{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:10.214Z","total":2,"returned":2,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2016-gru-spear-phished-election-vendor-vr-systems-then-122-local-election-off","title":"GRU spear-phished election vendor VR Systems, then 122 local election officials","date":"2016-11","date_precision":"month","year":2016,"victim_org":"VR Systems and US local election administrators","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Russian GRU military intelligence","summary":"A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.","how_it_worked":"The first stage was a credential phishing portal: emails that looked like Google security notices pointed VR Systems staff at a counterfeit Google sign-in page where they typed their passwords. The second stage weaponised the resulting familiarity. The operators registered a Gmail address in the name of a real VR Systems employee and mailed 122 local election administrators, who knew VR Systems as their voter-registration software vendor, attaching trojanised Word documents that ran PowerShell to fetch further malware. The trust signal was the vendor relationship itself, and the timing, days before the election, supplied the urgency that made recipients open attachments.","lessons":"Phishing-resistant MFA on vendor accounts and out-of-band confirmation of unexpected vendor attachments would have broken both stages of the chain.","confidence":"Reported","sources":[{"title":"Top-Secret NSA Report Details Russian Hacking Effort Days Before 2016 Election","url":"https://theintercept.com/2017/06/05/top-secret-nsa-report-details-russian-hacking-effort-days-before-2016-election/","publisher":"The Intercept"},{"title":"Report: Russia Launched Cyberattack On Voting Vendor Ahead Of Election","url":"https://www.npr.org/2017/06/05/531649602/report-russia-launched-cyberattack-on-voting-vendor-ahead-of-election","publisher":"NPR"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spear-phished-election-vendor-vr-systems-then-122-local-election-off"},{"title":"John Podesta and DNC staff phished by fake Google security alerts in 2016","date":"2016-03-19","date_precision":"day","victim_org":"Hillary for America campaign and the Democratic National Committee","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No direct monetary loss reported; harm was reputational and political.","records_affected":null,"threat_actor":"Fancy Bear / APT28, identified in the July 2018 US indictment as GRU Unit 26165","summary":"On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.","how_it_worked":"The message imitated Google's 'Someone has your password' notification and carried a Bitly link masking an attacker-controlled domain that rendered a pixel-perfect Google account login page. A campaign IT aide replied that the mail was legitimate, later saying he had meant to write 'illegitimate,' and the link was clicked and the password entered. With mailbox access the operators archived the account's contents. The same infrastructure was used across hundreds of targets; because Bitly statistics were public, researchers were later able to reconstruct the target list and confirm the operator's identity.","lessons":"Hardware security keys on campaign and executive Google accounts make a harvested password worthless, and a defined out-of-band process for verifying security alerts avoids relying on a hurried email reply.","confidence":"Confirmed","sources":[{"title":"Is this the email that hacked John Podesta's account?","url":"https://www.cnn.com/2016/10/28/politics/phishing-email-hack-john-podesta-hillary-clinton-wikileaks/index.html","publisher":"CNN"},{"title":"How hackers broke into John Podesta, DNC Gmail accounts","url":"https://news.sophos.com/en-us/2016/10/25/how-hackers-broke-into-john-podesta-dnc-gmail-accounts/","publisher":"Sophos Naked Security"},{"title":"How John Podesta's Emails Were Hacked And How To Prevent It From Happening To You","url":"https://www.forbes.com/sites/kevinmurnane/2016/10/21/how-john-podestas-emails-were-hacked-and-how-to-prevent-it-from-happening-to-you/","publisher":"Forbes"}],"entry_type":"incident","slug":"2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201"}]}