently legitimate executive approval, they were processed without out-of-band confirmation. The diversion went undetected until routine internal audit work flagged irregularities, at which point the funds had already left the institution. Crelan reported the matter to prosecutors and reviewed its internal control framework.",
      "lessons": "Internal payment instructions deserve the same scrutiny as external ones: even executive-originated transfers should require verification through a separate channel and a segregation-of-duties check before release.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Belgian bank Crelan loses €70 million to BEC scammers",
          "url": "https://www.helpnetsecurity.com/2016/01/26/belgian-bank-crelan-loses-e70-million-to-bec-scammers/",
          "publisher": "Help Net Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-belgian-bank-crelan-loses-70-million-to-ceo-fraud-payment-orders",
      "year": 2016,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-belgian-bank-crelan-loses-70-million-to-ceo-fraud-payment-orders"
    },
    {
      "title": "GRU spearphishing of the Clinton campaign, DNC and DCCC",
      "date": "2016",
      "date_precision": "year",
      "victim_org": "Hillary Clinton presidential campaign, Democratic National Committee and Democratic Congressional Campaign Committee",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported in the indictment.",
      "outcomes": [
        "Espionage",
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No monetary loss; the outcome was mass exfiltration and staged public release of emails and documents.",
      "records_affected": null,
      "threat_actor": "Russian GRU Units 26165 and 74455 (twelve officers indicted)",
      "summary": "A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.",
      "how_it_worked": "The unit sent targeted emails to campaign staff and party employees that harvested account usernames and passwords. Compromised mailboxes yielded further contact lists and internal context that made subsequent lures more credible, letting the operation spread laterally from volunteers to senior staff. Stolen credentials were then used to access other computers on the committees' networks, where the officers monitored employee activity and installed malware for persistent collection. The exfiltrated correspondence was subsequently staged and released publicly to maximise political effect during the campaign.",
      "lessons": "Hardware security keys for all campaign and party staff, which several campaigns adopted afterwards, defeat credential-harvesting pages regardless of how convincing the lure is.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Grand Jury Indicts 12 Russian Intelligence Officers for Hacking Offenses Related to the 2016 Election",
          "url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-election",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "incident",
      "slug": "2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc",
      "year": 2016,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc"
    },
    {
      "title": "Ukraine power grid blackout of 2015 began with BlackEnergy spear phishing",
      "date": "2015-12-23",
      "date_precision": "day",
      "victim_org": "Kyivoblenergo, Prykarpattyaoblenergo and Chernivtsioblenergo",
      "sector": "Energy & Utilities",
      "country": "Ukraine",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Service Disruption",
        "Espionage",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No monetary loss figure published; impact measured in customer-hours of lost electricity supply.",
      "records_affected": null,
      "threat_actor": "Sandworm (Russian GRU-linked)",
      "summary": "On 23 December 2015 three Ukrainian regional electricity distribution companies were hit by a coordinated cyberattack that opened breakers at roughly 30 substations and left about 225,000 customers without power. The joint E-ISAC/SANS analysis found the intrusion began months earlier with spear phishing emails carrying malicious Office documents that installed BlackEnergy 3, which was used to harvest credentials for the operators' VPN and SCADA environments.",
      "how_it_worked": "Staff at the distribution companies received emails with Word and Excel attachments; opening them produced a prompt to enable macros, which installed BlackEnergy 3. The attackers spent months conducting reconnaissance, stealing Windows domain credentials and mapping the SCADA environment, then used legitimate remote access to the operators' control systems to open circuit breakers by hand. They followed up by uploading malicious firmware to serial-to-Ethernet converters, wiping workstations with KillDisk, and flooding customer call centres with a telephony denial of service so outages were harder to report and restore.",
      "lessons": "Macro execution should be blocked by policy for ordinary users, and remote access into an ICS environment should be MFA-protected and separated from the corporate domain whose credentials phishing yields.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Analysis of the Cyber Attack on the Ukrainian Power Grid",
          "url": "https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2016/05/20081514/E-ISAC_SANS_Ukraine_DUC_5.pdf",
          "publisher": "E-ISAC and SANS ICS"
        },
        {
          "title": "Analysis of the Cyber Attack on the Ukrainian Power Grid (archived copy)",
          "url": "https://nsarchive.gwu.edu/sites/default/files/documents/3891751/SANS-and-Electricity-Information-Sharing-and.pdf",
          "publisher": "National Security Archive"
        },
        {
          "title": "Power grid cyberattack in Ukraine (2015)",
          "url": "https://cyberlaw.ccdcoe.org/wiki/Power_grid_cyberattack_in_Ukraine_(2015)",
          "publisher": "NATO CCDCOE Cyber Law Toolkit"
        }
      ],
      "entry_type": "incident",
      "slug": "2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin",
      "year": 2015,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin"
    },
    {
      "title": "IRS 'Get Transcript' abused to pull 334,000 taxpayer transcripts",
      "date": "2015-08-17",
      "date_precision": "day",
      "victim_org": "US taxpayers via the Internal Revenue Service (multi-victim campaign)",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement; attackers answered static knowledge-based questions.",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "The IRS did not publish a fraudulent-refund total tied specifically to this incident in the August 2015 disclosure.",
      "records_affected": 334000,
      "threat_actor": null,
      "summary": "In August 2015 the IRS disclosed that criminals had successfully retrieved prior-year tax transcripts for roughly 334,000 taxpayers through its online Get Transcript service, having attempted access against about 610,000 taxpayers. The Treasury Inspector General later put the potentially compromised total higher. Attackers defeated the service's knowledge-based authentication rather than breaching IRS systems.",
