{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T05:33:28.202Z","total":277,"returned":50,"limit":50,"offset":0,"next":"https://global-social-engineering-impact-da.vercel.app/api/incidents?offset=50&limit=50","note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ReliaQuest blocks ShinyHunters vishing attack with device-trust controls","date":"2026-08-24","date_precision":"day","victim_org":"ReliaQuest","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"ReliaQuest did not state whether synthetic voice was used on the calls.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; no customer data was accessed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.","how_it_worked":"The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.","lessons":"Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.","confidence":"Confirmed","sources":[{"title":"ReliaQuest confirms failed data-theft attack after ShinyHunters breach","url":"https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-reliaquest-blocks-shinyhunters-vishing-attack-with-device-trust-controls"},{"slug":"2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ","title":"Levi Strauss files 8-K after social engineering compromises three employee computers","date":"2026-08-07","date_precision":"day","year":2026,"victim_org":"Levi Strauss & Co.","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Levi Strauss & Co. filed a Form 8-K with the SEC on 7 August 2026 disclosing that attackers used social engineering to gain unauthorised access to three employee computers and exfiltrated unspecified corporate information. The company said it had no evidence that consumer information was affected and experienced no business disruption, and determined the incident was not material. Reuters reporting linked the infrastructure involved to a ransom-seeking crew that had targeted more than 200 companies in the preceding five weeks.","how_it_worked":"Levi Strauss disclosed only that the vector was social engineering against employees, without naming the technique. The linkage Reuters drew to a crew running a five-week, 200-company spree matches the voice-phishing-plus-lookalike-portal pattern dominant through 2026, in which callers impersonating IT support harvest credentials and session tokens from individual staff. Access reached three endpoints and corporate data was taken before the company contained it. Levi Strauss activated incident response and engaged third-party specialists; consumer systems were reported unaffected.","lessons":"Phishing-resistant MFA plus rapid session revocation limits a three-endpoint compromise to exactly that; the 8-K filing over three laptops shows how cheaply this vector reaches material-disclosure territory.","confidence":"Confirmed","sources":[{"title":"Levi Strauss discloses data breach after social engineering attack on employees","url":"https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/","publisher":"CyberInsider"},{"title":"Levi Strauss describes contained cyber incident, LEVI 8-K filing","url":"https://www.stocktitan.net/sec-filings/LEVI/8-k-levi-strauss-co-reports-material-event-0f6321560e78.html","publisher":"StockTitan (SEC filing)"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-levi-strauss-files-8-k-after-social-engineering-compromises-three-employ"},{"title":"Hedge funds targeted by UNC6671 vishing; Point72 and Two Sigma blocked attacks","date":"2026-08-06","date_precision":"day","victim_org":"Point72, Millennium Management, Two Sigma, Citadel and private-equity firms","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Reporting described human helpdesk impersonation and branded phishing kits; synthetic voice was not confirmed.","outcomes":["Attempt Blocked","Extortion","Credential Theft"],"loss_usd":10600000,"loss_note":"Between January and May 2026 the group received over $10.6 million in Bitcoin across victims; initial demands reached $3 million, typically settling near $750,000. This is a campaign-wide figure, not a per-victim loss.","records_affected":null,"threat_actor":"UNC6671, associated with BlackFile; public brands include Redact, Pink, Helix and Falcon","summary":"BleepingComputer reported on August 6, 2026 that extortion group UNC6671 had run vishing attacks against major hedge funds and private-equity firms including Point72, Millennium Management, Two Sigma and Citadel. Point72 said it was attacked but found no evidence of client data theft, and Two Sigma said it blocked the intrusion attempt with no system or data compromise. The group received more than $10.6 million in Bitcoin between January and May 2026.","how_it_worked":"Operators called employees on their personal mobile phones while impersonating the firm's helpdesk, then used a passkey enrolment or MFA update pretext to send them to fraudulent domains styled after the employer and hosting credential-stealing phishing kits. Captured credentials and session cookies gave access to Microsoft 365 or Okta single sign-on, and through SSO to every linked cloud platform. The attackers then automated data collection across those services and deleted security notification emails to slow detection before opening ransom negotiations.","lessons":"Device-bound passkeys plus conditional access that rejects sessions from unmanaged devices stop stolen cookies and relayed credentials from turning into SSO access.","confidence":"Confirmed","sources":[{"title":"Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group","url":"https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at","year":2026,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hedge-funds-targeted-by-unc6671-vishing-point72-and-two-sigma-blocked-at"},{"slug":"2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee","title":"Brinks Home breached after Microsoft Entra vishing call to an employee","date":"2026-07-13","date_precision":"day","year":2026,"victim_org":"Brinks Home","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.","how_it_worked":"The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.","lessons":"Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.","confidence":"Confirmed","sources":[{"title":"ShinyHunters claims Brinks Home breach, threatens to leak stolen data","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/","publisher":"BleepingComputer"},{"title":"Salesforce Hacks 2026: Everything We Know So Far","url":"https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"},{"title":"Apollo Global Management breached by BlackFile callers posing as IT support","date":"2026-07-06","date_precision":"day","victim_org":"Apollo Global Management","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Researchers described a large pool of human callers recruited for small fees rather than synthetic voice.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"Apollo did not disclose a figure; researchers said BlackFile typically opens around $3 million and settles under $1 million.","records_affected":null,"threat_actor":"BlackFile (tracked by Google as UNC6671), part of The Com, operating the Redact, Pink, Helix and Falcon extortion brands","summary":"Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.","how_it_worked":"BlackFile industrialised the phone call. Researchers describe hundreds of callers, often low-level people recruited for a small fee or for standing within the group, dialling employees while impersonating internal IT support until one target complies. Volume replaces finesse: the crew averages about 1.5 new victims a day and has hit private equity firms, law firms, ratings agencies and medical technology companies. Once an identity is obtained the operators move into cloud platforms and collect data for extortion, escalating with threatening messages and swatting when victims resist.","lessons":"Phishing-resistant MFA plus a strict no-credentials-over-the-phone policy blunts high-volume calling, and cloud data stores need export alerting because these crews steal rather than encrypt.","confidence":"Confirmed","sources":[{"title":"Apollo discloses data breach from ongoing wave of attacks hitting financial sector","url":"https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/","publisher":"CyberScoop"},{"title":"Details emerge on BlackFile's recent attacks on financial companies","url":"https://cyberscoop.com/blackfile-cyberattacks-financial-sector/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"},{"slug":"2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai","title":"RingCentral data on 1.6M accounts leaked after social engineering campaign","date":"2026-07","date_precision":"month","year":2026,"victim_org":"RingCentral","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1600000,"threat_actor":"ShinyHunters","summary":"Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.","how_it_worked":"RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.","lessons":"Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.","confidence":"Confirmed","sources":[{"title":"RingCentral data breach