{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T06:29:14.497Z","total":25,"returned":25,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware","date":"2026-02","date_precision":"month","victim_org":"An unnamed cryptocurrency company executive","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Deepfake Video Call","secondary_vectors":["Tech Support Scam","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No loss figure was published; Mandiant assessed the actors were positioning for cryptocurrency theft and further social engineering using the compromised identity.","records_affected":null,"threat_actor":"UNC1069 (DPRK), tracked by Mandiant since 2018","summary":"Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.","how_it_worked":"Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.","lessons":"No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.","confidence":"Confirmed","sources":[{"title":"North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam","url":"https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix","publisher":"The Record (Recorded Future News)"},{"title":"North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms","url":"https://www.infosecurity-magazine.com/news/north-korea-hackers-deepfake-crypto/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-deepfake-of-a-crypto-ceo-on-a-fake-zoom-call-delivered-macos-malware"},{"slug":"2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se","title":"Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service","date":"2025-09-16","date_precision":"day","year":2025,"victim_org":"Microsoft 365 customers in 94 countries, including US healthcare organisations","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000,"threat_actor":"Storm-2246 / RaccoonO365 (Nigeria-based operator named by Microsoft)","summary":"Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.","how_it_worked":"Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.","lessons":"Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.","confidence":"Confirmed","sources":[{"title":"Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service","url":"https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/","publisher":"Microsoft On the Issues"},{"title":"Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service","url":"https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"},{"title":"North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs","date":"2025-08","date_precision":"month","victim_org":"US Fortune 500 technology companies employing fraudulent remote workers","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.","outcomes":["Insider Access","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Salaries paid to fraudulent workers fund DPRK weapons programmes; amounts not quantified in this report","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.","how_it_worked":"The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.","lessons":"Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"},{"title":"Claude Code used to automate extortion of at least 17 organisations","date":"2025-08","date_precision":"month","victim_org":"At least 17 organisations across healthcare, emergency services, government and religious institutions","sector":"Other","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported a single actor used Claude Code to automate reconnaissance and credential harvesting, decide what data to steal, analyse victims' finances to set ransom amounts, and generate psychologically targeted extortion notes and on-screen ransom displays.","outcomes":["Extortion","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"Ransom demands sometimes exceeded US$500,000; amounts actually paid were not disclosed","records_affected":null,"threat_actor":"Tracked by Anthropic as a single cybercriminal actor (reported as GTG-2002)","summary":"Anthropic's August 2025 threat intelligence report described a cybercriminal who used Claude Code to conduct data extortion against at least 17 organisations in healthcare, emergency services, government and religious institutions within a single month. Rather than encrypting systems, the actor exfiltrated data and threatened public exposure, with ransom demands sometimes exceeding US$500,000. Anthropic said the AI was used across the operation, including analysing stolen financial data to calibrate demands and drafting extortion notes tailored to each victim's pressure points.","how_it_worked":"The coercive element was the extortion communication itself, which the model tailored to each organisation using the stolen data. Ransom notes referenced what had been taken and what its exposure would mean for that specific victim, whether patient confidentiality, emergency service continuity or congregational trust, so the threat was concrete rather than generic. Financial records were analysed to set a demand the victim could plausibly pay, which increases compliance relative to arbitrary figures. Alarming messages displayed on victims' own machines added immediacy, and the exfiltration-only model meant victims could not restore from backup to escape the leak threat.","lessons":"Preventing exfiltration through egress monitoring and least-privilege data access matters more than backup strategy against leak-only extortion, and incident response plans should assume ransom demands will be precisely tuned to the organisation's finances.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-claude-code-used-to-automate-extortion-of-at-least-17-organisations"},{"title":"BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware","date":"2025-06","date_precision":"month","victim_org":"Employee of a cryptocurrency foundation (Web3 sector)","sector":"Cryptocurrency","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.","outcomes":["Cryptocurrency Theft","Credential Theft","Espionage"],"loss_usd":null,"loss_note":"Amount stolen not disclosed","records_affected":null,"threat_actor":"BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)","summary":"In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.","how_it_worked":"The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.","lessons":"Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.","confidence":"Confirmed","sources":[{"title":"North Korean hackers deepfake execs in Zoom call to spread Mac malware","url":"https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/","publisher":"BleepingComputer"},{"title":"BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware","url":"https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"},{"title":"Impostor uses AI voice of Secretary of State Marco Rubio to contact foreign ministers","date":"2025-06","date_precision":"month","victim_org":"US State Department; three foreign ministers, a US governor and a member of Congress","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"A State Department cable described an impostor using AI-generated voice and text to mimic Secretary of State Marco Rubio, leaving Signal voicemails for at least two targets.","outcomes":["Attempt Blocked","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In mid-June 2025 an unidentified impostor created a Signal account displaying the name marco.rubio@state.gov