      "how_it_worked": "Get Transcript authenticated the requester with a name, date of birth, Social Security number and filing status, followed by four multiple-choice knowledge-based questions supplied by a credit bureau about matters such as previous addresses and loan amounts. Criminals already holding identity data from earlier breaches supplied the first tier and then guessed or looked up the multiple-choice answers, which were drawn from commercially available credit-header data. Success rates exceeded half of attempts. A retrieved transcript contains the prior year's income and withholding detail, which is exactly what is needed to file a convincing fraudulent refund claim.",
      "lessons": "Static knowledge-based authentication should not gate access to sensitive government records once bulk consumer data is in criminal hands; identity proofing needs a possession or biometric factor.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "IRS: 330K Taxpayers Hit by 'Get Transcript' Scam",
          "url": "https://krebsonsecurity.com/2015/08/irs-330k-taxpayers-hit-by-get-transcript-scam/",
          "publisher": "Krebs on Security"
        }
      ],
      "entry_type": "campaign",
      "slug": "2015-irs-get-transcript-abused-to-pull-334-000-taxpayer-transcripts",
      "year": 2015,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2015-irs-get-transcript-abused-to-pull-334-000-taxpayer-transcripts"
    },
    {
      "title": "Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise",
      "date": "2015-06-05",
      "date_precision": "day",
      "victim_org": "Ubiquiti Networks",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Spear Phishing (Email)",
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported; impersonation was text-based email spoofing.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 46700000,
      "loss_note": "Ubiquiti disclosed $46.7 million transferred; $8.1 million was recovered at the time of disclosure and the company said additional sums were subject to legal injunction and expected to be recovered.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.",
      "how_it_worked": "Fraudsters used spoofed email addresses and forged requests that appeared to come from senior Ubiquiti executives and from an external business counterparty, instructing the finance team of the company's Hong Kong subsidiary to make a series of international transfers. There was no malware or network compromise; the deception rode entirely on the apparent authority of the sender and on a payments process that accepted email as sufficient authorisation. The fraud was discovered only after the transfers had been made, and Ubiquiti moved to recover funds through legal injunctions in the receiving jurisdictions.",
      "lessons": "Out-of-band verification by known phone number for any payment instruction above a threshold, and dual authorisation for changes to beneficiary details, would have caught the fraudulent requests before the wires left.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Tech Firm Ubiquiti Suffers $46M Cyberheist",
          "url": "https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "Networking Manufacturer Ubiquiti Lost $46.7M after Falling for Elaborate Impersonation Scam",
          "url": "https://www.nextgov.com/cybersecurity/2015/08/breach/143746/",
          "publisher": "Nextgov/FCW"
        },
        {
          "title": "Ubiquiti Networks says it was victim of $47 million cyber scam",
          "url": "https://www.nbcnews.com/tech/security/ubiquiti-networks-says-it-was-victim-47-million-cyber-scam-n406201",
          "publisher": "NBC News"
        },
        {
          "title": "Ubiquiti Networks Form 8-K, August 2015",
          "url": "https://www.sec.gov/Archives/edgar/data/1511737/000157104915006288/t1501817_8k.htm",
          "publisher": "U.S. Securities and Exchange Commission (EDGAR)"
        }
      ],
      "entry_type": "incident",
      "slug": "2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email",
      "year": 2015,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email"
    },
    {
      "title": "Mattel wires $3 million to Chinese account in CEO impersonation scam, recovers it",
      "date": "2015-04-30",
      "date_precision": "day",
      "victim_org": "Mattel, Inc.",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 3000000,
      "loss_note": "$3 million transferred and subsequently recovered in full after Chinese authorities froze the receiving account.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "On April 30, 2015 a Mattel finance executive wired $3 million to a bank in Wenzhou, China after receiving an email purporting to come from newly appointed chief executive Christopher Sinclair. The fraud was recognized the same day. Because May 1 was a banking holiday in China, Mattel was able to work with U.S. and Chinese law enforcement and the receiving bank to freeze the account, and the funds were returned within days.",
      "how_it_worked": "The attackers studied Mattel's payment approval rule, which required sign-off from two senior managers, and timed their approach to a leadership transition when a new CEO's email habits were unfamiliar. They sent a spoofed request from the incoming chief executive asking for a vendor payment to a new supplier in China, framed as routine business expansion. The finance executive believed the request satisfied the two-approver rule because the CEO himself appeared to be one of the approvers. Only afterward, when she mentioned it to Sinclair, was the fraud exposed. A Chinese public holiday delayed onward movement of the money long enough for law enforcement to freeze it.",
      "lessons": "Approval rules must count only independently verified approvers; a request that supplies its own authorization by email is not dual control, and new-vendor payments deserve a mandatory verification step.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Chinese scammers take Mattel to the bank, phishing them for $3 million",
          "url": "https://www.csoonline.com/article/555513/chinese-scammers-take-mattel-to-the-bank-phishing-them-for-3-million.html",
          "publisher": "CSO Online"
        }
      ],
      "entry_type": "incident",
      "slug": "2015-mattel-wires-3-million-to-chinese-account-in-ceo-impersonation-scam-reco",
      "year": 2015,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2015-mattel-wires-3-million-to-chinese-account-in-ceo-impersonation-scam-reco"
    },
    {
      "title": "Ryanair loses nearly $5 million from fuel account via fraudulent transfer",
      "date": "2015-04",
      "date_precision": "month",
      "victim_org": "Ryanair Holdings plc",
      "sector": "Transportation & Logistics",
      "country": "Ireland",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 5000000,