exposed info of 1.6 million accounts","url":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","publisher":"BleepingComputer"},{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","url":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-ringcentral-data-on-1-6m-accounts-leaked-after-social-engineering-campai"},{"slug":"2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365","title":"Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Corporate Microsoft 365 users across a dozen countries","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Actors tracked as codemado, mail-argenta and saroula01","summary":"French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.","how_it_worked":"Two of the three crews ran reverse-proxy phishing: the victim received a link to a page that forwarded every keystroke to the real Microsoft login and returned the genuine responses, so the sign-in looked and behaved correctly while the operator captured the password and the resulting session cookie. The mail-argenta fork pre-filled the victim's email address and rewrote URLs to evade detection. The quietest and most successful operator instead abused Microsoft's legitimate device code flow, persuading targets to enter a short code on the real Microsoft site, which authorises the attacker's device without any fake page at all and defeats MFA including passkeys.","lessons":"Device code flow should be disabled by conditional access policy where it is not needed, and long-lived session cookies should be cut short and rebound to device compliance.","confidence":"Confirmed","sources":[{"title":"Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365","url":"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365"},{"slug":"2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre","title":"Armored Likho spear phishing targets government and power sector in three countries","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Government agencies and electric power organisations in Russia, Brazil and Kazakhstan","sector":"Government","country":"Russia","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Armored Likho (overlaps with Eagle Werewolf)","summary":"Kaspersky reported in July 2026 on Armored Likho, a group targeting government agencies and the electric power sector in Russia, Brazil and Kazakhstan with spear-phishing emails. Lures referenced official government notices and social programmes and carried RAR archives containing executables. The chain pulled payloads from GitHub, exploited CVE-2025-9491 in Windows LNK handling, and deployed BusySnake Stealer, AquilaRAT, Go2Tunnel and RustDesk.","how_it_worked":"The entry point was a document a civil servant would plausibly be expected to open: a notice about an official government matter or a social programme, delivered as a RAR attachment. AquilaRAT was disguised as a Starlink device checklist, borrowing the credibility of equipment the target's organisation actually uses. Opening the archive and running its contents started the chain; the LNK vulnerability then carried execution forward without further user action. BusySnake harvested clipboard data, files, screenshots, cryptocurrency wallets, Telegram credentials and browser cookies, while RustDesk and reverse SSH tunnels held remote access open.","lessons":"Blocking executable content inside archives at the mail gateway and patching the LNK handling flaw removes both halves of the chain; the lure only works if the attachment can run.","confidence":"Confirmed","sources":[{"title":"Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer","url":"https://thehackernews.com/2026/07/armored-likho-targets-government.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-armored-likho-spear-phishing-targets-government-and-power-sector-in-thre"},{"slug":"2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag","title":"FBI identifies North Korean remote IT worker employed by a US federal agency","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Unnamed US federal agency","sector":"Government","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Insider Access","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker programme","summary":"FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.","how_it_worked":"The DPRK remote IT worker programme wins access by being hired rather than by breaking in. Operatives apply for remote technical roles using stolen or fabricated identities, often with US-based facilitators who host company laptops, sit for identity checks, or lend a domestic address and bank account so that pay and equipment appear to land with a real person in the United States. Video interviews and onboarding checks are handled by the operative or the facilitator. Once employed the worker holds legitimate credentials and normal access, which is why detection typically comes from behavioural or payroll anomalies rather than security tooling.","lessons":"Live identity proofing at hire and again at equipment issue, plus checks that payroll destinations and laptop network locations match the claimed residence, are what surface these placements.","confidence":"Confirmed","sources":[{"title":"FBI investigating North Korean remote IT staffer working for US agency","url":"https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/","publisher":"Federal News Network"},{"title":"FBI finds North Korean IT worker inside federal agency","url":"https://www.thestreet.com/employment/fbi-north-korean-remote-worker-insider-threat-2026","publisher":"TheStreet"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag"},{"slug":"2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day","title":"Lazarus pairs fake recruiter approaches with a Windows zero-day","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Defence and aerospace organisations in Western Europe, India and South America","sector":"Defense","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Lazarus Group (North Korea)","summary":"Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.","how_it_worked":"Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.","lessons":"Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.","confidence":"Confirmed","sources":[{"title":"Lazarus hackers pair fake job offers with Windows zero-day exploit","url":"https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/","publisher":"Help Net Security"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"},{"slug":"2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe","title":"Abbott investigates ShinyHunters claim after mid-June vishing on employees","date":"2026-06","date_precision":"month","year":2026,"victim_org":"Abbott Laboratories (legacy Exact Sciences systems)","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.","how_it_worked":"Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.","lessons":"Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.","confidence":"Reported","sources":[{"title":"Abbott Investigating Cyberattack Claims From Two Threat Actors","url":"https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/","publisher":"HIPAA Journal"},{"title":"Abbott investigates after ShinyHunters claims massive data theft","url":"https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"},{"title":"Quantum Health network breached after social engineering call to a user","date":"2026-05-29","date_precision":"day","victim_org":"Quantum Health","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.","how_it_worked":"The intrusion started with a phone call rather than an email or an exploit. The caller persuaded a legitimate user to hand over the credentials needed to reach the network, and the attacker then held that access for roughly four days. Because the login was valid and used in a normal way, nothing surfaced until a network disruption on June 1 prompted investigation. HIPAA Journal noted that the tradecraft aligns with tactics commonly employed by the ShinyHunters threat group, though no ransomware operation claimed the incident.","lessons":"Phishing-resistant MFA prevents a disclosed password from being usable, and impossible-travel or new-device alerts would have flagged the four-day window of unfamiliar access.","confidence":"Reported","sources":[{"title":"Vishing Attack on Quantum Health Network Exposed Patient Data","url":"https://www.hipaajournal.com/quantum-health-precision-imaging-centers-heart-america-data-breaches/","publisher":"The HIPAA Journal"}],"entry_type":"incident","slug":"2026-quantum-health-network-breached-after-social-engineering-call-to-a-user","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-quantum-health-network-breached-after-social-engineering-call-to-a-user"},{"slug":"2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials","title":"MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices","date":"2026-05-06","date_precision":"day","year":2026,"victim_org":"Multiple organisations in the United States and MENA (unnamed)","sector":"Manufacturing","country":"United States and Middle East / North Africa","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"MuddyWater (Seedworm), assessed as linked to Iran's Ministry of Intelligence and Security, operating behind Chaos ransomware branding","summary":"Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.","how_it_worked":"The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.","lessons":"Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.","confidence":"Reported","sources":[{"title":"Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware","url":"https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/","publisher":"Rapid7 Labs"},{"title":"MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack","url":"https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"},{"slug":"2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft","title":"Cushman & Wakefield confirms vishing-triggered Salesforce data theft","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Cushman & Wakefield","sector":"Professional Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters; Qilin also claimed the victim","summary":"Commercial real estate firm Cushman & Wakefield confirmed in May 2026 that it had suffered a limited data security incident due to vishing. ShinyHunters listed the company on 5 May with a three-day ransom deadline claiming more than 500,000 Salesforce records including personal and internal corporate data, without publishing proof samples. Qilin separately listed the company on 4 May. Cushman & Wakefield said systems and operations continued to function normally.","how_it_worked":"The company's own statement names voice phishing as the cause. In this pattern a caller impersonating internal IT or a service provider contacts an employee about a supposedly urgent access issue and walks them through a login on a lookalike portal, capturing the password and the multi-factor response in real time. The stolen session gave the crew the employee's view of the firm's Salesforce tenant, from which client and corporate records were exported. Two extortion brands claiming the same victim within a day of each other points to shared or resold access.","lessons":"Phishing-resistant MFA plus export limits and alerting inside Salesforce would have blocked the login and capped what a single compromised seat could retrieve.","confidence":"Confirmed","sources":[{"title":"Two ransomware gangs now claim Cushman & Wakefield after Salesforce breach claim","url":"https://cybernews.com/news/cushman-wakefield-shinyhunters-salesforce-breach-claim/","publisher":"Cybernews"},{"title":"Cushman & Wakefield Hit by ShinyHunters Vishing Attack — 50GB Salesforce Data Dumped","url":"https://breached.company/cushman-wakefield-shinyhunters-vishing-salesforce-50gb-leak-2026/","publisher":"Breached.Company"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cushman-wakefield-confirms-vishing-triggered-salesforce-data-theft"},{"slug":"2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman","title":"700+ education and tech sites hijacked to serve ClickFix paste-the-command lures","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Visitors to 700+ compromised university and technology company websites","sector":"Education","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.","how_it_worked":"The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.","lessons":"Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.","confidence":"Confirmed","sources":[{"title":"700+ education and tech websites hijacked in huge ClickFix malware campaign","url":"https://www.malwarebytes.com/blog/bugs/2026/05/700-education-and-tech-websites-hijacked-in-huge-clickfix-malware-campaign","publisher":"Malwarebytes"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"},{"slug":"2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat","title":"UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services","sector":"Other","country":"Global","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":10600000,"loss_kind":"criminal_proceeds","loss_note":"USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.","records_affected":null,"threat_actor":"UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)","summary":"Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.","how_it_worked":"Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.","lessons":"Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.","confidence":"Confirmed","sources":[{"title":"Vishing Extortion Group UNC6671 Rebrands After Making Millions","url":"https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/","publisher":"SecurityWeek"},{"title":"UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data","url":"https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"},{"slug":"2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca","title":"City of Aurora loses $1.1M after employee falls for bank impersonation call","date":"2026-04-29","date_precision":"day","year":2026,"victim_org":"City of Aurora, Illinois","sector":"Government","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":1100000,"loss_kind":"direct_loss","loss_note":"USD, approximately $1.1 million taken from municipal payroll accounts. Recovery efforts ongoing with law enforcement and the bank; the city carries insurance covering losses of this type.","records_affected":null,"threat_actor":null,"summary":"On 29 April 2026 a City of Aurora, Illinois employee took a call from someone posing as a representative of the city's bank and disclosed sensitive banking information. The caller used those details to make fraudulent transactions totalling nearly $1.1 million from municipal accounts. Officials found no evidence that city networks or data systems were compromised. Law enforcement, the bank and outside cybersecurity experts were engaged, and the city holds insurance for losses of this kind.","how_it_worked":"The pretext was routine banking business and the identity impersonated was the city's own financial institution, the party a finance employee expects to hear from about account matters. Officials described these schemes as exploiting trust and manufacturing urgency, and the deception worked purely by phone; nothing was hacked. The employee supplied account credentials or verification details during the call, which the fraudster immediately used to authorise transfers out of city payroll accounts. Discovery came shortly after the payments cleared.","lessons":"A hard rule that no banking detail or verification code is ever given on an inbound call, only on a callback to a number held on file, plus bank-side dual authorisation on outbound transfers.","confidence":"Confirmed","sources":[{"title":"Aurora lost nearly $1.1M from city bank accounts after employee fell for phone scam, officials say","url":"https://www.nbcchicago.com/news/local/aurora-lost-1-1m-from-city-bank-accounts-after-employee-fell-for-phone-scam-officials-say/3939104/","publisher":"NBC Chicago"},{"title":"'Social Engineering Fraud' Cost Aurora, Ill., Nearly $1.1M","url":"https://www.govtech.com/security/social-engineering-fraud-cost-aurora-ill-nearly-1-1m","publisher":"Government Technology"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-city-of-aurora-loses-1-1m-after-employee-falls-for-bank-impersonation-ca"},{"title":"ADT confirms breach after vishing attack on employee's Okta SSO account","date":"2026-04-20","date_precision":"day","victim_org":"ADT","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using AI voice agents in its vishing operations; AI use in the ADT call was not separately confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"ShinyHunters set an April 27, 2026 ransom deadline; no payment or loss figure was disclosed.","records_affected":null,"threat_actor":"ShinyHunters","summary":"ADT detected unauthorised access on April 20, 2026 and confirmed the breach publicly on April 24, 2026. Attackers used voice phishing against an employee's Okta single sign-on account, then stole data from the company's Salesforce instance. Exposed data included names, phone numbers and addresses, with dates of birth and the last four digits of Social Security or Tax ID numbers in a small percentage of cases. ShinyHunters claimed more than 10 million records; ADT did not confirm that figure.","how_it_worked":"An operator called an ADT employee posing as internal support and used a plausible authentication pretext to route them to a company-branded fake sign-in page. The page relayed the credentials and one-time code to the real Okta login in real time, giving the attacker a live SSO session. Because Salesforce sat behind that same single sign-on, the session opened the CRM directly, and the attackers exported customer and prospect records in bulk before ADT terminated the intrusion. Extortion followed, with a leak deadline set three days after public confirmation.","lessons":"Phishing-resistant passkeys bound to managed devices, plus export-volume alerting on the CRM, would have blocked both the credential relay and the bulk