{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:09.697Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"3AM ransomware affiliate used email bombing plus spoofed IT support calls","date":"2025-05-21","date_precision":"day","victim_org":"Unnamed Sophos client","sector":"Other","country":"Unknown","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"Sophos did not report AI-generated audio; the caller spoofed the victim's real IT department number.","outcomes":["Data Breach","Attempt Blocked"],"loss_usd":null,"loss_note":"No ransom or loss figure disclosed. 868 GB of data was exfiltrated but ransomware encryption was blocked.","records_affected":null,"threat_actor":"3AM ransomware affiliate","summary":"Sophos disclosed on May 21, 2025 that a 3AM ransomware affiliate had attacked one of its clients earlier in 2025 using a combination of email bombing and phone-based impersonation of the victim's own IT department. Sophos observed at least 55 attacks using this technique between November 2024 and January 2025. In the documented case the attackers stole 868 GB of data but were stopped before encryption.","how_it_worked":"The affiliate first buried a target employee under 24 unsolicited emails in three minutes, manufacturing an apparent IT emergency. While the inbox was still filling, an operator phoned the employee using a spoofed caller ID that matched the company's real IT department number, offered to fix the flood, and asked the employee to start a Microsoft Quick Assist remote session. The employee granted control, giving the attacker hands-on-keyboard access. The attackers then exfiltrated 868 GB to Backblaze cloud storage over nine days before attempting ransomware deployment.","lessons":"A rule that IT never initiates remote-control sessions by inbound call, paired with blocking or alerting on Quick Assist use, breaks the email-bombing-plus-callback pattern.","confidence":"Confirmed","sources":[{"title":"3AM ransomware uses spoofed IT calls, email bombing to breach networks","url":"https://www.bleepingcomputer.com/news/security/3am-ransomware-uses-spoofed-it-calls-email-bombing-to-breach-networks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-3am-ransomware-affiliate-used-email-bombing-plus-spoofed-it-support-call"}]}