{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:20.298Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Iran's APT42 phishes Israeli and US officials with think-tank impersonation","date":"2024-08-14","date_precision":"day","victim_org":"Current and former Israeli and US government officials, diplomats and political campaign staff","sector":"Government","country":"Israel and United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_note":"No monetary loss; the objective was intelligence collection.","records_affected":null,"threat_actor":"APT42 / Charming Kitten (Iranian IRGC-linked)","summary":"On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.","how_it_worked":"APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.","lessons":"High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.","confidence":"Confirmed","sources":[{"title":"Iranian backed group steps up phishing campaigns against Israel, U.S.","url":"https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-iran-s-apt42-phishes-israeli-and-us-officials-with-think-tank-impersonat"}]}