{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:16:04.094Z","total":20,"returned":20,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},{"slug":"2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing","title":"Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts","date":"2025-08","date_precision":"month","year":2025,"victim_org":"Cryptocurrency holders and companies targeted by the group","sector":"Cryptocurrency","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft","Identity Theft"],"loss_usd":13000000,"loss_kind":"direct_loss","loss_note":"About $13 million in restitution ordered to 59 victims; the figure covers cryptocurrency stolen from individuals.","records_affected":null,"threat_actor":"Scattered Spider","summary":"A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.","how_it_worked":"The group ran two complementary human-centred plays. For individuals, they gathered personal details, then persuaded mobile carrier staff or used compromised carrier tooling to move a victim's phone number to a SIM they controlled, which handed them the SMS one-time codes protecting exchange and email accounts. For companies, they sent employees text messages claiming an urgent single sign-on or Okta password expiry, pointing at a lookalike portal that captured credentials and MFA codes in real time, and followed up with phone calls impersonating IT to talk hesitant staff through it. Both approaches turned on convincing a person, not breaking software.","lessons":"Carriers need strong port-out and SIM-change protections including account locks; enterprises should replace SMS and push MFA with phishing-resistant authenticators.","confidence":"Confirmed","sources":[{"title":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years","url":"https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/","publisher":"Krebs on Security"},{"title":"Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution","url":"https://therecord.media/scattered-spider-affiliate-sentenced-10-years","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-member-sentenced-to-10-years-over-sim-swap-and-phishing"},{"slug":"2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d","title":"Scattered Spider talks help desks into resets to reach VMware ESXi and deploy ransomware","date":"2025-07","date_precision":"month","year":2025,"victim_org":"US retail, airline, transportation and insurance organisations","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"UNC3944 / Scattered Spider","summary":"Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.","how_it_worked":"Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.","lessons":"Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.","confidence":"Confirmed","sources":[{"title":"Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure","url":"https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html","publisher":"The Hacker News"},{"title":"Scattered Spider targets VMware ESXi using social engineering","url":"https://securityaffairs.com/180466/cyber-crime/scattered-spider-targets-vmware-esxi-in-using-social-engineering/","publisher":"Security Affairs"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-scattered-spider-talks-help-desks-into-resets-to-reach-vmware-esxi-and-d"},{"title":"Hawaiian Airlines hit as Scattered Spider pivots to the aviation sector","date":"2025-06-26","date_precision":"day","victim_org":"Hawaiian Airlines","sector":"Transportation & Logistics","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported in this intrusion.","outcomes":["Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944 / Muddled Libra)","summary":"Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.","how_it_worked":"Scattered Spider's standard aviation playbook is to impersonate an employee or contractor in a call to the IT help desk and persuade the agent to reset credentials or enrol a new authenticator. The group also registers unauthorised devices against compromised accounts as a way of defeating multi-factor authentication, so that later logins look legitimate. Because airlines run large outsourced service desks covering shift workers and contractors around the clock, a caller claiming to be locked out mid-shift is a routine and hard-to-challenge request.","lessons":"Strict, scripted caller-verification for account recovery and alerting on new device registrations against existing accounts are the controls that surface this pattern early.","confidence":"Reported","sources":[{"title":"Scattered Spider appears to pivot toward aviation sector","url":"https://www.cybersecuritydive.com/news/scattered-spider-appears-to-pivot-toward-aviation-sector/751917/","publisher":"Cybersecurity Dive"}],"entry_type":"incident","slug":"2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-hawaiian-airlines-hit-as-scattered-spider-pivots-to-the-aviation-sector"},{"title":"Erie Insurance hit in Scattered Spider help desk campaign against insurers","date":"2025-06","date_precision":"month","victim_org":"Erie Insurance","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.","how_it_worked":"The intrusion set relied on service-desk manipulation rather than exploitation. An operator called the help desk holding enough identifying information to impersonate a named employee, asked for an MFA enrolment link to be issued for a supposed new mobile device, and once that device was trusted, used self-service password reset to seize the account outright. Researchers noted the technique was effective across multiple insurers precisely because help desks follow an identical procedure no matter who calls, so a single credible pretext worked repeatedly.","lessons":"Identity proofing that a caller cannot supply from public or previously breached data, such as manager callback or a live video ID check, is the control that breaks this chain.