and contacted at least five people, including three foreign ministers, a US governor and a member of Congress, using AI-generated voice messages and texts mimicking Secretary of State Marco Rubio. A State Department cable dated 3 July 2025 described the attempts, which officials characterised as unsuccessful and not technically sophisticated. Investigators assessed the likely goal was to gain access to information or accounts held by the targets.","how_it_worked":"The impostor exploited the fact that senior diplomats routinely use Signal for informal contact, so a message from an account labelled with the Secretary's official email address fit the expected pattern. Rather than opening with a request, the actor left short voicemails in a cloned voice and sent texts inviting the target to continue the conversation on Signal, which builds familiarity before anything is asked. The trust signal was the combination of a recognisable voice and a display name resembling a state.gov address, neither of which is authenticated by the platform. Targets who engaged would then have been positioned for requests for information or for account access.","lessons":"Display names and voices are not identity: diplomatic contact should be initiated or confirmed through embassy and ministry channels, and platforms used for official business need verified organisational identity.","confidence":"Confirmed","sources":[{"title":"Imposter used AI to pose as Marco Rubio and contact foreign ministers","url":"https://feeds.bbci.co.uk/news/articles/crrqkyyjewno","publisher":"BBC News"},{"title":"A Marco Rubio impostor is using AI voice to call high-level officials","url":"https://www.washingtonpost.com/national-security/2025/07/08/marco-rubio-ai-imposter-signal/","publisher":"The Washington Post"}],"entry_type":"incident","slug":"2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-impostor-uses-ai-voice-of-secretary-of-state-marco-rubio-to-contact-fore"},{"title":"FBI warns of AI voice-cloning campaign impersonating senior US officials","date":"2025-05-15","date_precision":"day","victim_org":"Current and former senior US federal and state officials and their contacts","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The FBI stated that malicious actors were sending AI-generated voice messages, alongside text messages, that purported to come from senior US officials.","outcomes":["Credential Theft","Identity Theft","Espionage"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 15 May 2025 the FBI's Internet Crime Complaint Center published a public service announcement describing a campaign running since April 2025 in which malicious actors impersonated senior US federal and state officials using text messages and AI-generated voice messages. The FBI said the aim was to build rapport with contacts of those officials, then move them to attacker-controlled platforms and compromise their personal or official accounts. Compromised accounts were then used to reach further officials and to harvest contact details for follow-on impersonation and fraud. The FBI reissued an updated warning in December 2025.","how_it_worked":"The campaign traded on the recipient's relationship with a named senior official rather than on any technical exploit. An initial text or voicemail in a cloned voice established that the official was reaching out personally, which for a colleague or former colleague is unremarkable. Once a reply came, targets were invited to continue on a separate messaging platform, a request that reads as security-conscious in government circles, and the link supplied there led to a credential-harvesting page or a device-linking flow. Each successful compromise fed the next round, since messages arriving from a genuinely compromised official account carry far more weight than any spoof.","lessons":"Officials and their contacts should verify unexpected outreach through a separately known number or channel, and adopt phishing-resistant authentication on personal accounts, which are typically the weak point rather than official systems.","confidence":"Confirmed","sources":[{"title":"Senior US Officials Impersonated in Malicious Messaging Campaign (PSA250515)","url":"https://www.ic3.gov/PSA/2025/PSA250515","publisher":"FBI Internet Crime Complaint Center"},{"title":"FBI warns senior US officials are being impersonated using texts, AI-based voice cloning","url":"https://www.cybersecuritydive.com/news/fbi-us-officials-impersonated-text-ai-voice/748334/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","slug":"2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-fbi-warns-of-ai-voice-cloning-campaign-impersonating-senior-us-officials"},{"title":"North Korean operatives adopt real-time deepfakes to pass remote job interviews","date":"2025-04","date_precision":"month","victim_org":"Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Deepfake Video Call","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.","how_it_worked":"The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.","lessons":"Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.","confidence":"Confirmed","sources":[{"title":"False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation","url":"https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/","publisher":"Palo Alto Networks Unit 42"},{"title":"North Korean Operatives Use Deepfakes in IT Job Interviews","url":"https://www.darkreading.com/remote-workforce/north-korean-operatives-deepfakes-it-job-interviews","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int"},{"title":"Singapore firm's finance director wires US$499,000 after deepfake Zoom with fake CFO","date":"2025-03","date_precision":"month","victim_org":"Unnamed multinational firm, Singapore office","sector":"Other","country":"Singapore","primary_vector":"Deepfake Video Call","secondary_vectors":["Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Singapore Police said deepfake technology was used to render the company's chief financial officer, chief executive and other officials during a Zoom video conference.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":499000,"loss_note":"Over US$499,000 transferred; funds recovered by Singapore and Hong Kong police within days","records_affected":null,"threat_actor":null,"summary":"On 24 March 2025 the finance director of a multinational firm's Singapore office received a WhatsApp message purporting to be from the company's chief financial officer, inviting him to a Zoom conference about a regional restructuring. On the call, deepfaked versions of the CFO, CEO and other executives instructed him to make a transfer, and a supposed lawyer had him sign a non-disclosure agreement. He transferred over US$499,000 and became suspicious only when asked for a further US$1.4 million. HSBC and the Singapore Police Anti-Scam Centre, working with Hong Kong's Anti-Deception Coordination Centre, recovered the funds by 28 March.","how_it_worked":"The approach opened on WhatsApp, a channel where an executive contact request feels informal but not alarming, and offered a business rationale, a confidential regional restructuring, that justified both secrecy and an unusual payment. The video conference supplied the decisive trust signal by putting the