{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:39.638Z","total":2,"returned":2,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Erie Insurance hit in Scattered Spider help desk campaign against insurers","date":"2025-06","date_precision":"month","victim_org":"Erie Insurance","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Erie Insurance was one of three US insurers publicly identified in June 2025 as victims of the Scattered Spider campaign against the insurance sector, alongside Aflac and Philadelphia Insurance Companies. The incidents involved theft of sensitive customer data and operational disruption, per the companies' SEC filings. The group had pivoted to insurance after earlier waves against UK retail.","how_it_worked":"The intrusion set relied on service-desk manipulation rather than exploitation. An operator called the help desk holding enough identifying information to impersonate a named employee, asked for an MFA enrolment link to be issued for a supposed new mobile device, and once that device was trusted, used self-service password reset to seize the account outright. Researchers noted the technique was effective across multiple insurers precisely because help desks follow an identical procedure no matter who calls, so a single credible pretext worked repeatedly.","lessons":"Identity proofing that a caller cannot supply from public or previously breached data, such as manager callback or a live video ID check, is the control that breaks this chain.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-erie-insurance-hit-in-scattered-spider-help-desk-campaign-against-insure"},{"title":"Philadelphia Insurance Companies disclosed breach in insurer-focused campaign","date":"2025-06","date_precision":"month","victim_org":"Philadelphia Insurance Companies","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.","how_it_worked":"Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.","lessons":"Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"}]}