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure"},{"title":"Transport for London hit by Scattered Spider teens in a £29m intrusion","date":"2024-09-01","date_precision":"day","victim_org":"Transport for London","sector":"Transportation & Logistics","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Service Disruption","Data Breach","Credential Theft"],"loss_usd":39000000,"loss_note":"TfL put the cost at about £29 million (roughly $39 million); prosecutors said a complete shutdown could have caused up to £56 billion of economic damage.","records_affected":null,"threat_actor":"Scattered Spider; Thalha Jubair and Owen Flowers were each sentenced to five and a half years in July 2026","summary":"Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.","how_it_worked":"TfL has not published the entry vector, and the prosecution described Scattered Spider's general reliance on phone, email and SMS social engineering rather than a specific script for this intrusion. What the response reveals is the assumption TfL made about the attackers' capability: the organisation judged that remote password resets could themselves be abused, and required roughly 27,000 staff to attend in person with identity documents to re-establish credentials. That is the signature countermeasure to help-desk impersonation, adopted precisely because remote identity proofing could no longer be trusted.","lessons":"In-person or strongly verified credential re-issuance for staff, and phishing-resistant MFA for remote administrative access, are the controls TfL was forced to adopt reactively.","confidence":"Reported","sources":[{"title":"Transport for London (TfL) is dealing with an ongoing cyberattack","url":"https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html","publisher":"Security Affairs"},{"title":"Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack","url":"https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion","year":2024,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion"},{"title":"Allianz Life's Salesforce CRM emptied after social engineering","date":"2025-07-16","date_precision":"day","victim_org":"Allianz Life Insurance Company of North America","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Vendor / Supply Chain Impersonation"],"ai_involvement":"Suspected AI-enabled","ai_notes":"Allianz Life did not describe AI use; the wider ShinyHunters campaign it belonged to was documented by EclecticIQ as abusing AI voice-agent platforms for automated vishing.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":1100000,"threat_actor":"ShinyHunters (UNC6040-style Salesforce vishing), publicised via a joint Telegram channel with Scattered Spider and Lapsus$ personas","summary":"Allianz Life disclosed that on 16 July 2025 a threat actor used social engineering to reach a third-party cloud-based CRM system holding its Salesforce data, affecting the majority of its roughly 1.4 million customers plus financial professionals and select employees. Have I Been Pwned recorded 1.1 million affected individuals, and about 2.8 million records from Salesforce Accounts and Contacts tables were later leaked. Exposed fields included names, dates of birth, contact details, tax IDs and professional licence data.","how_it_worked":"Allianz Life fits the mid-2025 Salesforce pattern: a phone call to an employee from someone presenting as internal IT support, a fake Salesforce connect or login page, and an authorisation step the victim completes themselves. Because the outcome is an authorised connected app or a live session rather than a stolen password, MFA is never challenged again and the export runs through supported APIs. The crews then advertised the haul on a shared Telegram channel, using publicity as extortion pressure against a regulated insurer.","lessons":"Lock connected-app installation to administrators, monitor for anomalous bulk object exports, and treat SaaS CRM as a crown-jewel system with its own phishing-resistant access policy.","confidence":"Confirmed","sources":[{"title":"Allianz Life security breach impacted 1.1 million customers","url":"https://securityaffairs.com/181294/data-breach/allianz-life-security-breach-impacted-1-1-million-customers.html","publisher":"Security Affairs"},{"title":"Allianz Life data breach exposed the data of most of its 1.4M customers","url":"https://securityaffairs.com/180445/data-breach/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html","publisher":"Security Affairs"},{"title":"Social engineering attack obtains data on 'majority' of Allianz Life customers","url":"https://therecord.media/allianz-life-social-engineering-data-breach","publisher":"The Record (Recorded Future News)"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-allianz-life-s-salesforce-crm-emptied-after-social-engineering"},{"title":"Qantas