target in a room with the two most senior people in his reporting line plus other familiar faces. An outside lawyer and an NDA added procedural theatre that made the transaction look governed rather than improvised, while also formalising the instruction not to tell colleagues. Compliance was easy because the finance director was doing precisely his job, executing a payment approved by the CFO.","lessons":"Payments authorised on a video call should still require callback verification to a directory-listed number and dual approval; the fast bank and police escalation here is what made recovery possible.","confidence":"Confirmed","sources":[{"title":"Singapore firm nearly lost $500,000 after deepfake video scam: police","url":"https://www.hcamag.com/asia/specialisation/hr-technology/singapore-firm-nearly-lost-500000-after-deepfake-video-scam-police/531450","publisher":"Human Resources Director Asia"}],"entry_type":"incident","slug":"2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-singapore-firm-s-finance-director-wires-us-499-000-after-deepfake-zoom-w"},{"title":"AI voice clone of Italy's defence minister used to extract EUR 1M from a businessman","date":"2025-02","date_precision":"month","victim_org":"Massimo Moratti and other Italian business leaders","sector":"Consumer","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Fraudsters used an AI-generated clone of Defence Minister Guido Crosetto's voice on phone calls, alongside accomplices posing as ministry staff.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":1000000,"loss_note":"Approx EUR 1 million paid by Massimo Moratti in two transfers; funds were traced to a Dutch bank account and frozen","records_affected":null,"threat_actor":null,"summary":"In February 2025 fraudsters using an AI clone of Italian Defence Minister Guido Crosetto's voice contacted a series of prominent Italian business figures, reportedly including Giorgio Armani, Patrizio Bertelli, Marco Tronchetti Provera, Diego Della Valle and members of the Beretta and Aleotti families. The callers said the government urgently needed funds to ransom Italian journalists held in the Middle East and promised reimbursement by the Bank of Italy. Only former Inter Milan owner Massimo Moratti paid, transferring about EUR 1 million; Italian police later traced and froze the money in a Dutch account. Crosetto publicly disclosed the scheme.","how_it_worked":"The pretext was engineered for the target audience: a matter of national interest, secret by nature, in which wealthy patriots were being asked to advance funds the state would repay. Calls came first from someone presenting as a ministry official, which set the frame, and then from the minister himself in a recognisable synthetic voice, an escalation that made the request feel personally sanctioned at the highest level. The promise of Bank of Italy reimbursement reduced the perceived risk to a short-term loan. Secrecy and the lives of hostages supplied both urgency and a reason not to consult advisers, and payment was directed to a foreign account presented as an operational necessity.","lessons":"Government officials do not solicit private funds by phone; any such request should be verified with the ministry's published switchboard before any transfer, and banks should challenge large first-time international transfers from personal accounts.","confidence":"Reported","sources":[{"title":"Police recover EUR 1M sent to deepfake scammers impersonating Italy's Defense Minister","url":"https://cybernews.com/cybercrime/deepfake-scammers-dupe-italian-buinessman-1-million-police-recover-funds/","publisher":"Cybernews"},{"title":"Fraudsters Allegedly Use AI-Generated Voice of Italian Defense Minister Guido Crosetto to Scam Business Leaders","url":"https://incidentdatabase.ai/cite/927/","publisher":"AI Incident Database"},{"title":"Guido Crosetto","url":"https://en.wikipedia.org/wiki/Guido_Crosetto","publisher":"Wikipedia"}],"entry_type":"incident","slug":"2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-ai-voice-clone-of-italy-s-defence-minister-used-to-extract-eur-1m-from-a"},{"title":"Hong Kong arrests 31 in second deepfake romance fraud ring targeting Southeast Asia","date":"2025-01","date_precision":"month","victim_org":"Victims in Taiwan, Singapore and Malaysia","sector":"Consumer","country":"Hong Kong","primary_vector":"Romance / Investment Scam","secondary_vectors":["Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The syndicate combined photographs of attractive people scraped online with deepfake technology to create and sustain fictitious personas on dating apps.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":4370000,"loss_note":"Over HK$34 million, approx US$4.37 million","records_affected":null,"threat_actor":"Hong Kong-based fraud syndicate operating from Kowloon Bay","summary":"Hong Kong police arrested 31 people on 2 and 3 January 2025 over a deepfake-enabled romance and investment fraud syndicate that operated from two premises in Kowloon Bay and took more than HK$34 million (about US$4.37 million) from victims in Taiwan, Singapore and Malaysia. Members were trained to approach targets on dating apps using online photographs of attractive people combined with deepfake technology. It was the second major deepfake fraud bust by Hong Kong authorities in three months.","how_it_worked":"Recruits worked from scripts and training materials, opening on dating apps with fabricated female personas assembled from scraped photographs and rendered live with face-swapping software when a target asked for video proof. The romance was cultivated over weeks so that the eventual investment pitch arrived from someone the victim believed they knew personally rather than from a stranger. Targets in neighbouring jurisdictions were chosen partly because cross-border reporting and recovery are slower. Funds were routed into cryptocurrency, which made reversal difficult once the persona went dark.","lessons":"Cross-border anti-fraud coordination and dating-platform detection of face-swap artefacts on live video are the two controls that materially shrink this model.","confidence":"Confirmed","sources":[{"title":"Hong Kong police arrest 31 over deepfakes used to scam victims in Singapore, Malaysia","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3293476/hong-kong-police-arrest-31-who-used-deepfakes-scam-victims-singapore-malaysia","publisher":"South China Morning Post"}],"entry_type":"campaign","slug":"2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou","year":2025,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-hong-kong-arrests-31-in-second-deepfake-romance-fraud-ring-targeting-sou"},{"title":"FBI warns criminals are using generative AI to scale voice-clone and identity fraud","date":"2024-12-03","date_precision":"day","victim_org":"US consumers, including seniors targeted by family-emergency voice clones (multi-victim campaign)","sector":"Consumer","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Deepfake Video Call","Romance / Investment Scam","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The entire advisory concerns criminal use of generative AI: AI text for phishing and fake profiles, AI images for fake IDs and personas, voice cloning to impersonate relatives and account holders, and real-time video synthesis to impersonate executives and authorities.