      "loss_note": "About €4.6 million (just under $5 million) transferred out of an aircraft fuel account via a Chinese bank; Ryanair said the funds were frozen and it expected repayment.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.",
      "how_it_worked": "The fraud targeted a single-purpose corporate account used for high-value, recurring commodity purchases, where large outbound payments are normal and unlikely to stand out. An unauthorized electronic transfer instruction moved nearly €4.6 million out of the fuel account and into the banking system via a Chinese institution, a common laundering corridor for payment-diversion fraud in that period. Ryanair identified the loss quickly enough for Irish authorities and their Asian counterparts to reach the receiving bank and freeze the balance. The airline declined to describe the precise attack vector, citing legal proceedings, and said corrective measures had been put in place.",
      "lessons": "High-value commodity payment accounts need transaction-level anomaly alerting and a dedicated approval path, so that a single unexpected instruction cannot drain them before anyone reviews it.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Ryanair Loses $5m in Bank Hack",
          "url": "https://www.infosecurity-magazine.com/news/ryanair-loses-5-million-in-bank/",
          "publisher": "Infosecurity Magazine"
        }
      ],
      "entry_type": "incident",
      "slug": "2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer",
      "year": 2015,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer"
    },
    {
      "title": "Anthem breach of 78.8 million records started with a spear phishing email",
      "date": "2015-02-04",
      "date_precision": "day",
      "victim_org": "Anthem Inc.",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Espionage",
        "Identity Theft"
      ],
      "loss_usd": 115000000,
      "loss_note": "Anthem agreed to a $115 million class-action settlement in 2017 and a $16 million HIPAA settlement with HHS OCR in 2018, plus a multistate settlement of about $39.5 million in 2020; the figure given is the class-action settlement only.",
      "records_affected": 78800000,
      "threat_actor": "China-linked espionage group (reported as Deep Panda / Black Vine; US DOJ later indicted Fujie Wang and others)",
      "summary": "Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.",
      "how_it_worked": "A targeted email delivered to at least one subsidiary employee installed a backdoor on the workstation. The attackers used that access to move laterally, harvest credentials and eventually obtain the credentials of database administrators, allowing them to query Anthem's data warehouse directly. Data was staged and exfiltrated over months to external infrastructure, including domains that typosquatted the company's former name. The activity was noticed only when an administrator saw a database query running under his own account that he had not issued.",
      "lessons": "Privileged database accounts should require phishing-resistant MFA and behavioural monitoring, and bulk queries against member data warehouses should alert regardless of which account issues them.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Commissioner Jones Announces Examination Findings of Anthem Cyber Attack",
          "url": "https://www.insurance.ca.gov/0400-news/0100-press-releases/anthemcyberattack.cfm",
          "publisher": "California Department of Insurance"
        },
        {
          "title": "Anthem Data Breach: What Happened, Impact, and Lessons",
          "url": "https://www.huntress.com/threat-library/data-breach/anthem-data-breach",
          "publisher": "Huntress"
        },
        {
          "title": "The Anthem Hack: All Roads Lead to China",
          "url": "https://threatconnect.com/blog/the-anthem-hack-all-roads-lead-to-china/",
          "publisher": "ThreatConnect"
        }
      ],
      "entry_type": "incident",
      "slug": "2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai",
      "year": 2015,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai"
    },
    {
      "title": "Xoom Corporation loses $30.8 million to employee impersonation fraud",
      "date": "2014-12-30",
      "date_precision": "day",
      "victim_org": "Xoom Corporation",
      "sector": "Financial Services",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 30800000,
      "loss_note": "$30.8 million of corporate cash transferred to overseas accounts. The company said no customer data or customer funds were involved.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.",
      "how_it_worked": "The attackers directed impersonated internal requests at Xoom's finance department, the function authorized to move corporate treasury cash. Posing as company personnel, they issued transfer instructions that fit the company's own internal request format, so the payments were processed as legitimate corporate disbursements rather than customer transactions. The money went to accounts abroad and was not recovered. Xoom emphasized that its systems were not breached and no customer funds or data were touched, underscoring that the failure was in the human approval chain for corporate wires. The board's response included an independent investigation, a review of internal controls, and the immediate departure of the CFO.",
      "lessons": "Corporate treasury disbursement requests should be authenticated in a workflow system with enforced separation of duties, never accepted as an emailed instruction that appears to come from a colleague.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Xoom Corporation Form 8-K (filed January 5, 2015)",
          "url": "https://www.sec.gov/Archives/edgar/data/1315657/000110465915000360/a15-1144_18k.htm",
          "publisher": "U.S. Securities and Exchange Commission (EDGAR)"
        }
      ],
      "entry_type": "incident",
      "slug": "2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud",
      "year": 2014,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud"
    },
    {
      "title": "Sony Pictures destructive hack preceded by fake Apple ID phishing emails",
      "date": "2014-11-24",
      "date_precision": "day",
      "victim_org": "Sony Pictures Entertainment",
      "sector": "Media & Entertainment",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Service Disruption",
        "Extortion",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_note": "Sony disclosed investigation and remediation costs in the tens of millions of dollars; a settlement of up to about $8 million with former employees was also reported. No single authoritative total is asserted here.",
      "records_affected": null,
      "threat_actor": "Guardians of Peace; attributed by the FBI to North Korea (Lazarus Group)",
      "summary": "On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.",