contact centre platform breached after help desk tricked into adding MFA","date":"2025-07-01","date_precision":"day","victim_org":"Qantas Airways","sector":"Transportation & Logistics","country":"Australia","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.","records_affected":5700000,"threat_actor":"Scattered Spider / Muddled Libra (reported)","summary":"Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.","how_it_worked":"The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.","lessons":"Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.","confidence":"Confirmed","sources":[{"title":"Qantas data breach impacted 5.7 million individuals","url":"https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html","publisher":"Security Affairs"},{"title":"Qantas confirms customer data breach amid Scattered Spider attacks","url":"https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html","publisher":"Security Affairs"},{"title":"Update on Qantas cyber incident: Wednesday 9 July 2025","url":"https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025","publisher":"Qantas Newsroom"},{"title":"Tech support scam caused massive data breach at Australian airline Qantas","url":"https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267","publisher":"The Register"}],"entry_type":"incident","slug":"2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"},{"title":"Aflac breached in insurance-sector social engineering campaign; 22.6M affected","date":"2025-06-12","date_precision":"day","victim_org":"Aflac","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No public reporting attributes AI-generated voice to the Aflac intrusion.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed; Aflac offered 24 months of credit monitoring, identity theft and medical fraud protection.","records_affected":22650000,"threat_actor":"Not confirmed by Aflac; reporting points to Scattered Spider's 2025 insurance-sector campaign","summary":"Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.","how_it_worked":"Aflac has not published the intrusion mechanics beyond describing a sophisticated cybercrime group and an industry-wide campaign, so the vector here is characterised from the campaign rather than from Aflac's own disclosure. Google Threat Intelligence, warning insurers during the same weeks, told the sector to pay particular attention to social engineering attempts against help desks and call centres, the route the same crews had used against retail and hospitality: a phone call impersonating staff to obtain credential or MFA resets, then rapid data collection with no malware deployed.","lessons":"Identity verification standards for help desks and call centres, applied to both employee and customer channels, is the control the sector was explicitly warned to strengthen.","confidence":"Confirmed","sources":[{"title":"Aflac discloses breach amidst Scattered Spider insurance attacks","url":"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/","publisher":"BleepingComputer"},{"title":"22M Affected by Aflac Data Breach","url":"https://www.securityweek.com/22-million-affected-by-aflac-data-breach/","publisher":"SecurityWeek"},{"title":"Aflac confirms June data breach affecting over 22 million customers","url":"https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html","publisher":"Security Affairs"},{"title":"Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised","url":"https://www.hipaajournal.com/aflac-data-breach/","publisher":"The HIPAA Journal"},{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff"},{"title":"Google's own Salesforce instance hit by UNC6040 IT-support vishing","date":"2025-06","date_precision":"month","victim_org":"Google","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"Suspected AI-enabled","ai_notes":"EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Google did not pay; ShinyHunters demanded roughly 20 bitcoin, about $2.3 million, and later called the demand a prank.","records_affected":null,"threat_actor":"UNC6040 / ShinyHunters, overlapping with The Com and operating with Scattered Spider as 'Sp1d3rHunters'","summary":"Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.","how_it_worked":"Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.","lessons":"Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.","confidence":"Confirmed","sources":[{"title":"Salesforce customers duped by series of social-engineering attacks","url":"https://cyberscoop.com/google-unc6040-salesforce-attacks/","publisher":"CyberScoop"},{"title":"Google confirms Salesforce CRM breach, faces extortion threat","url":"https://securityaffairs.com/181017/data-breach/google-confirms-salesforce-crm-breach-faces-extortion-threat.html","publisher":"Security Affairs"},{"title":"FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups","url":"https://securityaffairs.com/182159/cyber-crime/fbi-warns-of-salesforce-attacks-by-unc6040-and-unc6395-groups.html","publisher":"Security Affairs"},{"title":"Google Among Victims in Ongoing Salesforce Data Theft Campaign","url":"https://www.infosecurity-magazine.com/news/google-salesforce-data-theft/","publisher":"Infosecurity