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Extortion","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"The advisory does not publish an aggregate loss figure for AI-enabled fraud.","records_affected":null,"threat_actor":null,"summary":"On 3 December 2024 the FBI's Internet Crime Complaint Center published an advisory titled Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. It documents AI-generated text used for phishing, fake social media profiles and fraudulent investment sites; AI-generated images used for profile photos, fabricated identification documents and disaster imagery for fake charity appeals; and voice and video synthesis used to impersonate relatives, account holders and executives.","how_it_worked":"Voice cloning is the pivotal technique for consumer harm. A short sample of a person's speech, readily available from social media video, is enough to synthesise a distressed relative calling to say they have been in an accident or arrested and need money immediately. The lever is the recognisable voice of a loved one under duress, which suppresses verification instincts far more effectively than any script. The same technology is used to satisfy bank voice authentication as an account holder, and real-time video synthesis extends it to live calls impersonating executives or providing proof of legitimacy to a romance or investment target. AI translation also strips the grammatical errors that once exposed foreign operators.","lessons":"The FBI's own recommendation is the practical control: agree a family or organisational verification code word in advance, and independently call back on a known number before acting on any urgent request.","confidence":"Confirmed","sources":[{"title":"Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud","url":"https://www.ic3.gov/PSA/2024/PSA241203","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-fbi-warns-criminals-are-using-generative-ai-to-scale-voice-clone-and-ide"},{"title":"Deepfake Elon Musk videos drive crypto investment scams against US consumers","date":"2024-11","date_precision":"month","victim_org":"Multiple US consumers","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Romance / Investment Scam","Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Scammers generated AI video and voice of Elon Musk pitching cryptocurrency investment schemes and distributed them as ads and posts on Facebook and TikTok.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Individual victim Heidi Swan lost over US$10,000; Deloitte estimated generative AI contributed to more than US$12 billion in US fraud losses in 2023, projected to reach US$40 billion by 2027","records_affected":null,"threat_actor":null,"summary":"By late 2024 Elon Musk had become the most frequently impersonated figure in deepfake investment fraud, with AI-generated videos of him promoting crypto schemes circulating widely on Facebook and TikTok. CBS News reported in November 2024 on Heidi Swan, a 62-year-old healthcare worker who deposited more than US$10,000 with a fake platform after seeing such a video. Researchers and Deloitte estimated that AI-generated content contributed to more than US$12 billion in US fraud losses in 2023.","how_it_worked":"The lure ran on the credibility of a single very famous investor whose views on cryptocurrency are widely known, so a video of him endorsing a platform confirmed what many targets already half-believed. Distribution through paid social advertising delivered the content inside trusted feeds and let operators target older users with disposable savings. The synthetic Musk described a limited-time opportunity with outsized returns, and the follow-through moved victims onto a bogus exchange with a support representative who coached them through funding the account. Fabricated balance growth and, in some cases, small permitted withdrawals sustained belief and encouraged larger deposits until withdrawals were blocked.","lessons":"Celebrity endorsement is never a basis for investing; platforms must verify advertiser identity and screen for synthetic likeness of public figures before ads run.","confidence":"Reported","sources":[{"title":"Deepfakes of Elon Musk are contributing to billions of dollars in fraud losses in the U.S.","url":"https://www.cbsnews.com/texas/news/deepfakes-ai-fraud-elon-musk/","publisher":"CBS News"},{"title":"Deepfake Elon Musk Videos Have Reportedly Contributed to Billions in Fraud","url":"https://incidentdatabase.ai/cite/795/","publisher":"AI Incident Database"}],"entry_type":"campaign","slug":"2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-deepfake-elon-musk-videos-drive-crypto-investment-scams-against-us-consu"},{"title":"Wiz employees sent deepfake voice messages impersonating CEO Assaf Rappaport","date":"2024-10","date_precision":"month","victim_org":"Wiz","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers built a voice clone of chief executive Assaf Rappaport from audio of a conference talk and sent synthetic voice messages to dozens of employees seeking their credentials.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Wiz chief executive Assaf Rappaport said at TechCrunch Disrupt on 28 October 2024 that roughly two weeks earlier dozens of Wiz employees had received deepfaked voice messages impersonating him, in an attempt to harvest their credentials. Employees noticed that the voice matched his stage delivery at a conference rather than how he normally speaks, and the attempt failed. Wiz traced the source audio but did not identify the attackers.","how_it_worked":"The attackers scaled a single cloned sample across dozens of recipients, betting that at least one employee would act on what sounded like a direct request from the chief executive. Voice messages rather than live calls removed the risk of interactive questions and let the same recording be reused, while the boss's authority supplied the pressure to comply quickly with a credential request. The flaw was in the source material: the only clean public audio was a conference keynote, so the clone inherited a projected, presentational tone that colleagues who hear Rappaport daily immediately found off. Employees compared notes and reported the messages rather than responding.","lessons":"Credential requests should never be actionable from a voice message, and mass-distribution patterns across many employees should trigger automated correlation and alerting.","confidence":"Confirmed","sources":[{"title":"Wiz CEO says company was targeted with deepfake attack that used his voice","url":"https://techcrunch.com/2024/10/28/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice/","publisher":"TechCrunch"},{"title":"Hackers Sent a Deepfake of Wiz CEO to Dozens of Employees","url":"https://www.entrepreneur.com/business-news/hackers-sent-a-deepfake-of-wiz-ceo-to-dozens-of-employees/482027","publisher":"Entrepreneur"}],"entry_type":"incident","slug":"2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wiz-employees-sent-deepfake-voice-messages-impersonating-ceo-assaf-rappa"},{"title":"Hong Kong police dismantle HK$360M deepfake romance and crypto investment ring","date":"2024-10","date_precision":"month","victim_org":"Men across Asia targeted through dating apps","sector":"Consumer","country":"Hong Kong","primary_vector":"Romance / Investment Scam","secondary_vectors":["Deepfake Video Call"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Syndicate members used AI face-swapping to replace their own faces with those of attractive women during video calls with victims, sustaining the fiction of a relationship.