extraction.","confidence":"Confirmed","sources":[{"title":"ADT confirms data breach after ShinyHunters leak threat","url":"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/","publisher":"BleepingComputer"},{"title":"ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack","url":"https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack","publisher":"Rescana"}],"entry_type":"incident","slug":"2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-adt-confirms-breach-after-vishing-attack-on-employee-s-okta-sso-account"},{"slug":"2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi","title":"Carnival confirms social engineering of an employee account exposed 6 million customers","date":"2026-04-14","date_precision":"day","year":2026,"victim_org":"Carnival Corporation","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5995277,"threat_actor":"ShinyHunters","summary":"Carnival Corporation's IT security team identified unauthorized activity on an employee account on 14 April 2026, four days after the intrusion began. Carnival's notification states that an unauthorized actor used social engineering to deceive an employee and reach a limited portion of the company's IT systems, from which files were copied. Roughly 5,995,277 people were notified from 28 May 2026, and ShinyHunters claimed more than 8.7 million records including Holland America Line Mariner Society loyalty data. The Texas Attorney General opened an investigation in June 2026.","how_it_worked":"Carnival has confirmed only that an unauthorized actor used social engineering to deceive an employee into giving up access to that employee's account, which was then used to reach internal systems and copy customer files. The company has not published the channel, the pretext, or the identity the attacker impersonated. ShinyHunters, which claimed the data, was running a sustained voice-phishing campaign against corporate SSO accounts through this period, in which callers posed as internal IT support and walked staff through handing over sign-in codes, so vishing is the reported and likely channel rather than a confirmed one.","lessons":"Phishing-resistant MFA bound to the device, plus a rule that internal IT never asks staff for a sign-in code by phone, removes the credential a caller can talk an employee out of.","confidence":"Reported","sources":[{"title":"Carnival Cruise confirms data breach affecting nearly 6 million people","url":"https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/","publisher":"BleepingComputer"},{"title":"Carnival Data Breach Exposed 6 Million People","url":"https://www.securityweek.com/carnival-data-breach-exposed-6-million-people/","publisher":"SecurityWeek"},{"title":"Attorney General Paxton Announces Ongoing Investigation into Carnival Cruise Line Over Data Breach","url":"https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach","publisher":"Office of the Texas Attorney General"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-carnival-confirms-social-engineering-of-an-employee-account-exposed-6-mi"},{"title":"Kraken refuses extortion after two support insiders accessed client data","date":"2026-04-13","date_precision":"day","victim_org":"Kraken","sector":"Cryptocurrency","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported in this case.","outcomes":["Extortion","Insider Access","Attempt Blocked"],"loss_usd":null,"loss_note":"Kraken refused to pay and reported no funds at risk; no loss figure disclosed.","records_affected":2000,"threat_actor":null,"summary":"CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.","how_it_worked":"The route in was people, not software. Criminals worked through members of Kraken's own customer support team to reach client support data, mirroring the bribery-of-support-agents pattern seen at Coinbase a year earlier. The stolen material was then repackaged as leverage: the extortionists produced video framed to look like live access to Kraken's internal systems and demanded payment to suppress it. Kraken said its systems were never breached and that the access was terminated, controls tightened, affected clients notified, and law enforcement engaged, with sufficient evidence to identify those responsible.","lessons":"Scoped, justification-based access in support consoles plus insider-risk monitoring limits both what an insider can reach and how long it goes unnoticed.","confidence":"Confirmed","sources":[{"title":"Crypto exchange Kraken targeted in extortion attempt, but says there was no breach and no client funds at risk","url":"https://www.coindesk.com/business/2026/04/13/crypto-exchange-kraken-targeted-in-extortion-attempt-but-says-there-was-no-breach-and-no-client-funds-at-risk","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-kraken-refuses-extortion-after-two-support-insiders-accessed-client-data"},{"title":"Six-month DPRK social engineering operation preceded $285M Drift Protocol theft","date":"2026-04-01","date_precision":"day","victim_org":"Drift Protocol","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Physical Pretexting","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.","outcomes":["Cryptocurrency Theft"],"loss_usd":285000000,"loss_note":"USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.","records_affected":null,"threat_actor":"UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence","summary":"Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.","how_it_worked":"This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.","lessons":"Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.","confidence":"Reported","sources":[{"title":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","publisher":"The Hacker News"},{"title":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks","publisher":"TRM Labs"}],"entry_type":"incident","slug":"2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol","year":2026,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"},{"slug":"2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi","title":"Charter Communications breach of 4.9M accounts began with an Entra vishing call","date":"2026-04-01","date_precision":"day","year":2026,"victim_org":"Charter Communications (Spectrum)","sector":"Telecom","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4900000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.","how_it_worked":"The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.","lessons":"Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.","confidence":"Confirmed","sources":[{"title":"Charter Communications data breach affects 4.9 million accounts","url":"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/","publisher":"BleepingComputer"},{"title":"Charter confirms Spectrum data breach after ShinyHunters claims hack","url":"https://www.foxnews.com/tech/charter-breach-warning-customers-know","publisher":"Fox News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-charter-communications-breach-of-4-9m-accounts-began-with-an-entra-vishi"},{"slug":"2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account","title":"Crunchyroll support tickets stolen via compromised BPO agent SSO account","date":"2026-03-12","date_precision":"day","year":2026,"victim_org":"Crunchyroll","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.","how_it_worked":"The weak point was not Crunchyroll's own workforce but a third-party contact centre agent with standing access to the streaming service's ticketing system. The attacker said malware on the agent's machine captured their credentials, then used the resulting Okta session to authenticate into Zendesk as a legitimate support operator. Because helpdesk agents routinely open and read large numbers of tickets, bulk retrieval did not stand out immediately, and roughly 24 hours passed before access was cut. Some payment card details were exposed only where customers had typed them into tickets.","lessons":"Outsourced agent identities need the same phishing-resistant MFA and device-health enforcement as employees, plus per-agent ticket access rate limits so no single account can enumerate the whole queue.","confidence":"Reported","sources":[{"title":"Crunchyroll probes breach after hacker claims to steal 6.8M users' data","url":"https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/amp/","publisher":"BleepingComputer"},{"title":"1.2 million Crunchyroll users confirmed impacted by data breach","url":"https://cyberinsider.com/1-2-million-crunchyroll-users-confirmed-impacted-by-data-breach/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"},{"title":"Identity protection firm Aura breached in vishing attack; ~900,000 records taken","date":"2026-03","date_precision":"month","victim_org":"Aura","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call that compromised the employee account.