Magazine"},{"title":"ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications","url":"https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications","publisher":"EclecticIQ"}],"entry_type":"incident","slug":"2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-s-own-salesforce-instance-hit-by-unc6040-it-support-vishing"},{"title":"Philadelphia Insurance Companies disclosed breach in insurer-focused campaign","date":"2025-06","date_precision":"month","victim_org":"Philadelphia Insurance Companies","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.","how_it_worked":"Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.","lessons":"Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"},{"title":"Marks & Spencer attack tied to social engineering of outsourced service desk","date":"2025-04-22","date_precision":"day","victim_org":"Marks & Spencer Group plc","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vendor / Supply Chain Impersonation","Vishing (Voice Phishing)","MFA Fatigue / Push Bombing"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":null,"loss_note":"M&S publicly guided to a hit of around £300 million to operating profit before mitigation; no USD figure is asserted here.","records_affected":null,"threat_actor":"Scattered Spider, deploying DragonForce ransomware","summary":"Marks & Spencer suffered a cyberattack disclosed in April 2025 that suspended online ordering for weeks and left gaps on shelves. Reporting indicates the attackers obtained credentials belonging to a third-party service provider, Tata Consultancy Services, which ran parts of M&S's IT service desk, through social engineering rather than a software vulnerability. M&S later ended the service desk contract with TCS. DragonForce ransomware was deployed against the estate.","how_it_worked":"Consistent with Scattered Spider's established method, the attackers researched employees, then contacted the outsourced service desk impersonating staff to obtain password and multifactor resets, or phished credentials from third-party personnel with privileged access to M&S systems. Those credentials gave access to M&S's identity infrastructure, from which the group escalated, moved into virtualisation infrastructure and deployed DragonForce ransomware. M&S suspended online orders and contactless payment services during containment; the outage persisted for weeks, and customer personal data was subsequently confirmed to have been taken.","lessons":"Identity proofing for credential and MFA resets must be enforced identically at outsourced service desks, and third-party administrator accounts should be individually attributed, MFA-hardened and monitored.","confidence":"Confirmed","sources":[{"title":"M&S hackers gained access through third-party Tata Consulting Services, sources say","url":"https://cybernews.com/news/marks-spencer-hackers-used-employee-login-tsc-tata-consulting-scattered-spider/","publisher":"Cybernews"},{"title":"M&S confirms month-long breach result of third-party vendor phishing attack","url":"https://cybernews.com/news/marks-spencer-breach-tcs-third-party-vendor-social-engineering-attack/","publisher":"Cybernews"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Marks and Spencer confirms data breach after April cyber attack","url":"https://securityaffairs.com/177784/data-breach/marks-and-spencer-confirms-data-breach-after-april-cyber-attack.html","publisher":"Security Affairs"},{"title":"Marks & Spencer breach linked to Scattered Spider ransomware attack","url":"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-marks-spencer-attack-tied-to-social-engineering-of-outsourced-service-de"},{"title":"Co-op loses £206m of revenue and 6.5 million members' data to DragonForce","date":"2025-04","date_precision":"month","victim_org":"Co-operative Group","sector":"Retail","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Service Disruption","Extortion"],"loss_usd":275000000,"loss_note":"Co-op reported a £206 million revenue loss, roughly $275 million, driven by weeks of food supply disruption.","records_affected":6500000,"threat_actor":"DragonForce, with Scattered Spider-aligned English-speaking affiliates; four people aged 17 to 20 were arrested by the UK NCA in July 2025","summary":"The Co-operative Group was attacked in April 2025 in the same wave as Marks & Spencer. Attackers contacted Co-op's security leadership on Microsoft Teams on 25 April and by phone about a week later. Personal data of 6.5 million members was stolen, including names, contact details and dates of birth, though not passwords, financial details or transaction records; DragonForce claimed data on 20 million people. Co-op reported a £206 million revenue loss and weeks of empty shelves.","how_it_worked":"Co-op's account of the intrusion, given publicly by its leadership, is that the attackers impersonated an employee convincingly enough to have that employee's password reset, then used the re-issued credentials to enter the network. The Teams messages and follow-up phone calls to security staff show the same crew comfortable operating in the victim's own collaboration tools, negotiating and pressuring in real time. Co-op's decision to pull systems down aggressively contained the intrusion before encryption, which is why the damage landed as lost revenue and stolen data rather than ransomware.","lessons":"Caller verification at the service