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":46000000,"loss_note":"HK$360 million, approx US$46 million","records_affected":null,"threat_actor":"Hong Kong-based syndicate with reported triad links","summary":"Hong Kong police announced on 14 October 2024 that they had arrested 27 people, aged 21 to 34, over a deepfake-assisted romance and cryptocurrency investment fraud that took about HK$360 million (US$46 million) from victims across Asia. The syndicate operated from a 4,000-square-foot industrial unit in Hung Hom, recruited digital media graduates to build fake trading platforms, and used AI face-swapping on video calls. Police seized more than 100 phones, cash, computers, luxury watches and training manuals on manipulating victims.","how_it_worked":"Operators opened on dating apps with AI-generated or face-swapped profiles of attractive women and invested weeks in ordinary conversation, building an emotional bond before money was ever mentioned. Video calls were the decisive trust signal, because a target who has seen and spoken with the person on camera discounts warnings about catfishing. Once the relationship felt real, the persona introduced a cryptocurrency trading platform run by the syndicate, showing fabricated gains and letting small withdrawals succeed so the returns appeared genuine. Pressure came from a mixture of intimacy and fear of missing out, and the training documents seized by police show the manipulation was scripted, not improvised.","lessons":"Reverse-image and liveness checks on dating profiles help, but the durable control is treating any investment platform introduced by an online romantic contact as fraudulent by default.","confidence":"Confirmed","sources":[{"title":"Hong Kong fraudsters use deepfake tech to swindle love-struck men out of HK$360 million","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3282345/hong-kong-fraudsters-use-deepfake-tech-swindle-love-struck-men-out-hk360-million","publisher":"South China Morning Post"},{"title":"Police arrest 27 for deepfake love scams totaling $360m, seizes scam-training documents","url":"https://www.thestandard.com.hk/news/article/221507/Police-arrest-27-for-deepfake-love-scams-totaling-360m-seizes-scam-training-documents","publisher":"The Standard (Hong Kong)"}],"entry_type":"campaign","slug":"2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen","year":2024,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-hong-kong-police-dismantle-hk-360m-deepfake-romance-and-crypto-investmen"},{"title":"KnowBe4 hired a North Korean fake IT worker who loaded malware on day one","date":"2024-07-15","date_precision":"day","victim_org":"KnowBe4","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The candidate's profile photo was a stock image manipulated with AI to match a stolen US identity, and KnowBe4 described the persona as an AI deepfake that held up across four video interviews.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"No loss occurred. KnowBe4 stated no data was accessed and no systems were compromised.","records_affected":null,"threat_actor":"DPRK state-sponsored fake IT worker, confirmed with Mandiant and the FBI","summary":"Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.","how_it_worked":"The persona was assembled rather than invented: a real US person's identity supplied the details that background and reference checks validated, and a stock photograph enhanced with AI supplied a face consistent enough to survive four video calls. The shipping address was not a home but an IT mule laptop farm, so the corporate workstation arrived at a location that would keep it online in the US while the operative connected in by VPN from North Korea or nearby, working nights to match US hours. Within minutes of receipt the operative used a Raspberry Pi to download malware onto the workstation and began manipulating session history files. Challenged by the SOC, they claimed router troubleshooting, then went silent.","lessons":"Live identity verification against the government ID during interviews, plus device shipment to a verified address and endpoint monitoring that treats day-one activity as high-risk, are what turned this into a contained incident rather than a breach.","confidence":"Confirmed","sources":[{"title":"How a North Korean Fake IT Worker Tried to Infiltrate Us","url":"https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us","publisher":"KnowBe4"},{"title":"KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware","url":"https://www.securityweek.com/knowbe4-hires-fake-north-korean-it-worker-catches-new-employee-planting-malware/","publisher":"SecurityWeek"},{"title":"Cyber firm KnowBe4 hired a fake IT worker from North Korea","url":"https://cyberscoop.com/cyber-firm-knowbe4-hired-a-fake-it-worker-from-north-korea/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on"},{"title":"Ferrari executive defeats deepfake of CEO Benedetto Vigna with a book question","date":"2024-07","date_precision":"month","victim_org":"Ferrari","sector":"Manufacturing","country":"Italy","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Smishing (SMS)","Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The caller used a synthetic voice that reproduced chief executive Benedetto Vigna's southern Italian accent; the target noticed slightly mechanical intonation.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In July 2024 a Ferrari executive received WhatsApp messages and then a phone call from someone impersonating chief executive Benedetto Vigna, using a convincing AI clone of his voice. The caller described a confidential acquisition requiring a currency hedge transaction. The executive became suspicious of small artefacts in the voice and asked the caller to name the title of a book Vigna had recommended days earlier; the call ended immediately. Ferrari opened an internal investigation and did not comment publicly. Bloomberg first reported the incident.","how_it_worked":"The approach started on WhatsApp from an unfamiliar number, with the mismatch explained away by the claim that the deal was so sensitive it required a separate line, a pretext that turns a red flag into evidence of importance. The escalation to a voice call added the strongest trust signal available, the chief executive's distinctive accent and manner discussing an unannounced acquisition. Confidentiality supplied the reason not to consult anyone, and a currency hedge gave a technical, plausible-sounding financial action. The executive interrupted the frame by asking a shared-knowledge question with no public answer, which the synthetic caller could not handle.","lessons":"A pre-agreed challenge based on shared private knowledge, or a codeword for executive payment requests, reliably breaks a voice clone that cannot