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":900000,"threat_actor":"ShinyHunters","summary":"Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.","how_it_worked":"The attackers targeted a single employee account with a voice phishing call, the same pattern the group used against Okta and Microsoft Entra single sign-on accounts throughout early 2026: pose as internal IT, offer help with an authentication task, and capture credentials and a one-time code through a lookalike login page. The compromised account was live for only about an hour, but that was long enough to export a marketing database wholesale. The stolen combination of name, address, phone and email is itself high-quality raw material for follow-on phishing and vishing.","lessons":"Short-lived access still enables bulk export; rate-limiting and alerting on large database exports would have caught the theft inside the one-hour window.","confidence":"Reported","sources":[{"title":"Aura data breach","url":"https://en.wikipedia.org/wiki/Aura_data_breach","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-identity-protection-firm-aura-breached-in-vishing-attack-900-000-records"},{"slug":"2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a","title":"Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Organisations across education, healthcare, finance, nonprofit and government","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","QR Code Phishing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Tycoon2FA phishing-as-a-service operators","summary":"Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.","how_it_worked":"Tycoon2FA industrialised adversary-in-the-middle credential theft for buyers with no technical skill. A subscriber picked a template and sent lures; when a recipient entered their password on the fake sign-in page, the platform relayed it live to the real Microsoft or Google service and captured the returned session cookie along with whatever MFA the user completed. That defeated SMS codes, one-time passcodes and push approvals alike, because the victim genuinely authenticated, just into the attacker's session. Domains were rotated every 24 to 72 hours on cheap generic TLDs using readable subdomains such as cloud, desktop and sharepoint.","lessons":"Only origin-bound credentials such as FIDO2 passkeys break the relay; conditional access requiring a compliant managed device makes a stolen cookie useless from attacker infrastructure.","confidence":"Confirmed","sources":[{"title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale","url":"https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/","publisher":"Microsoft Security Blog"},{"title":"Europol, Microsoft, TrendAI and Collaborators Halt Tycoon 2FA Operations","url":"https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html","publisher":"Trend Micro"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a"},{"slug":"2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors","title":"Contagious Interview: fake developer job interviews deliver backdoors","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Software developers at enterprise solution, media and communications firms","sector":"Technology","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Cryptocurrency Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.","how_it_worked":"The pretext is a career opportunity, and the trust signal is the ordinary shape of a developer hiring process: a recruiter approach, a screening call, then a take-home coding exercise. The malicious step is disguised as the exercise itself, because cloning a repository and running it locally is exactly what a candidate is expected to do. Payloads fire automatically from task configuration files when the repository is opened in Visual Studio Code, so no obviously suspicious action is needed. The malware then harvests API tokens, cloud credentials, cryptocurrency wallets, password manager databases, private keys, source code and clipboard contents.","lessons":"Candidate exercises and any unvetted repository should be run only in a disposable sandbox with no access to corporate credentials, wallets or password vaults.","confidence":"Confirmed","sources":[{"title":"Contagious Interview: Malware delivered through fake developer job interviews","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"},{"slug":"2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo","title":"Figure Technology loses ~967,000 customer records after employee falls for SSO vishing","date":"2026-02-19","date_precision":"day","year":2026,"victim_org":"Figure Technology Solutions","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":967000,"threat_actor":"ShinyHunters","summary":"Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.","how_it_worked":"The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.","lessons":"Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.","confidence":"Reported","sources":[{"title":"Nearly 1 Million User Records Compromised in Figure Data Breach","url":"https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/","publisher":"SecurityWeek"},{"title":"Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters","url":"https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/","publisher":"Cybernews"},{"title":"Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People","url":"https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"},{"slug":"2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod","title":"CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes","date":"2026-02-13","date_precision":"day","year":2026,"victim_org":"CarGurus","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.","how_it_worked":"Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.","lessons":"One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.","confidence":"Reported","sources":[{"title":"CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach","url":"https://news.dealershipguy.com/p/cargurus-probes-cyberattack-shinyhunters-theft-1-7-million-records-data-breach-2026-02-23","publisher":"Dealership Guy News"},{"title":"CarGurus Reported Data Breach","url":"https://complyauto.com/cargurus-reported-data-breach/","publisher":"ComplyAuto"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-cargurus-hit-by-vishing-that-harvested-okta-microsoft-and-google-sso-cod"},{"title":"Optimizely confirms data breach after vishing attack on employees","date":"2026-02-11","date_precision":"day","victim_org":"Optimizely","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"Optimizely did not state whether synthetic voice was used on the calls.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed; the company said there was no disruption to business operations.","records_affected":null,"threat_actor":"Likely ShinyHunters-affiliated","summary":"Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.","how_it_worked":"Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.","lessons":"Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.","confidence":"Confirmed","sources":[{"title":"Ad tech firm Optimizely confirms data breach after vishing attack","url":"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-optimizely-confirms-data-breach-after-vishing-attack-on-employees"},{"slug":"2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts","title":"Hims & Hers support tickets stolen through compromised Okta SSO accounts","date":"2026-02-04","date_precision":"day","year":2026,"victim_org":"Hims & Hers Health","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.","how_it_worked":"Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.","lessons":"Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.","confidence":"Confirmed","sources":[{"title":"Hims & Hers warns of data breach after Zendesk support ticket breach","url":"https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/","publisher":"BleepingComputer"},{"title":"Telehealth Giant Hims & Hers Announces Data Breach","url":"https://www.hipaajournal.com/him-hers-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts"},{"title":"Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware","date":"2026-02","date_precision":"month","victim_org":"An unnamed cryptocurrency company executive","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Deepfake Video Call","secondary_vectors":["Tech Support Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.","records_affected":null,"threat_actor":"UNC1069 (DPRK), tracked by Mandiant since 2018","summary":"Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.","how_it_worked":"Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.","lessons":"No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.","confidence":"Confirmed","sources":[{"title":"North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam","url":"https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix","publisher":"The Record (Recorded Future News)"},{"title":"North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms","url":"https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"},{"title":"BlackFile extortion gang runs vishing campaign against retail and hospitality","date":"2026-02","date_precision":"month","victim_org":"Multiple retail and hospitality organisations (unnamed)","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.","records_affected":null,"threat_actor":"BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)","summary":"BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.","how_it_worked":"Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.","lessons":"Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.","confidence":"Confirmed","sources":[{"title":"New BlackFile extortion gang targets retail and hospitality orgs","url":"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"},{"title":"STAC4749 Teams vishing campaign led to Chaos ransomware in North America","date":"2026-02","date_precision":"month","victim_org":"Dozens of North American organisations (unnamed)","sector":"Manufacturing","country":"Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No ransom or loss totals were disclosed.","records_affected":null,"threat_actor":"STAC4749, deploying Chaos ransomware","summary":"Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.","how_it_worked":"The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.","lessons":"Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.","confidence":"Confirmed","sources":[{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","url":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america"},{"slug":"2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli","title":"Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido (and subsidiary Ben)","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.","how_it_worked":"Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.","lessons":"Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.","confidence":"Reported","sources":[{"title":"Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling","url":"https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling","publisher":"NOS"},{"title":"Major hack of Dutch telco Odido was a classic case of social engineering","url":"https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/","publisher":"Techzine"},{"title":"Odido data breach exposes personal info of 6.2 million customers","url":"https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"},{"slug":"2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo","title":"Odido: IT impersonation calls and MFA approval requests expose 6.2M customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.","how_it_worked":"The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.","lessons":"Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.","confidence":"Confirmed","sources":[{"title":"Odido hackers pretended to be an IT employee to breach corporate system","url":"https://cybernews.com/security/odido-hackers-phishing-attack/","publisher":"Cybernews"},{"title":"Odido Salesforce Hack: Up to 6M Customers' Data at Risk","url":"https://www.salesforceben.com/odido-salesforce-hack-up-to-6m-customers-data-at-risk/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-it-impersonation-calls-and-mfa-approval-requests-expose-6-2m-custo"},{"slug":"2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec","title":"Dickinson Public Schools loses $4.92M to vendor-impersonation BEC","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Dickinson Public Schools","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4920000,"loss_kind":"direct_loss","loss_note":"USD; two payments diverted from the district's restricted building fund. No recovery reported at time of disclosure.","records_affected":null,"threat_actor":null,"summary":"Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.","how_it_worked":"The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.","lessons":"Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.","confidence":"Confirmed","sources":[{"title":"North Dakota School District Loses $4.9M to Email Scam","url":"https://www.govtech.com/education/k-12/north-dakota-school-district-loses-4-9m-to-email-scam","publisher":"Government Technology"},{"title":"North Dakota school district loses nearly $5 million in sophisticated email scam","url":"https://www.valleynewslive.com/2026/02/11/north-dakota-school-district-loses-nearly-5-million-sophisticated-email-scam/","publisher":"Valley News Live"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"},{"slug":"2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill","title":"Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records","date":"2026-01-29","date_precision":"day","year":2026,"victim_org":"Match Group (Match, Hinge, OkCupid)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":10000000,"threat_actor":"ShinyHunters","summary":"ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.","how_it_worked":"The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.","lessons":"Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.","confidence":"Reported","sources":[{"title":"Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match","url":"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/","publisher":"BleepingComputer"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-match-group-sso-phished-via-lookalike-domain-shinyhunters-claims-10-mill"},{"slug":"2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient","title":"Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients","date":"2026-01-20","date_precision":"day","year":2026,"victim_org":"Xsolis","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1396519,"threat_actor":null,"summary":"Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.","how_it_worked":"Xsolis described the entry point as a targeted phishing attack against its own staff rather than an exploited vulnerability. The attacker reached an employee mailbox or account and, over roughly a two-day window before detection on 22 January, accessed and copied files holding protected health information belonging to patients of Xsolis's health system and payer customers. The company has not published the pretext used, the sender identity spoofed, or whether MFA was bypassed.","lessons":"Phishing-resistant MFA on email and any admin console, plus data-loss monitoring on bulk file access to PHI repositories, is what converts a successful lure into a contained account compromise.","confidence":"Confirmed","sources":[{"title":"Phishing attack on healthcare firm Xsolis impacts 1.4 million people","url":"https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/","publisher":"Help Net Security"},{"title":"Xsolis Data Breach Affects 1.4M Individuals","url":"https://www.hipaajournal.com/xsolis-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient"},{"slug":"2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages","title":"Starbucks employee data stolen via cloned Partner Central login pages","date":"2026-01-19","date_precision":"day","year":2026,"victim_org":"Starbucks","sector":"Hospitality","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":900,"threat_actor":null,"summary":"Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.","how_it_worked":"Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.","lessons":"Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.","confidence":"Confirmed","sources":[{"title":"Starbucks Data Breach Impacts Employees","url":"https://www.securityweek.com/starbucks-data-breach-impacts-employees/","publisher":"SecurityWeek"},{"title":"Starbucks suffers data breach via employee portal clone sites","url":"https://cyberinsider.com/starbucks-suffers-data-breach-via-employee-portal-clone-sites/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"},{"slug":"2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering","title":"$282M in Bitcoin and Litecoin stolen from a holder via social engineering","date":"2026-01-10","date_precision":"day","year":2026,"victim_org":"Unnamed cryptocurrency holder","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Tech Support Scam","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Cryptocurrency Theft"],"loss_usd":282000000,"loss_kind":"direct_loss","loss_note":"USD value at time of theft of 1,459 BTC and 2.05 million LTC; no recovery reported.","records_affected":null,"threat_actor":null,"summary":"On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.","how_it_worked":"Reporting characterised the theft as a support-impersonation social engineering attack of the kind that has become the dominant loss driver in crypto: the attacker poses as an employee of a wallet or exchange provider, builds trust with the holder, and persuades them to hand over a seed phrase, sign a malicious transaction or surrender login details. The theft came days after hardware-wallet maker Ledger disclosed a breach exposing customer names and contact details, the kind of list that makes such calls credible. The victim has not been identified and the exact pretext was not published.","lessons":"No legitimate wallet or exchange support agent ever needs a seed phrase or a remote-access session; large holdings belong behind multi-signature approval with an out-of-band co-signer.","confidence":"Reported","sources":[{"title":"Hacker steals $282 million crypto from a victim in social-engineering attack","url":"https://www.coindesk.com/business/2026/01/16/hacker-steals-usd282-milion-in-hardware-wallet-social-engineering-attack","publisher":"CoinDesk"},{"title":"Crypto User Loses $282 Million in Bitcoin and Litecoin to Social Engineering Scam","url":"https://bravenewcoin.com/insights/crypto-user-loses-282-million-in-bitcoin-and-litecoin-to-social-engineering-scam","publisher":"Brave New Coin"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-282m-in-bitcoin-and-litecoin-stolen-from-a-holder-via-social-engineering"},{"title":"Betterment named among victims of the January 2026 real-time vishing wave","date":"2026-01-09","date_precision":"day","victim_org":"Betterment","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"No synthetic voice was reported for this campaign; the calls were described as live operators.