desk, and separate approval paths for resets on high-privilege accounts, would have removed the single conversation that granted access.","confidence":"Confirmed","sources":[{"title":"Cyberattack on Co-op leaves shelves empty, data stolen, and $275M in lost revenue","url":"https://securityaffairs.com/182713/security/cyberattack-on-co-op-leaves-shelves-empty-data-stolen-and-275m-in-lost-revenue.html","publisher":"Security Affairs"},{"title":"DragonForce group claims the theft of data after Co-op cyberattack","url":"https://securityaffairs.com/177376/cyber-crime/dragonforce-group-claims-the-theft-of-data-after-co-op-cyberattack.html","publisher":"Security Affairs"},{"title":"Data of all 6.5 million Co-op members stolen - CEO says she is 'incredibly sorry'","url":"https://www.techradar.com/pro/security/data-of-all-6-5-million-coop-members-stolen-ceo-is-incredibly-sorry","publisher":"TechRadar Pro"},{"title":"Beware phony IT calls after Co-op and M&S hacks, says UK cyber centre","url":"https://feeds.bbci.co.uk/news/articles/c4grn878712o","publisher":"BBC News"},{"title":"Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages","url":"https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce","year":2025,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-co-op-loses-206m-of-revenue-and-6-5-million-members-data-to-dragonforce"},{"title":"MGM Resorts shut down for ten days after a help desk social engineering call","date":"2023-09-11","date_precision":"day","victim_org":"MGM Resorts International","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI or voice cloning was reported; the reported method was a live human call using details gathered from public professional profiles.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":110000000,"loss_note":"MGM reported roughly $100 million of negative impact to Las Vegas and regional operations' adjusted property earnings plus under $10 million of one-time costs; a $45 million class settlement covering this and an earlier breach was approved later.","records_affected":null,"threat_actor":"Scattered Spider, an affiliate of ALPHV/BlackCat","summary":"MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.","how_it_worked":"MGM has never published the entry point, but the widely reported account, consistent with the CISA advisory and Okta's contemporaneous warning, is that the crew identified an MGM employee from a public professional profile, gathered enough personal and organisational detail to pass as them, and phoned the IT help desk to obtain a credential and MFA reset in a call reported to have lasted about ten minutes. With a legitimate identity re-issued to them, the actors escalated inside the identity provider and, after exfiltration, deployed ransomware against virtualisation infrastructure.","lessons":"High-privilege credential and MFA resets should never be grantable on a single inbound phone call; out-of-band verification with a known manager or video identity check would have cost the caller the whole operation.","confidence":"Reported","sources":[{"title":"Ransomware attack on MGM Resorts costs $110 Million","url":"https://securityaffairs.com/152077/cyber-crime/mgm-resorts-ransomware-attack.html","publisher":"Security Affairs"},{"title":"MGM Resorts confirms hackers stole customers' personal data during cyberattack","url":"https://techcrunch.com/2023/10/06/mgm-resorts-admits-hackers-stole-customers-personal-data-cyberattack/","publisher":"TechCrunch"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"},{"title":"A full timeline of the MGM Resorts cyber attack","url":"https://www.cshub.com/attacks/news/a-full-timeline-of-the-mgm-resorts-cyber-attack","publisher":"Cyber Security Hub"}],"entry_type":"incident","slug":"2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering"},{"title":"Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered","date":"2023-08-18","date_precision":"day","victim_org":"Caesars Entertainment","sector":"Gaming & Casino","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Help Desk Impersonation","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Wire Fraud / Financial Loss"],"loss_usd":15000000,"loss_note":"Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.","records_affected":null,"threat_actor":"Scattered Spider, reportedly working with ALPHV/BlackCat","summary":"Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.","how_it_worked":"Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.","lessons":"Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.","confidence":"Confirmed","sources":[{"title":"Caesars Entertainment says social-engineering attack behind August breach","url":"https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/","publisher":"Cybersecurity Dive"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"incident","slug":"2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially","year":2023,"loss_kind":"ransom_paid","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"},{"title":"Clorox attack traced to help desk agents resetting passwords without verification","date":"2023-08-11","date_precision":"day","victim_org":"The Clorox Company","sector":"Manufacturing","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the complaint describes live phone calls.