improvise.","confidence":"Reported","sources":[{"title":"Ferrari narrowly dodges deepfake scam simulating deal-hungry CEO","url":"https://www.spokesman.com/stories/2024/jul/26/ferrari-narrowly-dodges-deepfake-scam-simulating-d/","publisher":"Bloomberg via The Spokesman-Review"},{"title":"Ferrari CEO Deepfake Shows Growing Threat of AI Scams Impersonating Executives","url":"https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo","publisher":"Bloomberg"}],"entry_type":"incident","slug":"2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ferrari-executive-defeats-deepfake-of-ceo-benedetto-vigna-with-a-book-qu"},{"title":"WPP executives targeted by deepfake Teams meeting impersonating CEO Mark Read","date":"2024-05","date_precision":"month","victim_org":"WPP","sector":"Media & Entertainment","country":"United Kingdom","primary_vector":"Deepfake Video Call","secondary_vectors":["Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Attackers set up a WhatsApp account using a publicly available image of chief executive Mark Read, then ran a Microsoft Teams meeting using YouTube footage of him alongside an AI voice clone.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"WPP chief executive Mark Read disclosed in an internal email reported in May 2024 that fraudsters had created a WhatsApp account bearing his photograph and used it to arrange a Microsoft Teams meeting with another senior WPP leader. During the meeting the attackers played YouTube footage of Read and used a voice clone, and impersonated him in the meeting chat, in an attempt to set up a new business venture and solicit money and personal details. WPP said the attempt was prevented by the vigilance of staff.","how_it_worked":"The pretext was a new business opportunity that a chief executive might plausibly want to explore quietly with one trusted agency leader, which explained both the confidentiality and the unusual approach. The attackers assembled several weak trust signals into a convincing whole: a WhatsApp profile with Read's real photo, a Teams invite from an apparently senior source, video that showed his face and a synthetic voice on the line, and chat messages written in his persona. The technical staging papered over the gaps, with camera and audio problems used to explain why the video looked like recorded footage. The target was asked to move on money and personal information without touching normal corporate process.","lessons":"Verifying meeting invitations through the corporate directory rather than a messaging-app contact, and refusing to progress financial arrangements outside standard process, are what stopped this.","confidence":"Confirmed","sources":[{"title":"CEO of world's biggest ad firm targeted by deepfake scam","url":"https://www.theguardian.com/technology/article/2024/may/10/ceo-wpp-deepfake-scam","publisher":"The Guardian"},{"title":"Scammers Reportedly Used AI Voice Clone and YouTube Footage to Impersonate WPP CEO","url":"https://incidentdatabase.ai/cite/983/","publisher":"AI Incident Database"}],"entry_type":"incident","slug":"2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wpp-executives-targeted-by-deepfake-teams-meeting-impersonating-ceo-mark"},{"title":"LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO","date":"2024-04","date_precision":"month","victim_org":"LastPass","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.","how_it_worked":"The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.","lessons":"A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.","confidence":"Confirmed","sources":[{"title":"Attempted Audio Deepfake Call Targets LastPass Employee","url":"https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee","publisher":"LastPass"},{"title":"LastPass: Hackers targeted employee in failed deepfake CEO call","url":"https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/","publisher":"BleepingComputer"},{"title":"LastPass employee targeted via an audio deepfake call","url":"https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"},{"title":"Arup Hong Kong office loses about $25 million in deepfake video call scam","date":"2024-02","date_precision":"month","victim_org":"Arup Group (Hong Kong office)","sector":"Professional Services","country":"Hong Kong","primary_vector":"Deepfake Video Call","secondary_vectors":["Business Email Compromise","Voice Clone / Audio Deepfake","Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Hong Kong police stated the fraudsters used AI-generated video and audio to impersonate the company's chief financial officer and other staff in a multi-person video conference; the fake participants did not interact naturally with the victim.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":25000000,"loss_note":"HK$200 million, about US$25 million, transferred into five local bank accounts. Arup publicly confirmed in May 2024 that it was the targeted firm.","records_affected":null,"threat_actor":null,"summary":"In early 2024 an employee at the Hong Kong office of British engineering firm Arup transferred HK$200 million, roughly $25 million, after joining a video conference in which AI-generated likenesses of the company's chief financial officer and other colleagues instructed the payment. Hong Kong police disclosed the case on February 4, 2024, and Arup was identified as the victim in May 2024. Funds went to five local bank accounts.","how_it_worked":"The fraud began with a payment request that the employee initially suspected, so the criminals escalated to a video meeting to overcome doubt. In the call, deepfaked video and cloned audio of the CFO and several recognizable colleagues appeared alongside the victim, who was asked to introduce himself but was never genuinely engaged in dialogue, the participants delivering scripted instructions instead. Seeing familiar faces and hearing familiar voices supplied the assurance that the earlier email could not. Follow-up instructions arrived by instant message, email and one-to-one video calls, and the employee executed a series of transfers into five Hong Kong accounts before the deception was discovered.","lessons":"High-value payments should require verification through a separate, pre-registered channel and multi-party approval independent of whoever appears on the call; a live challenge that only the real colleague could answer also defeats a pre-rendered persona.","confidence":"Confirmed","sources":[{"title":"Deepfaked video conference call makes employee send $25 million to scammers","url":"https://www.helpnetsecurity.com/2024/02/05/deepfake-video-conference-call/","publisher":"Help Net Security"},{"title":"Arup Group (fraud incident section)","url":"https://en.wikipedia.org/wiki/Arup_Group","publisher":"Wikipedia"},{"title":"Business Email Compromise: Virtual Meeting Platforms","url":"https://www.ic3.gov/PSA/2022/PSA220216","publisher":"FBI IC3"},{"title":"Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee","url":"https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk","publisher":"CNN"},{"title":"'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting","url":"https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage","publisher":"South China Morning