      "how_it_worked": "In September and October 2014 messages purporting to come from Apple warned recipients of unauthorised activity on their Apple ID and pointed to a lookalike verification page. Because many staff reused passwords between personal Apple accounts and Sony systems, harvested credentials could be replayed against corporate services. The intruders spent weeks inside the network collecting mail archives, unreleased films, salary and personnel files, then executed wiper malware that overwrote master boot records and disk volumes, disabling thousands of machines while the stolen data was published in stages.",
      "lessons": "Blocking password reuse between personal and corporate accounts, plus MFA on remote access, removes the value of a harvested consumer credential.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Sony hackers targeted employees with fake Apple ID emails",
          "url": "https://www.computerworld.com/article/1364510/sony-hackers-targeted-employees-with-fake-apple-id-emails.html",
          "publisher": "Computerworld"
        },
        {
          "title": "Sony Hackers Used Apple ID Phishing Scheme, Researchers Claim at RSA",
          "url": "https://www.eweek.com/security/sony-hackers-used-apple-id-phishing-scheme-researchers-claim-at-rsa/",
          "publisher": "eWeek"
        },
        {
          "title": "Sony Hackers Used Phishing Emails to Breach Company Networks",
          "url": "https://www.tripwire.com/state-of-security/sony-hackers-used-phishing-emails-to-breach-company-networks",
          "publisher": "Tripwire State of Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2014-sony-pictures-destructive-hack-preceded-by-fake-apple-id-phishing-emails",
      "year": 2014,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2014-sony-pictures-destructive-hack-preceded-by-fake-apple-id-phishing-emails"
    },
    {
      "title": "Celebrity iCloud photo theft: 600 victims phished with fake Apple and Google emails",
      "date": "2014-09",
      "date_precision": "month",
      "victim_org": "Celebrities and private individuals with Apple iCloud and Google accounts",
      "sector": "Consumer",
      "country": "United States",
      "primary_vector": "Credential Phishing Portal",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "No monetary loss figure was published; harm was the public leak of private photographs.",
      "records_affected": 600,
      "threat_actor": "Ryan Collins (convicted)",
      "summary": "The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.",
      "how_it_worked": "Collins sent messages that mimicked Apple and Google account security notices, using the vendors' visual conventions and a plausible security pretext to make responding feel like protecting the account rather than surrendering it. Victims replied with, or entered, their account usernames and passwords. Collins then signed in directly and downloaded the full contents of iCloud backups, which on Apple devices at that time included the entire camera roll and message history. No platform vulnerability was exploited; the whole compromise rested on the victim voluntarily supplying credentials to a convincing imitation of the provider.",
      "lessons": "Mandatory two-factor authentication on consumer cloud backup accounts, and provider policies that never request passwords by email, would have neutralised the harvested credentials.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Pennsylvania Man Sentenced to 18 Months in Federal Prison for Hacking Apple and Google E-Mail Accounts",
          "url": "https://www.justice.gov/usao-cdca/pr/pennsylvania-man-sentenced-today-18-months-federal-prison-hacking-apple-and-google-e",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "incident",
      "slug": "2014-celebrity-icloud-photo-theft-600-victims-phished-with-fake-apple-and-goo",
      "year": 2014,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2014-celebrity-icloud-photo-theft-600-victims-phished-with-fake-apple-and-goo"
    },
    {
      "title": "Scoular Company wires $17.2 million after fake CEO and auditor emails",
      "date": "2014-06",
      "date_precision": "month",
      "victim_org": "The Scoular Company",
      "sector": "Other",
      "country": "United States",
      "primary_vector": "Business Email Compromise",
      "secondary_vectors": [
        "Vendor / Supply Chain Impersonation"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media reported.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 17200000,
      "loss_note": "$17.2 million sent in three transfers of about $780,000, $7 million and $9.4 million to a bank in China.",
      "records_affected": null,
      "threat_actor": null,
      "summary": "In June 2014 the corporate controller of Omaha-based commodities trading firm The Scoular Company wired $17.2 million to a Chinese bank in three installments after receiving emails impersonating chief executive Chuck Elsea and the company's outside auditor at KPMG. The messages described a confidential international acquisition and demanded secrecy. The emails were sent from accounts associated with Germany, France and Israel using servers in Moscow.",
      "how_it_worked": "The fraudsters built a two-sided pretext so that the controller's natural verification instinct was satisfied inside the scam itself. Emails from the apparent CEO announced a blockbuster confidential acquisition in China and instructed him to coordinate with a named KPMG contact; emails from that fake auditor then corroborated the deal and supplied wiring details. Secrecy was explicitly demanded because of supposed securities sensitivity, which discouraged any check with colleagues. The story was plausible because Scoular genuinely had expansion discussions involving China. Three escalating transfers cleared over several days before the deception surfaced, by which point the funds were beyond reach.",
      "lessons": "External confirmation must originate from the victim, not the requester: calling KPMG's published main number or the CEO's office, rather than the contact details supplied in the email, would have ended the scheme immediately.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "55th Largest Private Company In America Sent Millions To China Because An Email Told Them To",
          "url": "https://www.techdirt.com/2015/02/06/55th-largest-private-company-america-sent-millions-to-china-because-email-told-them-to/",
          "publisher": "Techdirt"
        }
      ],
      "entry_type": "incident",
      "slug": "2014-scoular-company-wires-17-2-million-after-fake-ceo-and-auditor-emails",
      "year": 2014,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2014-scoular-company-wires-17-2-million-after-fake-ceo-and-auditor-emails"
    },
    {
      "slug": "2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million",
      "title": "Premera Blue Cross breach began with a spear-phishing email, 10.4 million affected",
      "date": "2014-05",