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Wire Fraud / Financial Loss"],"loss_usd":380000000,"loss_note":"$380 million is the total damages Clorox sought in its 2025 lawsuit against Cognizant, including about $49 million in direct remediation costs; it is a litigation claim, not an adjudicated loss.","records_affected":null,"threat_actor":"Scattered Spider","summary":"Clorox suffered an August 2023 cyberattack that halted manufacturing and caused widespread product shortages. In a July 2025 lawsuit against IT services provider Cognizant, Clorox alleged the attackers simply telephoned the outsourced service desk, impersonated Clorox employees, and were given password and multifactor resets without any identity verification. Clorox is seeking $380 million in damages; Cognizant disputes the claims.","how_it_worked":"According to the complaint, the attacker called the Cognizant-run service desk multiple times claiming to be a Clorox employee and asked for a password reset. The agent reset the credential and the multifactor enrolment without confirming the caller's identity, and transcripts quoted in the filing show no verification step took place. The attacker used the same technique against a Clorox IT security employee, which yielded privileged network access. From there the intrusion progressed to network-wide disruption; Clorox took systems offline, reverted to manual order processing, and saw sales and shipments fall for months afterwards.","lessons":"Outsourced service desks need contractually mandated, auditable identity proofing before any credential or MFA reset, with higher-assurance checks for accounts holding privileged access.","confidence":"Confirmed","sources":[{"title":"Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit","url":"https://www.bleepingcomputer.com/news/security/hackers-fooled-cognizant-help-desk-says-clorox-in-380m-cyberattack-lawsuit/","publisher":"BleepingComputer"},{"title":"Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack","url":"https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor","publisher":"The Record"},{"title":"Clorox files $380 million suit blaming Cognizant for 2023 cyberattack","url":"https://www.cybersecuritydive.com/news/clorox-380-million-suit-cognizant-cyberattack/753837/","publisher":"Cybersecurity Dive"},{"title":"$380M lawsuit: intruder got Clorox's passwords from Cognizant simply by asking","url":"https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/","publisher":"The Register"},{"title":"Clorox estimates the costs of the August cyberattack will exceed $49 Million","url":"https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-clorox-attack-traced-to-help-desk-agents-resetting-passwords-without-ver"},{"title":"Okta warns of a coordinated campaign against US customers' IT service desks","date":"2023-08","date_precision":"month","victim_org":"Multiple US-based Okta customer organizations","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in Okta's advisory.","outcomes":["Credential Theft","Data Breach","Insider Access"],"loss_usd":null,"loss_note":"Okta did not name victims or quantify losses in this advisory.","records_affected":null,"threat_actor":"Actor consistent with Scattered Spider / Muddled Libra (unnamed in the advisory)","summary":"Okta published an advisory on 31 August 2023 describing a coordinated campaign between 29 July and 19 August 2023 in which threat actors called the IT service desks of multiple US-based Okta customers and persuaded them to reset all MFA factors enrolled by highly privileged users. The actors then took over Super Administrator accounts, abused inbound federation to impersonate other users, and moved laterally. This advisory covers the same technique and window as the casino and hospitality intrusions that followed weeks later.","how_it_worked":"The caller arrived already holding something: either the password to a privileged account or the ability to manipulate delegated authentication. That partial knowledge is what makes the help desk call succeed, because the agent hears a caller who knows their own username, manager and internal jargon, and treats an MFA reset as routine. Once the factors were reset the actor enrolled their own, signed in from anonymising proxies on unfamiliar devices, escalated to Super Administrator and stood up a second identity provider so they could impersonate arbitrary users through federation.","lessons":"Identity-proofing the caller out of band, such as manager attestation or video verification, plus admin-console policies that require phishing-resistant factors and known devices, breaks the reset-to-takeover chain.","confidence":"Confirmed","sources":[{"title":"Cross-Tenant Impersonation: Prevention and Detection","url":"https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/","publisher":"Okta Security"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"campaign","slug":"2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-okta-warns-of-a-coordinated-campaign-against-us-customers-it-service-des"},{"title":"Coinbase employee phished by SMS then talked through by a fake IT caller","date":"2023-02-05","date_precision":"day","victim_org":"Coinbase","sector":"Cryptocurrency","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Vishing (Voice Phishing)","Help Desk Impersonation","Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"Coinbase