{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:39.847Z","total":8,"returned":8,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so","title":"LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code","date":"2022-03","date_precision":"month","year":2022,"victim_org":"T-Mobile US","sector":"Telecom","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Credential Phishing Portal","Insider Recruitment","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Insider Access","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"LAPSUS$ (DEV-0537)","summary":"Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.","how_it_worked":"LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.","lessons":"Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.","confidence":"Confirmed","sources":[{"title":"Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code","url":"https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/","publisher":"Krebs on Security"},{"title":"T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code","url":"https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html","publisher":"The Hacker News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-repeatedly-targeted-t-mobile-staff-to-reach-internal-tools-and-so"},{"title":"Lapsus$ rides a Sitel support engineer's laptop into Okta's admin tooling","date":"2022-01-21","date_precision":"day","victim_org":"Okta (via subprocessor Sitel/Sykes)","sector":"Technology","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"Okta did not disclose a financial loss figure.","records_affected":null,"threat_actor":"Lapsus$","summary":"A threat actor gained remote control of a laptop belonging to a support engineer at Sitel/Sykes, a customer-support subprocessor for Okta, and used the engineer's delegated access to Okta's internal SuperUser application. Okta initially said up to 366 customers were potentially exposed but its concluded investigation found the actor had hands-on-keyboard access for 25 minutes on 21 January 2022 and reached two customer tenants. Lapsus$ published screenshots in March 2022, forcing disclosure.","how_it_worked":"Lapsus$ specialised in abusing the human layer of outsourced IT: support agents at business-process outsourcers hold standing, broadly scoped access to customer tenants but sit outside the customer's own security controls. Having taken over a Sitel engineer's workstation, the actor inherited that trusted seat and drove the Okta SuperUser console as the agent, in the agent's session, from the agent's device. No password or MFA prompt was presented to the attacker because the legitimate operator had already satisfied them. The blast radius was limited only by what the support role could do.","lessons":"Outsourced support seats need the same scrutiny as privileged internal admins: just-in-time, scoped, session-recorded access with device trust, rather than standing tenant-wide impersonation rights.","confidence":"Confirmed","sources":[{"title":"Okta Concludes its Investigation Into the January 2022 Compromise","url":"https://www.okta.com/blog/company-and-culture/okta-concludes-its-investigation-into-the-january-2022-compromise/","publisher":"Okta"},{"title":"Okta says hundreds of companies impacted by security breach","url":"https://techcrunch.com/2022/03/23/okta-breach-sykes-sitel/","publisher":"TechCrunch"}],"entry_type":"incident","slug":"2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lapsus-rides-a-sitel-support-engineer-s-laptop-into-okta-s-admin-tooling"},{"slug":"2026-shinyhunters-sso-vishing-campaign-hits-100-organizations","title":"ShinyHunters SSO vishing campaign hits 100+ organizations","date":"2026-01","date_precision":"month","year":2026,"victim_org":"100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance","sector":"Other","country":"Global","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered LAPSUS$ Hunters","summary":"Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.","how_it_worked":"Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.","lessons":"Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.","confidence":"Confirmed","sources":[{"title":"Over 100 Organizations Targeted in ShinyHunters Phishing Campaign","url":"https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/","publisher":"SecurityWeek"},{"title":"A new wave of 'vishing' attacks is breaking into SSO accounts in real time","url":"https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/","publisher":"CyberScoop"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-shinyhunters-sso-vishing-campaign-hits-100-organizations"},{"slug":"2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform","title":"Stellantis confirms customer data stolen from Salesforce platform","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Stellantis","sector":"Manufacturing","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / Scattered Lapsus$ Hunters (claimed)","summary":"Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.","how_it_worked":"The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.","lessons":"Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.","confidence":"Reported","sources":[{"title":"Automaker giant Stellantis confirms data breach after Salesforce hack","url":"https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/","publisher":"BleepingComputer"},{"title":"Stellantis confirms data breach involving customers' contact information","url":"https://www.engadget.com/big-tech/stellantis-confirms-data-breach-involving-customers-contact-information-194136744.html","publisher":"Engadget"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-stellantis-confirms-customer-data-stolen-from-salesforce-platform"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"title":"Rockstar