      "date_precision": "month",
      "year": 2014,
      "victim_org": "Premera Blue Cross",
      "sector": "Healthcare",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Espionage"
      ],
      "loss_usd": 6850000,
      "loss_kind": "business_impact",
      "loss_note": "US$6.85 million HIPAA penalty imposed by HHS Office for Civil Rights in 2020; separate class-action and multistate settlements followed.",
      "records_affected": 10400000,
      "threat_actor": null,
      "summary": "Attackers compromised Premera Blue Cross in May 2014 and remained undetected for about nine months until January 2015. The intrusion exposed the protected health information of roughly 10.4 million individuals, including names, dates of birth, Social Security numbers, bank account details and clinical information. The HHS Office for Civil Rights, describing the incident, stated that the entry point was a spear-phishing email that installed malware.",
      "how_it_worked": "The intrusion started with a spear-phishing email sent to Premera staff which, when acted on, installed malware and gave the attackers an interactive foothold inside the health plan's network. From there they operated quietly for nine months, moving through systems that held member enrolment, claims and clinical data. The regulator's later findings emphasised that Premera had not run an adequate enterprise-wide risk analysis and lacked the monitoring that would have surfaced anomalous internal activity, which is why a single successful email turned into nine months of undetected access across a database of more than ten million members.",
      "lessons": "Email filtering and user reporting only reduce the odds; the decisive control here was internal detection, since the damage came from nine months of unnoticed lateral movement.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "OCR Imposes 2nd Largest Ever HIPAA Penalty of $6.85 Million on Premera Blue Cross",
          "url": "https://www.hipaajournal.com/ocr-imposes-2nd-largest-ever-hipaa-penalty-of-6-85-million-on-premera-blue-cross/",
          "publisher": "HIPAA Journal"
        },
        {
          "title": "Premera Blue Cross Breach Exposes Financial, Medical Records",
          "url": "https://krebsonsecurity.com/2015/03/premera-blue-cross-breach-exposes-financial-medical-records/",
          "publisher": "Krebs on Security"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million"
    },
    {
      "slug": "2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto",
      "title": "Yahoo network breached via spear-phishing email, 500 million accounts stolen",
      "date": "2014",
      "date_precision": "year",
      "year": 2014,
      "victim_org": "Yahoo! Inc.",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Espionage"
      ],
      "loss_usd": null,
      "loss_kind": null,
      "loss_note": "",
      "records_affected": 500000000,
      "threat_actor": "Russian FSB officers Dmitry Dokuchaev and Igor Sushchin with criminal hackers Alexsey Belan and Karim Baratov (per 2017 DOJ indictment)",
      "summary": "In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.",
      "how_it_worked": "The operation opened with a spear-phishing email sent to Yahoo staff in early 2014. The message carried custom content tailored to the recipient so it read as ordinary internal or business correspondence, and required only a single click on a malicious link to succeed. Once a foothold existed, one of the criminal hackers moved laterally to Yahoo's User Database and its Account Management Tool, then minted forged authentication cookies that let the group open targeted mailboxes without any password. The intelligence-service sponsors used that capability to read the mail of journalists, officials and company executives of interest.",
      "lessons": "Phishing-resistant authentication on administrative tooling, plus segmentation so a single employee foothold cannot reach the master user database, would have contained the initial click.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Inside the Russian hack of Yahoo: How they did it",
          "url": "https://www.csoonline.com/article/560623/inside-the-russian-hack-of-yahoo-how-they-did-it.html",
          "publisher": "CSO Online"
        },
        {
          "title": "Four Men Charged With Hacking 500M Yahoo Accounts",
          "url": "https://krebsonsecurity.com/2017/03/four-men-charged-with-hacking-500m-yahoo-accounts/",
          "publisher": "Krebs on Security"
        }
      ],
      "entry_type": "incident",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto"
    },
    {
      "title": "Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical",
      "date": "2013-12",
      "date_precision": "month",
      "victim_org": "Target Corporation",
      "sector": "Retail",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI element reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft",
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": null,
      "loss_note": "Target reported cumulative gross breach expenses in the hundreds of millions of dollars across later filings; the sources cited here do not itemise a single figure, so no dollar value is asserted.",
      "records_affected": 110000000,
      "threat_actor": null,
      "summary": "Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.",
      "how_it_worked": "Criminals emailed malware to staff at Fazio Mechanical, a refrigeration and HVAC contractor. Investigators believed the payload was Citadel, a password-stealing derivative of the ZeuS banking trojan; Fazio ran a free anti-malware product without real-time protection. The stolen credentials let attackers log into Target's external vendor-facing systems (Ariba and Partners Online), from which they pivoted into the internal network, deployed memory-scraping malware to point-of-sale registers, and staged and exfiltrated track data from cards swiped in US stores.",
      "lessons": "Vendor portal accounts should be scoped to the billing and project functions they need, with no network path into card-processing segments, and third-party remote access should require phishing-resistant MFA.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Email Attack on Vendor Set Up Breach at Target",
          "url": "https://krebsonsecurity.com/2014/02/email-attack-on-vendor-set-up-breach-at-target/",
          "publisher": "Krebs on Security"
        },
        {
          "title": "A 'Kill Chain' Analysis of the 2013 Target Data Breach",
          "url": "https://www.commerce.senate.gov/services/files/24d3c229-4f2f-405d-b8db-a3a67f183883",
          "publisher": "US Senate Committee on Commerce, Science, and Transportation"
        },
        {
          "title": "Target Breach: Phishing Attack Implicated",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/target-breach-phishing-attack-implicated",
          "publisher": "Dark Reading"
        }
      ],
      "entry_type": "incident",