described a live human caller impersonating corporate IT; no synthetic voice was reported.","outcomes":["Data Breach","Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No customer funds or customer data were lost; exposure was limited to some employee contact details.","records_affected":null,"threat_actor":"Reported as the 0ktapus / Scattered Spider cluster","summary":"In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.","how_it_worked":"The lure was a text claiming the employee needed to sign in immediately to receive an important message, pointing at a credential-capture page. With a valid password but no second factor, the attacker escalated to a phone call, presenting themselves as internal IT and asking the employee to log into their workstation and follow instructions, which is the standard escalation pattern for this actor. The requests grew progressively more unusual as the call went on. Detection came from behavioural alerting on unusual account activity rather than from the employee, and an internal messaging outreach broke the attacker's hold before meaningful access was established.","lessons":"Blocking employee installation of unsanctioned remote-access tools and training staff that IT will never call to ask for MFA codes or screen control converts a credential phish into a contained event.","confidence":"Confirmed","sources":[{"title":"Social Engineering - A Coinbase Case Study","url":"https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study","publisher":"Coinbase"},{"title":"Coinbase cyberattack targeted employees with fake SMS alert","url":"https://www.bleepingcomputer.com/news/security/coinbase-cyberattack-targeted-employees-with-fake-sms-alert/","publisher":"BleepingComputer"},{"title":"Coinbase breached by social engineers, employee data stolen","url":"https://news.sophos.com/en-us/2023/02/21/coinbase-breached-by-social-engineers-employee-data-stolen","publisher":"Sophos News"}],"entry_type":"incident","slug":"2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-coinbase-employee-phished-by-sms-then-talked-through-by-a-fake-it-caller"},{"title":"Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers","date":"2022-08-04","date_precision":"day","victim_org":"Twilio","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the kit relayed credentials to operators via Telegram in real time.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published across the affected organisations.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (tracked by Okta and Group-IB; overlaps with Scattered Spider reporting)","summary":"In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.","how_it_worked":"The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.","lessons":"SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.","confidence":"Confirmed","sources":[{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Twilio confirms data breach after its employees got phished","url":"https://www.helpnetsecurity.com/2022/08/09/twilio-phished-data-breach/","publisher":"Help Net Security"},{"title":"Twilio says breach also compromised Authy two-factor app users","url":"https://techcrunch.com/2022/08/26/twilio-breach-authy/","publisher":"TechCrunch"},{"title":"Incident Report: Employee and Customer Account Compromise","url":"https://www.twilio.com/en-us/blog/archive/2022/august-2022-social-engineering-attack","publisher":"Twilio"}],"entry_type":"incident","slug":"2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust"},{"slug":"2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org","title":"0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations","date":"2022-08","date_precision":"month","year":2022,"victim_org":"Over 130 organisations targeted (Group-IB tracked campaign)","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":9931,"threat_actor":"0ktapus (linked to Scattered Spider / UNC3944 activity)","summary":"Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.","how_it_worked":"Employees received text messages, often outside working hours, claiming their VPN session had expired or that a schedule change required immediate action, with a link to what looked like their employer's Okta single sign-on page. The pages were cloned per target company, so each recipient saw their own branding. Victims typed their username, password and then the one-time MFA code, all of which were relayed to the operators in real time and used to log in before the code expired. SMS was chosen deliberately: it arrives on a phone, outside corporate email defences, and reads as urgent IT housekeeping rather than an attack.","lessons":"Only phishing-resistant authentication such as FIDO2 security keys defeats a real-time relay of passwords and one-time codes; SMS-delivered lures also need out-of-band IT verification channels staff actually know to use.","confidence":"Confirmed","sources":[{"title":"Roasting 0ktapus: The phishing campaign going after Okta identity credentials","url":"https://www.group-ib.com/blog/0ktapus/","publisher":"Group-IB"},{"title":"0ktapus Phishing Campaign Targets Okta Identity Credentials","url":"https://www.infosecurity-magazine.com/news/0ktapus-phishing-targets-okta/","publisher":"Infosecurity Magazine"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org"}]}