Post"}],"entry_type":"incident","slug":"2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-arup-hong-kong-office-loses-about-25-million-in-deepfake-video-call-scam"},{"title":"AI voice clone of Taylor Swift used in fake Le Creuset giveaway ads","date":"2024-01","date_precision":"month","victim_org":"Multiple US consumers; brands Taylor Swift and Le Creuset impersonated","sector":"Consumer","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Voice Clone / Audio Deepfake","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The ads paired authentic images of the singer with a synthesised clone of her voice; a Carnegie Mellon researcher confirmed the audio was fabricated while the photographs were genuine.","outcomes":["Wire Fraud / Financial Loss","Identity Theft"],"loss_usd":null,"loss_note":"Individual victims reported paying small shipping fees and supplying card details; aggregate loss not published","records_affected":null,"threat_actor":null,"summary":"In January 2024 advertisements circulating on Meta platforms used real photographs of Taylor Swift together with an AI-cloned version of her voice to promote a fake Le Creuset cookware giveaway. Victims were told to click through, answer questions and pay a small shipping charge, which exposed payment card details. Le Creuset said it had no such promotion with the singer and Meta removed the ads.","how_it_worked":"The scam borrowed two trusted identities at once, a celebrity with an unusually devoted fanbase and a premium cookware brand that plausibly runs promotions. Distribution came through paid social ads, so the content arrived inside a feed the target already trusted rather than in an unsolicited message. The cloned voice narrating a personal-sounding offer supplied the authenticity that still images alone would not, and the giveaway framing made urgency natural: a limited number of free sets meant acting immediately. The small shipping fee was the conversion step, low enough to feel harmless while capturing card data and personal details.","lessons":"Consumers should verify giveaways on the brand's own site, and ad platforms need celebrity-likeness and synthetic-voice detection in advertiser review rather than post-hoc takedown.","confidence":"Reported","sources":[{"title":"The Taylor Swift Le Creuset cookware giveaway is fake","url":"https://www.today.com/food/news/taylor-swift-le-creuset-cookware-giveaway-fake-rcna133325","publisher":"TODAY / NBC News"},{"title":"AI-generated ads using Taylor Swift's likeness dupe fans with fake Le Creuset giveaway","url":"https://cbsnews.com/news/taylor-swift-le-creuset-ai-generated-ads","publisher":"CBS News"}],"entry_type":"campaign","slug":"2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-voice-clone-of-taylor-swift-used-in-fake-le-creuset-giveaway-ads"},{"title":"AI-cloned Biden robocall told New Hampshire voters to skip the primary","date":"2024-01","date_precision":"month","victim_org":"New Hampshire primary voters","sector":"Government","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Political consultant Steve Kramer admitted commissioning an AI-cloned voice of President Biden for the robocall; the FCC's enforcement action describes the recording as AI-generated.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"FCC proposed a US$6 million forfeiture against Kramer; carrier Lingo Telecom settled for US$1 million","records_affected":null,"threat_actor":"Steven Kramer (political consultant)","summary":"On 21 January 2024, two days before the New Hampshire presidential primary, thousands of voters received a robocall using an AI clone of President Joe Biden's voice urging them to 'save your vote for the November election' rather than vote in the primary. Political consultant Steve Kramer acknowledged commissioning the call, saying he intended it as a warning about AI. The FCC proposed a US$6 million fine against Kramer and reached a US$1 million settlement with transmitting carrier Lingo Telecom, and New Hampshire prosecutors charged Kramer with voter suppression and candidate impersonation.","how_it_worked":"The channel was an ordinary automated phone call with spoofed caller ID, arriving in the last hours before an election when voters have little time to check anything. The trust signal was the president's recognisable voice delivering a message in his own idiom, addressed to Democratic voters as if from the campaign itself. The persuasion was framed not as suppression but as helpful strategy, telling recipients their vote mattered more in November, which gave the instruction an internally consistent rationale. Because the medium is one-way and the timing left no room for correction, targets had no natural opportunity to verify before the primary took place.","lessons":"Carriers enforcing STIR/SHAKEN caller-ID attestation on upstream customers, plus rapid election-authority rebuttal channels, are the practical controls; voters should treat any voting instruction by phone as unverified.","confidence":"Confirmed","sources":[{"title":"FCC Proposes $6 Million Fine For Illegal Robocalls That Used Deepfake AI Voice","url":"https://docs.fcc.gov/public/attachments/DOC-402762A1.pdf","publisher":"US Federal Communications Commission"},{"title":"Criminal charges and FCC fines issued for deepfake Biden robocalls","url":"https://www.npr.org/2024/05/23/nx-s1-4977582/fcc-ai-deepfake-robocall-biden-new-hampshire-political-operative","publisher":"NPR"}],"entry_type":"incident","slug":"2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ai-cloned-biden-robocall-told-new-hampshire-voters-to-skip-the-primary"},{"title":"Retool breach used SMS phishing plus an AI-cloned voice of a real IT employee","date":"2023-08-27","date_precision":"day","victim_org":"Retool","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Voice Clone / Audio Deepfake","Vishing (Voice Phishing)","Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Retool stated the caller used a deepfaked voice imitating a specific member of its IT team, whom the target employee knew. This is one of the earliest well-documented uses of voice cloning in a corporate intrusion.","outcomes":["Data Breach","Cryptocurrency Theft","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Retool reported no loss of its own; downstream, cryptocurrency customer Fortress Trust separately reported a theft of roughly $15 million tied to the compromise, a figure attributed to Fortress Trust rather than confirmed by Retool.","records_affected":27,"threat_actor":null,"summary":"Retool disclosed that on 27 August 2023 an attacker phished an employee by SMS and then called them using an AI-generated clone of a colleague's voice, obtaining a multifactor code. Because Google Authenticator's then-new cloud sync feature backed up one-time-password seeds to the employee's Google account, capturing the account gave the attacker every OTP token. Twenty-seven cloud customers, all in the cryptocurrency sector, had their accounts accessed.","how_it_worked":"The employee received a text claiming to be from Retool IT about a payroll and healthcare enrolment issue, with a link to a page cloning the company's internal identity portal. After the employee submitted credentials and an MFA code, the attacker phoned them; the voice was a deepfake of a specific IT team member the employee