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.","how_it_worked":"The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.","lessons":"Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-betterment-named-among-victims-of-the-january-2026-real-time-vishing-wav"},{"slug":"2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov","title":"FBI FLASH warns of Kimsuky QR-code spear phishing on think tanks and government","date":"2026-01-08","date_precision":"day","year":2026,"victim_org":"Think tanks, academic institutions and government entities","sector":"Government","country":"United States","primary_vector":"QR Code Phishing","secondary_vectors":["Spear Phishing (Email)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Kimsuky (APT43)","summary":"The FBI issued a FLASH alert on 8 January 2026 warning that North Korean state-sponsored group Kimsuky, also tracked as APT43, was embedding malicious QR codes in spear-phishing emails aimed at think tanks, academics and government bodies. The FBI documented incidents from May and June 2025 in which the group spoofed foreign officials and embassy staff to solicit information from think tank leaders, and redirected targets to fake Google credential pages and bogus document-sharing sites.","how_it_worked":"Kimsuky wrote emails in the voice of a diplomat or embassy employee inviting a policy expert to an event or a document review, and placed the link inside a QR code rather than as clickable text. Scanning moved the victim off the monitored corporate desktop onto a personal phone, where enterprise mail filtering and endpoint detection do not reach, and onto a spoofed Google or document-portal sign-in. The FBI noted these operations frequently end in session token theft and replay, which defeats multi-factor authentication because the attacker never faces the login challenge.","lessons":"Treat QR codes in inbound mail as untrusted links and render them for inspection at the gateway; bind sessions to device posture so a stolen token cannot be replayed from unmanaged hardware.","confidence":"Confirmed","sources":[{"title":"FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing","url":"https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html","publisher":"The Hacker News"},{"title":"FBI FLASH AC-000001-MW, 08 January 2026","url":"https://www.ic3.gov/CSA/2026/260108.pdf","publisher":"FBI / IC3"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-flash-warns-of-kimsuky-qr-code-spear-phishing-on-think-tanks-and-gov"},{"title":"SoundCloud hit as real-time vishing kits drive browsers through SSO logins","date":"2026-01","date_precision":"month","victim_org":"SoundCloud","sector":"Media & Entertainment","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"Researchers described live human callers driving phishing kits in real time; no synthetic voice was reported, though attribution of voice authenticity was not addressed.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":36000000,"threat_actor":"Actors identifying themselves as ShinyHunters","summary":"A voice-phishing campaign discovered in mid-December 2025 and running through January 2026 broke into single sign-on accounts in real time. SoundCloud was among the named victims, with roughly 36 million users affected, about 20% of its user base. Betterment was also named, with an attack dated 9 January 2026. Okta researchers identified at least two phishing kits with dedicated panels impersonating Google, Microsoft, Okta and cryptocurrency sign-in flows, and Sophos tracked around 150 malicious domains.","how_it_worked":"The operator registers a lookalike SSO domain, then calls the target and controls what the victim's browser shows page by page while the call is in progress. That synchronisation is the innovation: the caller can say exactly what will appear next, and can time the spoken instruction to the moment a genuine MFA prompt lands, so the victim approves on cue rather than reading a code aloud to a stranger. Because the operator drives a live session against the real identity provider, the stolen authentication is immediately usable.","lessons":"Origin-bound passkeys or FIDO2 keys defeat real-time relay regardless of how persuasive the caller is; number matching alone does not, because the caller narrates the number.","confidence":"Reported","sources":[{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-soundcloud-hit-as-real-time-vishing-kits-drive-browsers-through-sso-logi"},{"title":"Okta SSO accounts targeted in vishing campaign against financial firms","date":"2026-01","date_precision":"month","victim_org":"Multiple fintech, wealth management and advisory firms (unnamed)","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","MFA Fatigue / Push Bombing"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Mandiant documented this actor set using voice phishing with AI voice agents and company-branded phishing sites; AI use in individual calls was not separately confirmed.","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_note":"Ransom demands were made by email; no aggregate figure was published for this wave.","records_affected":null,"threat_actor":"ShinyHunters (signed some extortion demands)","summary":"BleepingComputer reported on January 22, 2026 that Okta had privately warned customers about a vishing campaign targeting single sign-on accounts at fintech, wealth management, financial and advisory firms. Attackers impersonated corporate IT staff and captured credentials and one-time codes in real time through adversary-in-the-middle phishing sites. Data was then stolen, particularly from Salesforce, and followed by extortion emails.","how_it_worked":"Callers posed as the target company's own IT team and offered to help the employee set up passkeys, a request timed to coincide with genuine passwordless rollouts. The employee was directed to a lookalike SSO page that relayed every keystroke to the real Okta login in real time. As the victim typed, the attacker was logging in alongside them, so the MFA challenge the victim saw on their phone matched the one they expected, and the one-time code they read out was immediately replayed. With a live session, attackers reached every application behind SSO.","lessons":"Phishing-resistant, origin-bound authentication such as FIDO2 passkeys with device trust makes real-time credential relay useless, since the credential will not release to a lookalike domain.","confidence":"Confirmed","sources":[{"title":"Okta SSO accounts targeted in vishing-based data theft attacks","url":"https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-okta-sso-accounts-targeted-in-vishing-campaign-against-financial-firms"},{"slug":"2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec","title":"Crunchbase confirms breach after ShinyHunters Okta vishing; 2 million records leaked","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Crunchbase","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":2000000,"threat_actor":"ShinyHunters","summary":"Business intelligence provider Crunchbase confirmed a data breach in late January 2026 after ShinyHunters published roughly 400 MB of compressed files it said contained more than 2 million records plus contracts and corporate documents. ShinyHunters told reporters it reached Crunchbase through voice phishing aimed at Okta single sign-on codes, the same campaign it used against Betterment and other firms. Crunchbase said it engaged outside cybersecurity experts, contacted federal law enforcement, contained the intrusion, and that no business operations were disrupted. The data was published after Crunchbase declined to pay.","how_it_worked":"The attackers called Crunchbase staff and posed as internal IT support, using a pretext about an account or access issue that required the employee to sign in while the caller stayed on the line. The employee entered Okta single sign-on credentials and read back the one-time code, which the caller replayed against the live Okta login within its validity window, producing an authenticated session under a legitimate staff identity. The trust signals