      "slug": "2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic",
      "year": 2013,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic"
    },
    {
      "title": "AP Twitter account hijacked, fake White House bombing tweet jolts markets",
      "date": "2013-04-23",
      "date_precision": "day",
      "victim_org": "The Associated Press",
      "sector": "Media & Entertainment",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media involvement was reported.",
      "outcomes": [
        "Credential Theft",
        "Service Disruption"
      ],
      "loss_usd": null,
      "loss_note": "No direct loss to AP was reported. The Dow Jones Industrial Average fell about 143 points within minutes before recovering.",
      "records_affected": null,
      "threat_actor": "Syrian Electronic Army (claimed responsibility)",
      "summary": "On 23 April 2013 the Associated Press's main Twitter account posted a false report of two explosions at the White House injuring President Obama. The Dow Jones Industrial Average dropped roughly 143 points in minutes before recovering once AP disavowed the tweet. AP said the account takeover was preceded by phishing attempts against its corporate network; the Syrian Electronic Army claimed responsibility, a claim that was not independently corroborated at the time.",
      "how_it_worked": "Staff at AP received phishing emails aimed at the corporate network shortly before the hijack. The lure exploited newsroom urgency and normal internal circulation of story links, leading recipients toward a credential capture page. Harvested credentials gave the attackers control of the wire service's verified Twitter account, whose authority with algorithmic traders and human readers alike was the real payload. A single 12-word tweet asserting an attack on the President was enough to move equity markets before any verification could occur.",
      "lessons": "Two-factor authentication on corporate social accounts, plus separation of newsroom publishing credentials from ordinary staff email, would have prevented a single phished mailbox from becoming a market-moving broadcast channel.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "AP Twitter Account Hacked; Tweet About Obama Shakes Market",
          "url": "https://www.npr.org/sections/thetwo-way/2013/04/23/178620410/ap-twitter-account-hacked-tweet-about-obama-shakes-market",
          "publisher": "NPR"
        },
        {
          "title": "Hackers compromise AP Twitter account",
          "url": "https://www.cbsnews.com/news/hackers-compromise-ap-twitter-account/",
          "publisher": "CBS News"
        }
      ],
      "entry_type": "incident",
      "slug": "2013-ap-twitter-account-hijacked-fake-white-house-bombing-tweet-jolts-markets",
      "year": 2013,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2013-ap-twitter-account-hijacked-fake-white-house-bombing-tweet-jolts-markets"
    },
    {
      "title": "Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million",
      "date": "2013",
      "date_precision": "year",
      "victim_org": "Google LLC and Facebook, Inc.",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Vendor / Supply Chain Impersonation",
      "secondary_vectors": [
        "Business Email Compromise",
        "Spear Phishing (Email)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI or synthetic media was reported; the scheme relied on forged paper documents and lookalike corporate identity.",
      "outcomes": [
        "Wire Fraud / Financial Loss"
      ],
      "loss_usd": 120000000,
      "loss_note": "DOJ states the scheme caused more than $120 million in losses to the two victim companies. Rimasauskas was ordered to forfeit $49,738,559.41 and pay $26,479,079.24 in restitution.",
      "records_affected": null,
      "threat_actor": "Evaldas Rimasauskas (Lithuanian national) and co-conspirators",
      "summary": "From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.",
      "how_it_worked": "The fraud abused the accounts payable relationship between two technology giants and a legitimate Taiwanese hardware manufacturer. Rimasauskas incorporated a shell company bearing the supplier's name in Latvia, opened bank accounts in its name, and sent phishing and invoice emails from addresses designed to look like the supplier's. He supported the requests with forged invoices, contracts and letters carrying counterfeit corporate stamps and executive signatures, which satisfied the victims' vendor verification paperwork. Because the amounts matched real ongoing supplier business, finance staff processed the wires as routine vendor payments, and the funds were quickly moved across Latvian, Cypriot and other accounts.",
      "lessons": "Bank-detail changes for existing suppliers must be verified by callback to a phone number already on file, and payment files should be reconciled against master vendor records rather than against details supplied in the invoice email.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Lithuanian Man Sentenced To 5 Years In Prison For Theft Of Over $120 Million In Fraudulent Business Email Compromise Scheme",
          "url": "https://www.justice.gov/usao-sdny/pr/lithuanian-man-sentenced-5-years-prison-theft-over-120-million-fraudulent-business",
          "publisher": "U.S. Department of Justice, S.D.N.Y."
        },
        {
          "title": "Ringleader of Business Email Compromise Scheme Sentenced",
          "url": "https://www.fbi.gov/news/stories/ringleader-of-business-email-compromise-scheme-sentenced-012820",
          "publisher": "Federal Bureau of Investigation"
        },
        {
          "title": "Lithuanian Man Arrested For Theft Of Over $100 Million In Fraudulent Email Compromise Scheme",
          "url": "https://www.justice.gov/usao-sdny/pr/lithuanian-man-arrested-theft-over-100-million-fraudulent-email-compromise-scheme",
          "publisher": "U.S. Department of Justice"
        },
        {
          "title": "Lithuanian Man Sentenced to Prison Over BEC Scheme Targeting Facebook, Google",
          "url": "https://www.securityweek.com/lithuanian-man-sentenced-prison-over-bec-scheme-targeting-facebook-google/",
          "publisher": "SecurityWeek"
        },
        {
          "title": "How this scammer used phishing emails to steal over $100 million from Google and Facebook",
          "url": "https://www.cnbc.com/2019/03/27/phishing-email-scam-stole-100-million-from-facebook-and-google.html",
          "publisher": "CNBC"
        },
        {
          "title": "Lithuanian scammer gets 5 years for defrauding Google, Facebook of $120 million",
          "url": "https://cyberscoop.com/facebook-google-scam-man-sentenced/",
          "publisher": "CyberScoop"
        }
      ],
      "entry_type": "incident",
      "slug": "2013-rimasauskas-bec-scheme-defrauds-google-and-facebook-of-over-120-million",
      "year": 2013,