recognised, and the caller was familiar with office layout, colleagues and internal processes. During the call the employee provided an additional MFA code, which let the attacker add their own device to the employee's Okta account. From there they reached the employee's Google account, where Authenticator's cloud sync had backed up OTP seeds, and used those to pivot into internal admin systems and alter customer accounts.","lessons":"Voice is no longer an identity proof; hardware security keys plus a policy that MFA codes are never read aloud, and disabling authenticator cloud sync on enterprise accounts, close both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Retool blames breach on Google Authenticator MFA cloud sync feature","url":"https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/","publisher":"BleepingComputer"},{"title":"Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients","url":"https://thehackernews.com/2023/09/retool-falls-victim-to-sms-based.html","publisher":"The Hacker News"},{"title":"Google Feature Blamed for Retool Breach That Led to Cryptocurrency Firm Hacks","url":"https://www.securityweek.com/google-feature-blamed-for-retool-breach-that-led-to-cryptocurrency-firm-hacks/","publisher":"SecurityWeek"},{"title":"When MFA isn't actually MFA","url":"https://retool.com/blog/mfa-isnt-mfa","publisher":"Retool"}],"entry_type":"incident","slug":"2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-retool-breach-used-sms-phishing-plus-an-ai-cloned-voice-of-a-real-it-emp"},{"title":"French woman loses EUR 830,000 to an AI-image 'Brad Pitt' romance scam","date":"2023-02","date_precision":"month","victim_org":"Private individual in France (identified only as 'Anne')","sector":"Consumer","country":"France","primary_vector":"Romance / Investment Scam","secondary_vectors":[],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Scammers sent AI-generated photographs purporting to show Brad Pitt in a hospital bed, along with images of a fake passport, to sustain the impersonation across an 18-month relationship.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":857900,"loss_note":"EUR 830,000, approx US$858,000","records_affected":null,"threat_actor":"Nigerian-linked fraud network under French investigation","summary":"Beginning in February 2023, a 53-year-old French woman known publicly as Anne was drawn into an online relationship with someone posing as actor Brad Pitt. Over about 18 months she sent EUR 830,000, largely after being told he needed money for kidney cancer treatment and that his accounts were frozen by divorce proceedings. AI-generated images of the actor in hospital and a forged passport reinforced the deception. She realised she had been defrauded on seeing genuine photographs of Pitt with his partner, and filed a police complaint; the case became public in January 2025 when French broadcaster TF1 aired and then withdrew her interview.","how_it_worked":"Contact began through social media with a persona claiming to be the actor's mother, which lent credibility before the celebrity persona itself appeared. The relationship was built slowly with daily messages, declarations of love and a promise of marriage, so that by the time money was requested the target was emotionally invested rather than evaluating a proposition. AI-generated hospital photographs, tailored to each new claim, answered the natural demand for proof, and a fabricated passport addressed identity doubts. The medical emergency supplied urgency, and the story that the actor's assets were frozen in divorce explained why a wealthy man would need her money at all.","lessons":"Any claim of celebrity contact should be treated as fraudulent absent verified representation, and banks flagging repeated large outbound transfers from an unusual customer profile can interrupt the sequence.","confidence":"Reported","sources":[{"title":"Nigerian scammers accused in AI-driven fake Brad Pitt fraud","url":"https://www.france24.com/en/live-news/20250121-nigerian-scammers-accused-in-ai-driven-fake-brad-pitt-fraud","publisher":"AFP via France 24"},{"title":"AI Brad Pitt convinced a French woman to pay EUR 830K for kidney treatment","url":"https://www.ccn.com/news/technology/ai-brad-pitt-convinced-french-woman-pay-e830k/","publisher":"CCN"}],"entry_type":"incident","slug":"2023-french-woman-loses-eur-830-000-to-an-ai-image-brad-pitt-romance-scam","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-french-woman-loses-eur-830-000-to-an-ai-image-brad-pitt-romance-scam"},{"title":"Deepfake of Binance communications chief used to scam crypto projects on video calls","date":"2022-08","date_precision":"month","victim_org":"Multiple cryptocurrency projects seeking Binance listings","sector":"Cryptocurrency","country":"Multiple countries","primary_vector":"Deepfake Video Call","secondary_vectors":["Romance / Investment Scam"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Binance chief communications officer Patrick Hillmann said attackers built an AI video 'hologram' of him from his past news interviews and TV appearances and used it live on Zoom calls.","outcomes":["Wire Fraud / Financial Loss","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Losses to individual projects were not disclosed","records_affected":null,"threat_actor":null,"summary":"In August 2022 Binance disclosed that a 'sophisticated hacking team' had produced a deepfake video likeness of chief communications officer Patrick Hillmann and used it on Zoom calls with representatives of cryptocurrency projects. The impersonator offered help getting tokens listed on Binance and solicited payments and information. Hillmann said several project managers were convinced before the fraud was discovered, and that the clone was built from his publicly available interview footage.","how_it_worked":"The pretext was the single thing small crypto projects want most, a listing on the largest exchange, and the caller occupied a role that plausibly controls access to it. Contact was made over social channels and then escalated to a Zoom call, where the deepfake of a face the targets had seen in Binance media coverage supplied the trust signal that a mere email could not. Because listing discussions are routinely confidential and involve fees, requests for money and business documents did not look out of place. Victims were pushed to move fast on the implied scarcity of a listing slot, and only later checked with Binance through official channels.","lessons":"Exchange listing and partnership discussions should be confirmed through the company's published contact channels, and no vendor should treat a video likeness as proof of employment.","confidence":"Reported","sources":[{"title":"Binance exec says scammers made a deepfake hologram of him","url":"https://www.theregister.com/2022/08/23/binance_deepfake_scam/","publisher":"The Register"},{"title":"Deepfake hologram targets Binance and crypto community","url":"https://www.malwarebytes.com/blog/news/2022/08/deepfake-hologram-targets-binance-and-crypto-community","publisher":"Malwarebytes Labs"}],"entry_type":"campaign","slug":"2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-deepfake-of-binance-communications-chief-used-to-scam-crypto-projects-on"}]}