{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:19.812Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"STAC4749 Teams vishing campaign led to Chaos ransomware in North America","date":"2026-02","date_precision":"month","victim_org":"Dozens of North American organisations (unnamed)","sector":"Manufacturing","country":"Canada","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Tech Support Scam"],"ai_involvement":"Unknown","ai_notes":"Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No ransom or loss totals were disclosed.","records_affected":null,"threat_actor":"STAC4749, deploying Chaos ransomware","summary":"Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.","how_it_worked":"The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.","lessons":"Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.","confidence":"Confirmed","sources":[{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","url":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-stac4749-teams-vishing-campaign-led-to-chaos-ransomware-in-north-america"}]}