      "loss_kind": "direct_loss",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2013-rimasauskas-bec-scheme-defrauds-google-and-facebook-of-over-120-million"
    },
    {
      "title": "Epsilon email marketing breach exposes address lists of banks and retailers",
      "date": "2011-04",
      "date_precision": "month",
      "victim_org": "Epsilon Data Management and other email service providers",
      "sector": "Professional Services",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [
        "Watering Hole / Malvertising",
        "Credential Phishing Portal"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement reported.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": 2000000,
      "loss_note": "The indictment alleged the defendants generated over $2 million from spam campaigns promoting counterfeit software using the stolen lists; downstream costs to the affected brands were not quantified.",
      "records_affected": 1000000000,
      "threat_actor": "Viet Quoc Nguyen, Giang Hoang Vu and David-Manuel Santos Da Silva (indicted March 2015)",
      "summary": "In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.",
      "how_it_worked": "The lead defendant sent targeted phishing emails to employees of email service providers. The messages carried links to sites built to exploit browser vulnerabilities and silently install malware, giving backdoor access to employee workstations and, from there, harvested access credentials for the marketing platforms. With those credentials he bulk-downloaded subscriber lists to a server he controlled in the Netherlands. Because the stolen records paired real names with the specific brands each person banked or shopped with, they were unusually valuable for follow-on spear phishing against consumers.",
      "lessons": "Marketing platforms holding client subscriber lists need bulk-export alerting and least-privilege segregation, so one phished employee workstation cannot pull the entire customer database.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Feds Indict Three in 2011 Epsilon Hack",
          "url": "https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/",
          "publisher": "Krebs on Security"
        }
      ],
      "entry_type": "incident",
      "slug": "2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail",
      "year": 2011,
      "loss_kind": "criminal_proceeds",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2011-epsilon-email-marketing-breach-exposes-address-lists-of-banks-and-retail"
    },
    {
      "title": "RSA SecurID breach begins with '2011 Recruitment Plan' spear phishing email",
      "date": "2011-03",
      "date_precision": "month",
      "victim_org": "RSA Security (EMC)",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Spear Phishing (Email)",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "Pre-dates generative AI tooling; no AI component reported.",
      "outcomes": [
        "Data Breach",
        "Espionage",
        "Supply Chain Compromise"
      ],
      "loss_usd": 66000000,
      "loss_note": "EMC publicly attributed roughly $66 million of incident-related costs (including token replacement and monitoring) to the breach across 2011 quarters; press reporting of that figure is consistent, but the number is a company estimate rather than an audited breach loss.",
      "records_affected": null,
      "threat_actor": "Suspected nation-state actor (widely reported as China-linked; never formally attributed by RSA)",
      "summary": "In March 2011 attackers stole information related to RSA's SecurID two-factor authentication product after two small groups of RSA employees were sent spear phishing emails carrying a booby-trapped Excel attachment. RSA executive Uri Rivner publicly described the lure email as being titled '2011 Recruitment Plan.' The stolen SecurID data was subsequently used in attempted intrusions at US defense contractors, and RSA offered to replace tokens for customers.",
      "how_it_worked": "Two batches of emails, each to a small group of non-executive employees, carried an Excel spreadsheet named for a '2011 Recruitment Plan.' At least one recipient retrieved the message from their junk folder and opened it. The workbook embedded an Adobe Flash object exploiting a then-unpatched zero-day (CVE-2011-0609), which dropped a Poison Ivy remote access tool configured in reverse-connect mode. The attackers then harvested credentials, escalated to administrative and service accounts, staged data in password-protected RAR archives and exfiltrated it over FTP to an external staging host, taking SecurID-related information with them.",
      "lessons": "Attachment sandboxing and aggressive third-party plugin patching would have blunted the exploit, and segmenting the seed-record environment from general corporate desktops would have contained a single opened attachment.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "RSA: SecurID Attack Was Phishing Via an Excel Spreadsheet",
          "url": "https://threatpost.com/rsa-securid-attack-was-phishing-excel-spreadsheet-040111/75099/",
          "publisher": "Threatpost"
        },
        {
          "title": "RSA SecureID Attack Began With Excel File Rigged With Flash Zero-Day",
          "url": "https://www.darkreading.com/cyberattacks-data-breaches/rsa-secureid-attack-began-with-excel-file-rigged-with-flash-zero-day",
          "publisher": "Dark Reading"
        },
        {
          "title": "'Tricked' RSA Employee Opened Door that Led to APT Attack",
          "url": "https://www.bankinfosecurity.com/tricked-rsa-worker-opened-backdoor-to-apt-attack-a-3504",
          "publisher": "BankInfoSecurity"
        }
      ],
      "entry_type": "incident",
      "slug": "2011-rsa-securid-breach-begins-with-2011-recruitment-plan-spear-phishing-emai",
      "year": 2011,
      "loss_kind": "business_impact",
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2011-rsa-securid-breach-begins-with-2011-recruitment-plan-spear-phishing-emai"
    },
    {
      "title": "Sarah Palin Yahoo email account taken over via password-reset questions",
      "date": "2008-09",
      "date_precision": "month",
      "victim_org": "Sarah Palin (then Governor of Alaska and vice-presidential candidate)",
      "sector": "Government",
      "country": "United States",
      "primary_vector": "Physical Pretexting",
      "secondary_vectors": [],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement; the attack relied on publicly available biographical facts.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "No financial loss reported; the harm was disclosure of private correspondence during a national election campaign.",
      "records_affected": null,
      "threat_actor": "David C. Kernell (convicted)",
      "summary": "During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.",