Games internal Slack breached and GTA 6 footage leaked","date":"2022-09-18","date_precision":"day","victim_org":"Rockstar Games","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Rockstar and parent Take-Two did not quantify losses publicly.","records_affected":null,"threat_actor":"Arion Kurtaj, linked to Lapsus$ (same actor as the Uber intrusion)","summary":"An actor using the handle teapotuberhacker, the same persona behind the Uber intrusion days earlier, posted roughly 90 in-development Grand Theft Auto VI videos and claimed to hold GTA V and GTA VI source code, saying they had reached Rockstar's internal Slack and Confluence. Rockstar confirmed a network intrusion and unauthorised access to early development footage. A UK teenager, Arion Kurtaj, was later convicted and in December 2023 given an indefinite hospital order.","how_it_worked":"The actor did not publish a technical exploit chain, and Rockstar has never described the entry point, so the mechanics are attacker-claimed and inferred from the same operator's behaviour at Uber days earlier: harvesting employee credentials and then talking a human into approving access, followed by collection from collaboration platforms rather than code repositories. Once inside Slack and Confluence the value was not code execution but corporate memory, build videos, design documents and chat, which the actor packaged directly into an extortion attempt and a public leak.","lessons":"Collaboration platforms hold the crown jewels for a media company and deserve the same phishing-resistant MFA, device trust and data-egress monitoring as source control.","confidence":"Alleged","sources":[{"title":"Alleged Grand Theft Auto 6 (GTA6) gameplay videos and source code leaked online","url":"https://securityaffairs.com/135923/data-breach/gta6-gameplay-videos-source-code-leak.html","publisher":"Security Affairs"},{"title":"London Police arrested a teen suspected to be behind Uber, Rockstar Games breaches","url":"https://securityaffairs.com/136146/cyber-crime/uber-rockstar-games-hacker-arrest.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked"},{"title":"Uber breached after MFA push bombing and a WhatsApp message posing as IT","date":"2022-09-15","date_precision":"day","victim_org":"Uber Technologies","sector":"Transportation & Logistics","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Insider Access","Service Disruption"],"loss_usd":null,"loss_note":"No monetary loss disclosed; Uber said no public-facing systems or user accounts were accessed.","records_affected":null,"threat_actor":"Lapsus$ (an 18-year-old member was later convicted in the UK)","summary":"In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.","how_it_worked":"With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.","lessons":"Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.","confidence":"Confirmed","sources":[{"title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack","url":"https://www.darkreading.com/cyberattacks-data-breaches/uber-breach-external-contractor-mfa-bombing-attack","publisher":"Dark Reading"},{"title":"Lessons to learn from the Uber security breach","url":"https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/09/27-september-2022-lessons-to-learn-from-the-uber-security-breach.pdf.coredownload.inline.pdf","publisher":"KPMG"},{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Security Update","url":"https://www.uber.com/newsroom/security-update/","publisher":"Uber"},{"title":"Uber links breach to Lapsus$ group, blames contractor for hack","url":"https://www.bleepingcomputer.com/news/security/uber-links-breach-to-lapsus-group-blames-contractor-for-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it"},{"title":"Cisco breached after vishing and MFA fatigue against an employee","date":"2022-05-24","date_precision":"day","victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No financial loss disclosed; Cisco said no impact to its business operations, products or supply chain.","records_affected":null,"threat_actor":"Initial access broker linked to UNC2447, Lapsus$ and Yanluowang","summary":"Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.","how_it_worked":"Credentials saved in Chrome were synchronised to the employee's personal Google account, which the attacker compromised. Holding valid corporate credentials, the attacker triggered a stream of MFA push prompts to wear the user down, while simultaneously calling them in English with a plausible accent posing as support from trusted organisations. The employee eventually approved one push, giving the attacker VPN access. They then enrolled new MFA devices, escalated to administrative privileges, added backdoor accounts, and used remote access tooling and LogMeIn/TeamViewer to maintain persistence, repeatedly attempting to return after eviction.","lessons":"Number matching or FIDO2 keys instead of simple push approval, plus blocking browser credential sync to personal accounts on managed devices, would have closed both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Cisco Talos shares insights related to recent cyber attack on Cisco","url":"https://blog.talosintelligence.com/recent-cyber-attack/","publisher":"Cisco Talos"},{"title":"Cisco Confirms Network Breach Via Hacked Employee Google Account","url":"https://threatpost.com/cisco-network-breach-google/180385/","publisher":"Threatpost"},{"title":"Cisco network hack: Voice phishing and MFA fatigue gave attacker access","url":"https://www.thestack.technology/cisco-network-hack-voice-phishing-mfa-fatigue/","publisher":"The Stack"}],"entry_type":"incident","slug":"2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee"}]}