abused were the routine familiarity of an IT support call and the employee's own genuine Okta prompt; the pressure was urgency framed as fixing a problem already affecting the employee's access.","lessons":"Phishing-resistant, origin-bound authenticators remove the readable one-time code these calls depend on, and a standing rule that IT never requests codes by phone gives staff a clean refusal script.","confidence":"Reported","sources":[{"title":"Crunchbase Confirms Data Breach After Hacking Claims","url":"https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/","publisher":"SecurityWeek"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","url":"https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/","publisher":"The Register"},{"title":"ShinyHunters claims 2 Million Crunchbase records; company confirms breach","url":"https://securityaffairs.com/187340/data-breach/shinyhunters-claims-2-million-crunchbase-records-company-confirms-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchbase-confirms-breach-after-shinyhunters-okta-vishing-2-million-rec"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing","title":"ShinyHunters claim 14M Panera Bread records after Entra SSO vishing","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Panera Bread","sector":"Hospitality","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters listed Panera Bread on its leak site in late January 2026, claiming roughly 14 million customer records totalling about 760MB compressed. Reporting attributes the access to a Microsoft Entra single sign-on compromise achieved through voice phishing. Panera Bread has not publicly confirmed the incident, and the claimed record count is unverified.","how_it_worked":"The crew phoned staff while impersonating IT or a trusted service provider and talked them through a fake Entra sign-in flow, capturing the password and then the MFA code or push approval needed to complete the login. Urgency around a supposed account or migration problem carried the call. With a valid Entra session the attackers reached customer data stores and exfiltrated names, email and postal addresses, phone numbers and account details before opening an extortion negotiation. Payment card data and passwords were reportedly not included.","lessons":"Number matching alone does not stop a real-time relay; phishing-resistant MFA plus a strict rule that IT never asks for codes by phone is the control that holds.","confidence":"Alleged","sources":[{"title":"ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach","url":"https://www.techrepublic.com/article/news-panera-bread-data-breach/","publisher":"TechRepublic"},{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-claim-14m-panera-bread-records-after-entra-sso-vishing"},{"slug":"2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands","title":"CrashFix: fake ad blocker crashes browsers to trigger ClickFix commands","date":"2026-01","date_precision":"month","year":2026,"victim_org":"Users of malicious Chrome extension impersonating uBlock Origin Lite","sector":"Technology","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Threat Intelligence documented a ClickFix variant it named CrashFix, identified in January 2026. Malicious search ads for ad blockers led users to a convincing fake Chrome Web Store page hosting an extension impersonating uBlock Origin Lite. After a delay the extension deliberately crashed the browser and displayed a fake security warning, tricking users into running attacker-supplied commands that installed the Python-based ModeloRAT.","how_it_worked":"The lure inverted the usual ClickFix pattern. Rather than a fake CAPTCHA, the attackers manufactured a real, visible fault: the installed extension broke the victim's browser, then presented a repair prompt that looked like a security notice. Because the user had genuinely just experienced a crash, the instruction to paste a command into a terminal read as a fix rather than an attack. Operators showed selectivity, deploying extra backdoors only where the compromised host was domain-joined, indicating they were filtering for enterprise environments worth returning to.","lessons":"Blocking clipboard-to-shell execution patterns and restricting extension installation to an allowlist stops the paste step, which is the only point where the user's action is required.","confidence":"Confirmed","sources":[{"title":"New ClickFix variant 'CrashFix' deploying Python Remote Access Trojan","url":"https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crashfix-fake-ad-blocker-crashes-browsers-to-trigger-clickfix-commands"},{"title":"Manhattan indicts SIM-swap ring that used AT&T and T-Mobile store insiders","date":"2025-11-20","date_precision":"day","victim_org":"AT&T and T-Mobile customers, including four Manhattan residents","sector":"Telecom","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":["SIM Swap"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":435000,"loss_note":"$435,000 stolen from four Manhattan residents, with additional victims identified in other jurisdictions. The indictment covers conduct from October 2021 through July 2022.","records_affected":null,"threat_actor":"Eleven indicted defendants, including AT&T and T-Mobile retail employees Jadakiss Bonilla, Kendrah Vasquez, Amanda Rodado and Jared Moreland","summary":"Manhattan District Attorney Alvin Bragg announced an eleven-defendant indictment on November 20, 2025 against a SIM-swapping and identity theft ring that included four AT&T and T-Mobile retail employees. Between October 2021 and July 2022 the ring stole $435,000 from four Manhattan residents, with further victims elsewhere. The insiders used their employee access to perform the swaps in exchange for payment, and in some cases logged in with coworkers' credentials to obscure their involvement.","how_it_worked":"Ringleaders identified targets and passed their account details to retail store employees on the inside. Rather than talk a rep into a fraudulent swap, the crew paid the reps directly: the store workers used their own authorised access to customer account information to execute the SIM swaps, and in some cases signed in under a coworker's credentials so the audit trail pointed at the wrong person. Once a victim's number was ported to a device the ring controlled, incoming SMS one-time passcodes and password-reset links let them take over bank and payment accounts and move money out through wire transfers and peer-to-peer payment apps before the victim understood why their handset had lost service.","lessons":"Carriers need per-employee SIM-change rate monitoring, mandatory customer confirmation on a second channel, and credential controls that make shared or borrowed logins impossible, since insider swaps look identical to legitimate ones.","confidence":"Alleged","sources":[{"title":"D.A. Bragg Announces Indictment Of SIM-Swapping ID Theft Ring, Including AT&T And T-Mobile Employees","url":"https://manhattanda.org/d-a-bragg-announces-indictment-of-sim-swapping-id-theft-ring-including-att-and-t-mobile-employees/","publisher":"Manhattan District Attorney's Office"}],"entry_type":"campaign","slug":"2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-manhattan-indicts-sim-swap-ring-that-used-at-t-and-t-mobile-store-inside"},{"slug":"2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack","title":"Harvard alumni and donor data stolen in phone-based phishing attack","date":"2025-11-18","date_precision":"day","year":2025,"victim_org":"Harvard University","sector":"Education","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.","how_it_worked":"The attacker telephoned someone with access to the advancement systems and, over the call, obtained what was needed to log in as that person. Harvard characterised the incident explicitly as a phone-based phishing attack on its Alumni Affairs and Development environment. Advancement offices are attractive because a small number of staff hold broad read access to donor records, and because fundraising work involves frequent legitimate calls from unfamiliar people, which normalises an unexpected voice asking for help. Once authenticated as the employee, the intruder queried and exported donor and alumni records before the university revoked the access and brought in outside responders.","lessons":"Phishing-resistant MFA on advancement systems and a standing rule that credentials or one-time codes are never handled over the phone would have blocked the login.","confidence":"Confirmed","sources":[{"title":"Harvard University discloses data breach affecting alumni, donors","url":"https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/","publisher":"BleepingComputer"},{"title":"Harvard University reports data breach following voice phishing incident","url":"https://www.paubox.com/blog/harvard-university-reports-data-breach-following-voice-phishing-incident","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-harvard-alumni-and-donor-data-stolen-in-phone-based-phishing-attack"}]}