      "how_it_worked": "Kernell did not exploit a software flaw. He used the provider's self-service password reset flow, which authenticated the requester by asking knowledge-based security questions such as birth date, postal code and where the account holder met her spouse. Because the account holder was a sitting governor and national candidate, all of those answers were recoverable from publicly published biography and news coverage. Supplying them let him set a new password and read the mailbox, and he then published screenshots, turning a consumer account recovery convenience into a national political disclosure.",
      "lessons": "Knowledge-based authentication is unusable for public figures whose life details are published; account recovery should use possession-based factors such as a registered device or hardware key.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Tennessee Man Sentenced for Illegally Accessing Former Governor Sarah Palin's E-mail Account",
          "url": "https://www.justice.gov/archives/opa/pr/tennessee-man-sentenced-illegally-accessing-former-governor-sarah-palin-s-e-mail-account-and",
          "publisher": "U.S. Department of Justice"
        }
      ],
      "entry_type": "incident",
      "slug": "2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions",
      "year": 2008,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions"
    },
    {
      "title": "HP boardroom pretexting scandal: investigators impersonate directors to phone carriers",
      "date": "2006-10-04",
      "date_precision": "day",
      "victim_org": "Hewlett-Packard directors, journalists and their family members",
      "sector": "Technology",
      "country": "United States",
      "primary_vector": "Physical Pretexting",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement.",
      "outcomes": [
        "Data Breach",
        "Identity Theft"
      ],
      "loss_usd": null,
      "loss_note": "No direct theft; the consequences were criminal charges, executive resignations and reputational damage.",
      "records_affected": 13,
      "threat_actor": "Security Outsourcing Solutions and Action Research Group investigators retained by HP",
      "summary": "California Attorney General Bill Lockyer filed criminal charges on 4 October 2006 against former HP chairwoman Patricia Dunn, former HP ethics chief Kevin Hunsaker and three outside investigators. To identify the source of boardroom leaks to the press, investigators obtained the private telephone billing records of 12 people by impersonating them to phone carriers. Personal identifying information for 13 board members, journalists and family members was obtained and used unlawfully. Each defendant faced four felony counts.",
      "how_it_worked": "Investigators working for HP called telephone carriers and posed as the account holders, supplying names, phone numbers and Social Security numbers to satisfy the carriers' identity checks and unlock the account. Carrier call center agents, whose job incentives favored resolving customer problems quickly, released detailed billing and call-detail records. Those records were then correlated to link directors and reporters and identify the leak. The lever was ordinary customer service helpfulness combined with weak caller verification, and the extracted action was disclosure of confidential subscriber records.",
      "lessons": "Carriers needed possession-based caller verification such as a callback to the number of record or an account PIN rather than knowledge of publicly obtainable identifiers; the case directly prompted federal pretexting legislation for phone records.",
      "confidence": "Confirmed",
      "sources": [
        {
          "title": "Attorney General Lockyer Files Criminal Charges Against Former Hewlett-Packard Chairwoman, Others",
          "url": "https://www.oag.ca.gov/news/press-releases/attorney-general-lockyer-files-criminal-charges-against-former-hewlett-packard",
          "publisher": "California Office of the Attorney General"
        }
      ],
      "entry_type": "incident",
      "slug": "2006-hp-boardroom-pretexting-scandal-investigators-impersonate-directors-to-p",
      "year": 2006,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/2006-hp-boardroom-pretexting-scandal-investigators-impersonate-directors-to-p"
    },
    {
      "title": "Kevin Mitnick's telecom pretexting campaign and 1995 arrest",
      "date": "1995-02-15",
      "date_precision": "day",
      "victim_org": "Pacific Bell, Digital Equipment Corporation and other telecommunications and computer firms",
      "sector": "Telecom",
      "country": "United States",
      "primary_vector": "Physical Pretexting",
      "secondary_vectors": [
        "Vishing (Voice Phishing)"
      ],
      "ai_involvement": "No AI reported",
      "ai_notes": "No AI involvement; the era predates generative tooling.",
      "outcomes": [
        "Data Breach",
        "Credential Theft"
      ],
      "loss_usd": null,
      "loss_note": "Loss estimates in the case were heavily disputed at the time and are not stated here.",
      "records_affected": null,
      "threat_actor": "Kevin Mitnick",
      "summary": "Kevin Mitnick was arrested by the FBI in Raleigh, North Carolina on 15 February 1995 and found with cloned cellular phones, more than 100 cloned cellular phone codes and multiple pieces of false identification. In 1999 he pleaded guilty to four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting wire communications, and admitted copying proprietary software from large cellular telephone and computer companies. He was sentenced to 46 months plus 22 months for violating supervised release. His case is the formative reference point for social engineering as a discipline.",
      "how_it_worked": "Mitnick's intrusions leaned far more on telephone pretexting than on exploits. He would call employees while posing as a colleague from another department, a vendor engineer or an internal support technician, using accurate internal jargon, employee names and project references gathered from earlier calls and from discarded documents. Each call extracted a small, individually harmless item, a dial-in number, a system name, a temporary password reset, and those items compounded into working access. The lever was deference to apparent internal authority and the desire to be helpful to a co-worker under time pressure.",
      "lessons": "Identity verification for any internal request must be independent of the caller's own claims, and password resets should require an out-of-band confirmation the caller cannot supply by talking.",
      "confidence": "Reported",
      "sources": [
        {
          "title": "Kevin Mitnick",
          "url": "https://en.wikipedia.org/wiki/Kevin_Mitnick",
          "publisher": "Wikipedia"
        }
      ],
      "entry_type": "incident",
      "slug": "1995-kevin-mitnick-s-telecom-pretexting-campaign-and-1995-arrest",
      "year": 1995,
      "loss_kind": null,
      "url": "https://global-social-engineering-impact-da.vercel.app/incidents/1995-kevin-mitnick-s-telecom-pretexting-campaign-and-1995-arrest"
    }
  ]
}